Hello Diego,
Could you verify that the SIEM dashboard is displaying other types of 
alerts? In case it is not, it might be related to the way it is sending the 
alerts to the interface.
Also, make sure that your interface ingestion is taking the information 
from the alerts.log file. I would recommend making sure that the file used 
for the Dashboard ingestion is enabled.

Let me know if you need anything.



On Monday, October 21, 2019 at 4:05:32 PM UTC+2 [email protected] wrote:

> Hi everyone!
>
> Im not getting the alerts generated on the server reflected on SIEM 
> dashboard.
> I followed this steps to take data from logs of an agent.
>
> https://www.alienvault.com/documentation/usm-appliance/ids-configuration/process-reading-log-file-with-hids-agent-windows.htm
>   
> Im getting the alert on alerts.log but im not able to find it on SIEM 
> dashboard.
>
> [image: image.png]
>
> I dont know if this is a policy or event correlation thing. But im not 
> clear what is the process from reciving an alert to getting reflected on 
> SIEM.
>
> Thanks and regards!
> Diego.  
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/90a105fb-ad81-438e-abb1-04ce9050eeban%40googlegroups.com.

Reply via email to