You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This documentation issue aims to detail the addition of the journald log format to the localfile configuration in Wazuh's Logcollector. It will cover the configuration specifics, including the support for multiple <localfile> blocks, filtering options, and the logic applied when merging these blocks.
Objectives
Document journald Configuration: Provide comprehensive documentation on configuring journald log collection through the localfile tag in ossec.conf.
Explain Multiple Blocks Handling: Clarify how multiple configuration blocks for journald logs are parsed and applied, emphasizing the OR logic between blocks and the precedence of certain settings.
Detail Filtering Options: Describe the filtering capabilities within <localfile> blocks, including the use of PCRE2 regex for selective log collection.
Configuration Examples: Offer practical examples of journald log collection configurations to aid users in setting up their environments.
Tasks
Write documentation sections for the journald log format configuration within localfile.
Explain the logic of merging multiple <localfile> blocks for journald, including logical operations and setting precedence.
Provide clear examples of configurations for collecting journald logs with various filters and settings.
Review and validate the documentation for accuracy and clarity.
Acceptance Criteria
The documentation accurately reflects the new journald log format configuration options in Logcollector.
Users can easily understand how to configure multiple journald log sources and apply filters.
The documentation includes examples that are practical and applicable to common use cases.
The text was updated successfully, but these errors were encountered:
Description
This documentation issue aims to detail the addition of the
journald
log format to thelocalfile
configuration in Wazuh's Logcollector. It will cover the configuration specifics, including the support for multiple<localfile>
blocks, filtering options, and the logic applied when merging these blocks.Objectives
journald
Configuration: Provide comprehensive documentation on configuringjournald
log collection through thelocalfile
tag inossec.conf
.journald
logs are parsed and applied, emphasizing the OR logic between blocks and the precedence of certain settings.<localfile>
blocks, including the use of PCRE2 regex for selective log collection.journald
log collection configurations to aid users in setting up their environments.Tasks
journald
log format configuration withinlocalfile
.<localfile>
blocks forjournald
, including logical operations and setting precedence.journald
logs with various filters and settings.Acceptance Criteria
journald
log format configuration options in Logcollector.journald
log sources and apply filters.The text was updated successfully, but these errors were encountered: