That shouldn't be a problem, really. Our default integration looks like this:
input {
file {
type => "wazuh-alerts"
path => "/var/ossec/logs/alerts/alerts.json"
codec => "json"
}
}
So parser on localhost with Wazuh is monitoring the files. In your case, if Wazuh is writing to multiple files at once and then rotating them, that would look something like this:
input {
file {
type => "wazuh-alerts"
path => "/var/ossec/logs/alerts/*/*/*.json"
codec => "json"
}
}
Not 100% if it would work as copy and paste, but if you like, we can run some test and see what will come out of this.