Query Regarding Sangfor EDR Log Format Compatibility with Wazuh

Newbie176014 Lv1Posted 2026-Jul-29 20:24

Hi Sangfor Support Team,

We are currently integrating Sangfor EDR with Wazuh SIEM.

During our testing, we observed that Sangfor EDR sends logs as a JSON array containing multiple JSON objects within a single syslog message. However, Wazuh 4.x expects one JSON object per log event and does not natively support decoding JSON arrays containing multiple events.

As a result, Wazuh is only able to decode the first JSON object in the array, while the remaining events are ignored.

We would like to know the following:

Is it possible to configure Sangfor EDR to send one JSON object per syslog message instead of a JSON array containing multiple objects?
Is there any option in Sangfor EDR to disable event batching and send each event individually?
Does Sangfor provide a Wazuh-compatible log format or an integration guide for Wazuh?
Are there any recommended settings or best practices for integrating Sangfor EDR with Wazuh?

Our objective is to receive each security event as an individual JSON object so that Wazuh can decode and process every event correctly without requiring custom preprocessing.

We would appreciate your guidance on whether this log format can be modified or if there is an alternative output format supported by Sangfor EDR.

Thank you for your support.

Kind regards,

Sangfor Jojo has solved this question and earned 20 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

I Can Help:

Change

Moderator on This Board

2
1
0

Started Topics

Followers

Follow

1
1
0

Started Topics

Followers

Follow

1077
227
100

Started Topics

Followers

Follow

Trending Topics

Board Leaders

Muhamma...

Weekly Sharers

Uzair A...

Weekly Questioners