I've installed Snare using the documentation available. I've checked to make sure that the device is sending to the correct IP and all of that.
The events are being sent to the Sensor and I can see them in syslog, but they don't show up in the SIEM. Any ideas?
I'm actually seeing some logs go through but they come up with the following error "ossec: Non standard syslog message (size too large)."