i'm having trouble indexing and monitoring the alerts.log file from ossec. ive tried manually adding in "/var/ossec/alerts/alerts.log" to the data inputs with source type automatic and index default but with no luck as well. when i try to search in the default search and reporting app, no alerts show up, and when i use the Reporting and Management app for OSSEC this error shows up. ive tried rebuilding the lookup table as well but no luck.
attached are screenshots showing the file data inputs and the result from regenerating the lookup table.
if anyone has any idea on how to properly setup the app please let me know.
thanks