I'm sending OSSEC logs via syslog. All OSSEC logs are indexed and can be found using search, but all OSSEC dashboards are empty. Why is that?
In your ossec.conf, please make sure that your log format is default not splunk or any other thing.
...
default
...
In your ossec.conf, please make sure that your log format is default not splunk or any other thing.
...
default
...
This is correct. The "splunk" option in ossec.conf was added by someone else long after the Splunk management app for OSSEC was written, and it does not follow the same logic. Counterintuitive though it may seem, using the "splunk" output option in ossec.conf is not recommended.
The other common source of this problem is if sourcetype is not set correctly for the incoming OSSEC logs.