Typo, that should have been source=alerts.log. Try the search by eventtype (added to answer above) as well, but if sourcetype=ossec returns events, then it sounds like you are getting data. Be aware that some dashboards require setup, but the "OSSEC Dashboard" and "OSSEC Event Search" should be fine if you can see events. If you are still having problems, can you be more specific about what's not working?
... View more