We found our solution to this issue. However, our splunk dashboard is having difficulty understanding the severity level. Overtime we will fix this and update this post. The problem was that we needed to edit our inputs.conf file with the "alerts" sourcetype in the splunkforwarder: Path: /opt/splunkforwarder/etc/apps/Splunk_TA_nix_ossec/local/inputs.conf Added: [monitor:///var/ossec/logs/alerts/alerts.log] disabled = false index = ids sourcetype=alerts More information: https://uit.stanford.edu/service/ossec/install-source
... View more