Search log decoders
wazuh_list_decodersSearch decoders to inspect how raw logs are parsed into fields. Use when alert fields are missing or incorrect to diagnose parsing issues.
Instructions
Search the decoders that parse raw logs into fields. Use this when an alert's fields look wrong or absent, to see how a log source is being parsed.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| offset | No | ||
| search | No | Free-text substring match. | |
| status | No | ||
| filename | No | Decoder file name. | |
| decoder_names | No | Specific decoder names, e.g. ['sshd']. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||