On every docker host, run a log-pilot instance. Log-pilot will monitor docker events, and parse log labels on new docker conatainer, and generate appropriate log configuration and notify fluentd or ...
I have configured the azure (azure-logs) module as follows in my ossec.conf : <wodle name="azure-logs"> <disabled>no</disabled> <run_on_start>yes</run_on_start ...