Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16377
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
David Brindley
2
5:56 PM
Custom rule not applying proper rule level
Sorry for the confusion. After some further research, I realized I was missing the "overwrite
unread,
Custom rule not applying proper rule level
Sorry for the confusion. After some further research, I realized I was missing the "overwrite
5:56 PM
Julien Bard
,
Juan Sebastián Saldarriaga Arango
2
4:25 PM
Dashboard errors
Hi, this error is from the OpenSearch parent circuit breaker, not the Dashboard itself. From your log
unread,
Dashboard errors
Hi, this error is from the OpenSearch parent circuit breaker, not the Dashboard itself. From your log
4:25 PM
elferdaous Mejhed
,
Olamilekan Abdullateef Ajani
3
2:18 PM
Duplicate Agent on Ubuntu-22 (one active, one disconnected) – How to clean it up?
Merci , Je veux savoir si les modifications dans les fichiers dans cet agent et toutes les
unread,
Duplicate Agent on Ubuntu-22 (one active, one disconnected) – How to clean it up?
Merci , Je veux savoir si les modifications dans les fichiers dans cet agent et toutes les
2:18 PM
Chandra pal singh Chauhan
,
Gustavo Choquevilca
2
2:05 PM
Security Hub Logs Not Appearing in Wazuh Dashboard
Hi Chandra, Thank you for the detailed report. The log shows the module is running and completing the
unread,
Security Hub Logs Not Appearing in Wazuh Dashboard
Hi Chandra, Thank you for the detailed report. The log shows the module is running and completing the
2:05 PM
никита какдела
,
Isaiah Daboh
6
9:04 AM
Monitor performance
I got this response: { "took": 37, "timed_out": false, "_shards": {
unread,
Monitor performance
I got this response: { "took": 37, "timed_out": false, "_shards": {
9:04 AM
Suvadip Ghosh
6:13 AM
AWS VPC Flow Logs & AWS nlb logs are not coming in WAZUH UI
Dear Team, While integrating AWS services like AWS nlb & AWS VPC I am facing some issue with the
unread,
AWS VPC Flow Logs & AWS nlb logs are not coming in WAZUH UI
Dear Team, While integrating AWS services like AWS nlb & AWS VPC I am facing some issue with the
6:13 AM
CRIZ
,
hasitha.u...@wazuh.com
7
6:13 AM
Clarification on CDB Value Limits
Hi Hasitha, Thanks for the response, Is it possible to make the matching case-insensitive instead of
unread,
Clarification on CDB Value Limits
Hi Hasitha, Thanks for the response, Is it possible to make the matching case-insensitive instead of
6:13 AM
Miran Ul Haq
,
Awwal Ishiaku
2
2:46 AM
No Logs after Upgrade on Wazuh Dashboard
Hi Miran, Please show the status of the central components: systemctl status wazuh-manager systemctl
unread,
No Logs after Upgrade on Wazuh Dashboard
Hi Miran, Please show the status of the central components: systemctl status wazuh-manager systemctl
2:46 AM
Emar Flix
,
Md. Nazmur Sakib
6
Mar 3
Changing Wazuh GUI password
Thank you for your answer, Mr. Nazmur. You know I have two cluster and between them there is CCR (PR
unread,
Changing Wazuh GUI password
Thank you for your answer, Mr. Nazmur. You know I have two cluster and between them there is CCR (PR
Mar 3
IT Linguaserve
,
Olamilekan Abdullateef Ajani
4
Mar 3
Sending alerts to third party apps
Hello Sistemas, I am not sure how you have programmed this into your script, but the hook_url is
unread,
Sending alerts to third party apps
Hello Sistemas, I am not sure how you have programmed this into your script, but the hook_url is
Mar 3
DIWAHAR RAHAWID
,
Md. Nazmur Sakib
2
Mar 3
FIM Issue
Hello Diwahar, We have encountered similar errors in versions prior to 4.14.0 when real-time FIM was
unread,
FIM Issue
Hello Diwahar, We have encountered similar errors in versions prior to 4.14.0 when real-time FIM was
Mar 3
Robby Hunters
,
Md. Nazmur Sakib
4
Mar 3
Office365 GeoLocation Rule Not Triggering
In case the field is an IP address, you must use not_address_match_key Ref: Negative key match On
unread,
Office365 GeoLocation Rule Not Triggering
In case the field is an IP address, you must use not_address_match_key Ref: Negative key match On
Mar 3
Max Kirshin
,
Ian Yenien Serrano
4
Mar 3
Centralized configuration
Sorry, I can't manage to run it inside the docker container bash-5.2# systemctl status wazuh-
unread,
Centralized configuration
Sorry, I can't manage to run it inside the docker container bash-5.2# systemctl status wazuh-
Mar 3
Facu Basgall
,
Olamilekan Abdullateef Ajani
2
Mar 2
CDB List for IP ranges
Hello Facub, Based on the documentation, CDBList support for IP addresses is prefix-based matching
unread,
CDB List for IP ranges
Hello Facub, Based on the documentation, CDBList support for IP addresses is prefix-based matching
Mar 2
Майкл Миколайович
,
juan.c...@wazuh.com
2
Mar 2
Audit Wazuh Dahboard users
Hi Майкл, it's possible that some of the audit categories required for login, privilege
unread,
Audit Wazuh Dahboard users
Hi Майкл, it's possible that some of the audit categories required for login, privilege
Mar 2
Dmitry Mikheev
,
Stuti Gupta
16
Mar 2
Duplicate agent name:
Hi Dirmit Please allow me some time. I'm discussing this issue with the teammate. They are
unread,
Duplicate agent name:
Hi Dirmit Please allow me some time. I'm discussing this issue with the teammate. They are
Mar 2
Denis Grilli
,
Federico Gustavo Caffieri
5
Mar 2
Error changing the selected API - wazuh-dashboard
Hi Federico, thanks again for your useful and very detailed reply. From the wazuh dashboard journal I
unread,
Error changing the selected API - wazuh-dashboard
Hi Federico, thanks again for your useful and very detailed reply. From the wazuh dashboard journal I
Mar 2
Roman
,
Stuti Gupta
9
Mar 2
Rule only works for limited number of events
Hi, Yes, for once a week its good, but what if we have a task with period in days: once in 2 days,
unread,
Rule only works for limited number of events
Hi, Yes, for once a week its good, but what if we have a task with period in days: once in 2 days,
Mar 2
Roman
,
Bony V John
6
Mar 2
Alerts files stop archiving
Ok, thank you for detailed answer. We'll try to give wazuh vm more memory first and then try your
unread,
Alerts files stop archiving
Ok, thank you for detailed answer. We'll try to give wazuh vm more memory first and then try your
Mar 2
m mun
,
Nikhil Gurjar
3
Mar 2
DATA MASKING IN WAZUH
Hi Team, Yes, your understanding is correct. If the <options>no_full_log</options>
unread,
DATA MASKING IN WAZUH
Hi Team, Yes, your understanding is correct. If the <options>no_full_log</options>
Mar 2
流苏
,
Md. Nazmur Sakib
2
Mar 2
Subject: Inquiry Regarding Filebeat 7.10.2 Vulnerability (CVE-2025-68381/68382/68383) in Wazuh 4.12 and Fix Status in Latest Releases
Hi Sihan, Wazuh manager uses Filebeat to process and forward the logs from the Wazuh Manager to the
unread,
Subject: Inquiry Regarding Filebeat 7.10.2 Vulnerability (CVE-2025-68381/68382/68383) in Wazuh 4.12 and Fix Status in Latest Releases
Hi Sihan, Wazuh manager uses Filebeat to process and forward the logs from the Wazuh Manager to the
Mar 2
Yogi Valentino
,
hasitha.u...@wazuh.com
2
Mar 1
Wazuh Syscolector (Not Enough Hardware or Operating System Information)
Hi Yogi, The Syscollector module is responsible for collecting endpoint details such as hardware,
unread,
Wazuh Syscolector (Not Enough Hardware or Operating System Information)
Hi Yogi, The Syscollector module is responsible for collecting endpoint details such as hardware,
Mar 1
Henry Valero
,
hasitha.u...@wazuh.com
7
Feb 28
Remote command execution is not working on Wazuh 4.14.3
Hi Henry, I suggested checking on the agent side because this issue seems to be specific to Windows
unread,
Remote command execution is not working on Wazuh 4.14.3
Hi Henry, I suggested checking on the agent side because this issue seems to be specific to Windows
Feb 28
никита какдела
,
Olamilekan Abdullateef Ajani
4
Feb 27
Wazuh Reporting
Hello Bless, As I mentioned earlier, this works more as a borrowed functionality from opensearchCLI;
unread,
Wazuh Reporting
Hello Bless, As I mentioned earlier, this works more as a borrowed functionality from opensearchCLI;
Feb 27
Domenica Wairimu
,
Bony V John
3
Feb 27
Sophos Decoders Issue
Hi, Based on the three logs you shared, I created a custom Sophos decoder and some basic rules to
unread,
Sophos Decoders Issue
Hi, Based on the three logs you shared, I created a custom Sophos decoder and some basic rules to
Feb 27
Dale Cooper
,
Stuti Gupta
2
Feb 27
Help needed: FortiOS v7.x logs breaking Wazuh decoders (os_regex quoting issue)
Hi Dale You can resolve this issue by changing the existing default decoder. Start by copying the
unread,
Help needed: FortiOS v7.x logs breaking Wazuh decoders (os_regex quoting issue)
Hi Dale You can resolve this issue by changing the existing default decoder. Start by copying the
Feb 27
YASHWANTH S
,
Himanshu Sharma
2
Feb 27
Request for Guidance on ClamAV Integration with Wazuh for Malware Detection
Hi Team, Wazuh detects malicious files through integration with ClamAV, a free and open-source
unread,
Request for Guidance on ClamAV Integration with Wazuh for Malware Detection
Hi Team, Wazuh detects malicious files through integration with ClamAV, a free and open-source
Feb 27
Robby Hunters
,
Md. Nazmur Sakib
5
Feb 26
wazuh-modulesd WARNING Response buffer size limit reached.
The warning "Response buffer size limit reached" comes from the WriteMemoryCallback
unread,
wazuh-modulesd WARNING Response buffer size limit reached.
The warning "Response buffer size limit reached" comes from the WriteMemoryCallback
Feb 26
Steeven Sánchez
,
Javier Adán Méndez Méndez
2
Feb 26
Docker logs error
Hi Steeven This behavior usually comes from how n8n writes the file, not from the Wazuh path/
unread,
Docker logs error
Hi Steeven This behavior usually comes from how n8n writes the file, not from the Wazuh path/
Feb 26
CRiaks
,
Md. Nazmur Sakib
3
Feb 26
Extract value from CDB list
Hi Nazmur, Thank you for reply. I rephrase my issue. Context: Several users use the same account to
unread,
Extract value from CDB list
Hi Nazmur, Thank you for reply. I rephrase my issue. Context: Several users use the same account to
Feb 26