Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16231
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
никита какдела
,
musbau....@wazuh.com
19
7:40 AM
Per Bucket monitor Error.
{ "error": "no handler found for uri [/_plugins/_alerting/alerts/_search] and method [
unread,
Per Bucket monitor Error.
{ "error": "no handler found for uri [/_plugins/_alerting/alerts/_search] and method [
7:40 AM
Ricardo Barros
,
Md. Nazmur Sakib
3
7:40 AM
No cached mapping for this field. Refresh field list
I have already completed this activity, but I was not successful. Em quinta-feira, 22 de janeiro de
unread,
No cached mapping for this field. Refresh field list
I have already completed this activity, but I was not successful. Em quinta-feira, 22 de janeiro de
7:40 AM
Slavica SL
7:40 AM
CEF Format Decoder Needed_Safeguard log
Hello all, I have a safeguard log for which I need to create a wazuh decoder, but I only manage to
unread,
CEF Format Decoder Needed_Safeguard log
Hello all, I have a safeguard log for which I need to create a wazuh decoder, but I only manage to
7:40 AM
exe
,
Pablo Moliz Arias
12
7:06 AM
Vulnerability Detection List not updating
Hello Pablo, in the meantime i fixed the issue. It was a network problem, the docker container had
unread,
Vulnerability Detection List not updating
Hello Pablo, in the meantime i fixed the issue. It was a network problem, the docker container had
7:06 AM
никита какдела
7:06 AM
Per_bucket monitor performance
Hi! I've noticed that sometimes I don't receive a notification for a triggered alert, meaning
unread,
Per_bucket monitor performance
Hi! I've noticed that sometimes I don't receive a notification for a triggered alert, meaning
7:06 AM
Andrehens Chicfici
,
Cedrick Foko
2
7:02 AM
Vulnerability Scanner triggering hundreds of false positives at the same tim
Hello, The issue you describe is caused by one of the followings: There are multiple versions of the
unread,
Vulnerability Scanner triggering hundreds of false positives at the same tim
Hello, The issue you describe is caused by one of the followings: There are multiple versions of the
7:02 AM
Facu Basgall
,
Luis Enrique Chico Capistrano
13
6:42 AM
Help with a rule
Thank you for your response. Similarly it does not work for me to make a single rule for each case,
unread,
Help with a rule
Thank you for your response. Similarly it does not work for me to make a single rule for each case,
6:42 AM
Yazid
,
Richmond Aribibia Fimie
10
6:28 AM
Wazuh / Symentec Integration
Hello @Yazid Thank you for sharing the results, I'll run some tests on my end to validate the
unread,
Wazuh / Symentec Integration
Hello @Yazid Thank you for sharing the results, I'll run some tests on my end to validate the
6:28 AM
mariano hinjos
,
Dennis Ariel Gamboa Veliz
4
6:27 AM
Threat Hunting is empty
Hi mariano, This is expected behavior. Wazuh creates daily alert indices (wazuh-alerts-4.x-YYYY.MM.DD
unread,
Threat Hunting is empty
Hi mariano, This is expected behavior. Wazuh creates daily alert indices (wazuh-alerts-4.x-YYYY.MM.DD
6:27 AM
Gabriele Ventura
,
Natalia Castillo
5
5:52 AM
Wazuh quickstart works initially but dashboard loses events over time on small single-node setup (disk pressure?)
Hi Natalia, Thanks, this clarifies a lot and matches what I observed in practice. I appreciate the
unread,
Wazuh quickstart works initially but dashboard loses events over time on small single-node setup (disk pressure?)
Hi Natalia, Thanks, this clarifies a lot and matches what I observed in practice. I appreciate the
5:52 AM
Bayu Sangkaya (bayusky.labs)
,
Stuti Gupta
3
5:34 AM
Always invalid parent
Hi Stuti, this is the log {"schemaVersion": "1.21", "id": "WB-
unread,
Always invalid parent
Hi Stuti, this is the log {"schemaVersion": "1.21", "id": "WB-
5:34 AM
Muhammad Ali Khan
,
Hossam El Amraoui
5
4:27 AM
Decoder Pre-match issue
I have modified the decoders to adapt them well. The decoders should look like this: ``` <decoder
unread,
Decoder Pre-match issue
I have modified the decoders to adapt them well. The decoders should look like this: ``` <decoder
4:27 AM
doc dodo
,
John Adewale Olatunde
11
3:30 AM
AD control cinfiguration with SCA
Hello, John. Yes, OS language is English. Debug logs show empty result of the command: 2026/01/22 11:
unread,
AD control cinfiguration with SCA
Hello, John. Yes, OS language is English. Debug logs show empty result of the command: 2026/01/22 11:
3:30 AM
wazuh
,
Federico Gustavo Galland
7
3:15 AM
Tracking MFA enable/disable events through MS-graph integration
Hi again, i was finally able to get my hands on a test environment for this issue. so now with the
unread,
Tracking MFA enable/disable events through MS-graph integration
Hi again, i was finally able to get my hands on a test environment for this issue. so now with the
3:15 AM
David Lima
,
josue....@wazuh.com
2
1:10 AM
No Integratord logs
Hi David, To help us confirm the behavior you're observing, could you please help us validate the
unread,
No Integratord logs
Hi David, To help us confirm the behavior you're observing, could you please help us validate the
1:10 AM
Ham Somalyvann
,
Bony V John
3
1:03 AM
Monitoring Email Security and Phishing Detection
Hi, Wazuh can help detect phishing emails by correlating email-related events with threat
unread,
Monitoring Email Security and Phishing Detection
Hi, Wazuh can help detect phishing emails by correlating email-related events with threat
1:03 AM
никита какдела
,
Md. Nazmur Sakib
6
12:43 AM
New SCA policies
This can happen due to a connectivity issue or if the agent cannot properly communicate with the
unread,
New SCA policies
This can happen due to a connectivity issue or if the agent cannot properly communicate with the
12:43 AM
DK
,
Julián Morales
3
12:23 AM
ruleset hot reload problem
Hi, Julián Morales! I change level and description in custom rule, save and reload. With "Mange
unread,
ruleset hot reload problem
Hi, Julián Morales! I change level and description in custom rule, save and reload. With "Mange
12:23 AM
DK
Jan 21
rulest hot reload problem
Hello! I updated wazuh to version 4.14.2 and encountered an issue when changing rules. When I change
unread,
rulest hot reload problem
Hello! I updated wazuh to version 4.14.2 and encountered an issue when changing rules. When I change
Jan 21
Joaquim António
,
Isaiah Daboh
10
Jan 21
Can't get ms-graph to obtain logs
Hello, After changing the frequency of the queries, from <interval>5m</interval> to <
unread,
Can't get ms-graph to obtain logs
Hello, After changing the frequency of the queries, from <interval>5m</interval> to <
Jan 21
Jacob Molland
,
raul....@wazuh.com
4
Jan 21
Using Keycloak as an IdP
Hi jacob As you mentioned earlier, you followed the https://documentation.wazuh.com/current/user-
unread,
Using Keycloak as an IdP
Hi jacob As you mentioned earlier, you followed the https://documentation.wazuh.com/current/user-
Jan 21
German DiCasas
,
juanjos...@wazuh.com
6
Jan 21
Alerts Logs
Hi German You can follow https://wazuh.com/blog/recover-your-data-using-wazuh-alert-backups/ the same
unread,
Alerts Logs
Hi German You can follow https://wazuh.com/blog/recover-your-data-using-wazuh-alert-backups/ the same
Jan 21
Facu Basgall
,
Nicolas Stefani
3
Jan 21
Help with custom Windows rule
The rule 101806 works fine as I sent it and no match is necessary. The following rules do not work
unread,
Help with custom Windows rule
The rule 101806 works fine as I sent it and no match is necessary. The following rules do not work
Jan 21
HALELUJAH
,
Nicolás Edgardo Rocca
2
Jan 21
Can not save rule file after edit
Hi, We'll need a little more information about the rule you're trying to create and how you
unread,
Can not save rule file after edit
Hi, We'll need a little more information about the rule you're trying to create and how you
Jan 21
Nyengka Prosper
,
Federico Gustavo Caffieri
2
Jan 21
macOS FIM rules causing the cluster crash after a configuration(modifying a rule file) modification is made
The timeout and cluster crashes you're experiencing with custom FIM rules in 4.13.1 could be
unread,
macOS FIM rules causing the cluster crash after a configuration(modifying a rule file) modification is made
The timeout and cluster crashes you're experiencing with custom FIM rules in 4.13.1 could be
Jan 21
David Lima
,
Ifeanyi Onyia Odike
7
Jan 21
Custom Fortimail Rule not abiding by the 200 frequency option
Hi David Regarding your question: "Do you have any tips on how to extract each TO field from
unread,
Custom Fortimail Rule not abiding by the 200 frequency option
Hi David Regarding your question: "Do you have any tips on how to extract each TO field from
Jan 21
Yogi Valentino
,
hasitha.u...@wazuh.com
3
Jan 21
Wazuh Sysmon Installation Detection
Hi Yogi, I've tested this rule and identified the problem. The regex type isn't defined in
unread,
Wazuh Sysmon Installation Detection
Hi Yogi, I've tested this rule and identified the problem. The regex type isn't defined in
Jan 21
Robby Hunters
,
hasitha.u...@wazuh.com
3
Jan 21
Question regarding upgrade from Wazuh v4.14.1 to v4.14.2
Hi Hashita, Thanks for the info. Just to confirm, if I take a full VM snapshot of the Wazuh server,
unread,
Question regarding upgrade from Wazuh v4.14.1 to v4.14.2
Hi Hashita, Thanks for the info. Just to confirm, if I take a full VM snapshot of the Wazuh server,
Jan 21
CJK
,
Benjamin Nworah
5
Jan 21
Delay in AWS log fetching on services without even high EPS - "aws-s3" woodle
Hi Banjamin, Thanks, That helps. Will try the same. Does this multiple wodle support on other wodles
unread,
Delay in AWS log fetching on services without even high EPS - "aws-s3" woodle
Hi Banjamin, Thanks, That helps. Will try the same. Does this multiple wodle support on other wodles
Jan 21
Robby Hunters
, …
Matías Exequiel García
8
Jan 21
Vulnerability Detection not detect All Agent
Hi Marias, Okay that's enough for me, Thank you for your asisstance. Regards, Robby On Tuesday,
unread,
Vulnerability Detection not detect All Agent
Hi Marias, Okay that's enough for me, Thank you for your asisstance. Regards, Robby On Tuesday,
Jan 21