Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16488
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Aditya Firman Nugroho
3:31 AM
Need Explain about opensearch.yml Wazuh Indexer
Dead Wazuh Team, I Need to know about opensearch.yml ( /etc/wazuh-indexer/opensearch.yml ), where i
unread,
Need Explain about opensearch.yml Wazuh Indexer
Dead Wazuh Team, I Need to know about opensearch.yml ( /etc/wazuh-indexer/opensearch.yml ), where i
3:31 AM
Chandra pal singh Chauhan
,
Victor Carlos Erenu
5
3:31 AM
Assistance Required for Viewing Backup Indices and Alert Logs in Dashboard
Hello Victor I moved those indices to an S3 bucket, and now I want to copy them to the server and
unread,
Assistance Required for Viewing Backup Indices and Alert Logs in Dashboard
Hello Victor I moved those indices to an S3 bucket, and now I want to copy them to the server and
3:31 AM
Brenno Garcia
,
Olamilekan Abdullateef Ajani
3
3:31 AM
Wazuh Multi Clients
Hello, Thank you, In this case, for each client, will a new single-node Docker stack be necessary,
unread,
Wazuh Multi Clients
Hello, Thank you, In this case, for each client, will a new single-node Docker stack be necessary,
3:31 AM
Sebastian Cuadro
,
Bony V John
6
12:10 AM
I have a problem with Wazuh alerts.
Hi, Apologies for the late response. If the issue is occurring only for a specific rule ID, I
unread,
I have a problem with Wazuh alerts.
Hi, Apologies for the late response. If the issue is occurring only for a specific rule ID, I
12:10 AM
Robby Hunters
,
Md. Nazmur Sakib
2
Apr 13
CDB List Support for IPv6
Hi Robby, Yes, CDB lists can contain IPv6 addresses and can be used to check events containing these.
unread,
CDB List Support for IPv6
Hi Robby, Yes, CDB lists can contain IPv6 addresses and can be used to check events containing these.
Apr 13
Ilsa Khan
,
hasitha.u...@wazuh.com
3
Apr 12
nquiry Regarding New Feature Addition for Ransomware Detection in Wazuh Plugin
Hi Ilsa Khan, Your approach is valid as a research/custom-extension idea, but it should be described
unread,
nquiry Regarding New Feature Addition for Ransomware Detection in Wazuh Plugin
Hi Ilsa Khan, Your approach is valid as a research/custom-extension idea, but it should be described
Apr 12
Nick
, …
hasitha.u...@wazuh.com
4
Apr 11
Email notifications
Hi Nick We are glad that your option 1 is working. In option 2, yes, you can use both. Wazuh supports
unread,
Email notifications
Hi Nick We are glad that your option 1 is working. In option 2, yes, you can use both. Wazuh supports
Apr 11
areeeba fatima
,
Olamilekan Abdullateef Ajani
5
Apr 10
Need help detecting port/network scans from FTD firewall logs
Thank you for your response. I tried the rule you shared, but it is still not triggering. Rule 100006
unread,
Need help detecting port/network scans from FTD firewall logs
Thank you for your response. I tried the rule you shared, but it is still not triggering. Rule 100006
Apr 10
exe
,
Awwal Ishiaku
4
Apr 10
Deleted duplicate index pattern, visualization now broken
In that case, let's search without the string kibana GET /_search { "_source": ["
unread,
Deleted duplicate index pattern, visualization now broken
In that case, let's search without the string kibana GET /_search { "_source": ["
Apr 10
Bayu Sangkaya (bayusky.labs)
,
hasitha.u...@wazuh.com
7
Apr 10
Agent never connected event though port 1515 and 1514 open and reachable
Hi Hashita, Sorry for the late reply This is the starting log in attachement, The agent didn't
unread,
Agent never connected event though port 1515 and 1514 open and reachable
Hi Hashita, Sorry for the late reply This is the starting log in attachement, The agent didn't
Apr 10
Chandra pal singh Chauhan
,
Olamilekan Abdullateef Ajani
3
Apr 10
Observation on Disk Consumption Pattern and Log Rotation
Hello Olamilekan, Thanks for the response and help. I have already disabled the archive and delete
unread,
Observation on Disk Consumption Pattern and Log Rotation
Hello Olamilekan, Thanks for the response and help. I have already disabled the archive and delete
Apr 10
exe
,
Bony V John
5
Apr 10
CVE should be fixed but not showing in wazuh
Hi, Apologies for the late response. If the agent is showing as inactive on the Wazuh dashboard, the
unread,
CVE should be fixed but not showing in wazuh
Hi, Apologies for the late response. If the agent is showing as inactive on the Wazuh dashboard, the
Apr 10
doc dodo
,
rodrigo....@wazuh.com
2
Apr 9
SCA check command result
Hello! I suggest you attempt using a regex that doesn't just check if the word "directories
unread,
SCA check command result
Hello! I suggest you attempt using a regex that doesn't just check if the word "directories
Apr 9
Anas Rotbi
,
Isaiah Daboh
3
Apr 9
Issue with Security Controls Display in Compliance Dashboards (NIST, HIPAA, PCI DSS, TSC, IT Hygiene)
Hello, Regarding the screenshots of the dashboard, the index pattern used in the dashboard does not
unread,
Issue with Security Controls Display in Compliance Dashboards (NIST, HIPAA, PCI DSS, TSC, IT Hygiene)
Hello, Regarding the screenshots of the dashboard, the index pattern used in the dashboard does not
Apr 9
Milene Hadil BEDOUHENE
,
Luis Enrique Chico Capistrano
4
Apr 9
Logs in archives but no alerts
Hi Milene, Thanks for your reply — we've tracked down all the issues causing your Sysmon port
unread,
Logs in archives but no alerts
Hi Milene, Thanks for your reply — we've tracked down all the issues causing your Sysmon port
Apr 9
Sandy
,
Christian Borla
2
Apr 9
Wazuh: data.dstip vs dstip mismatch (pfSense DNS exclusion)
Hi Sandy In your case, if the event is decoded with data.dstip, this could be the correct pattern:
unread,
Wazuh: data.dstip vs dstip mismatch (pfSense DNS exclusion)
Hi Sandy In your case, if the event is decoded with data.dstip, this could be the correct pattern:
Apr 9
Stefano Raspadori
,
Miguel Ángel De la Vega Rodríguez
3
Apr 9
CVE-2025-29803 patched version not excluded?
Ok, I have 3 vulnerabilities reported for same CVE: 1) Microsoft Visual Studio Tools for Applications
unread,
CVE-2025-29803 patched version not excluded?
Ok, I have 3 vulnerabilities reported for same CVE: 1) Microsoft Visual Studio Tools for Applications
Apr 9
Milene Hadil BEDOUHENE
Apr 9
Logs in Archives But No alerts
Dear Wazuh Support Team, I hope you are doing well. I am writing to report an issue with my Wazuh
unread,
Logs in Archives But No alerts
Dear Wazuh Support Team, I hope you are doing well. I am writing to report an issue with my Wazuh
Apr 9
Security xthreating
,
Stuti Gupta
2
Apr 9
Feedback on Wazuh Product Experience and Suggestions for Improvement and limitations
Hi, Security xthreatinng Glad to know you find using Wazuh interesting, and we really appreciate your
unread,
Feedback on Wazuh Product Experience and Suggestions for Improvement and limitations
Hi, Security xthreatinng Glad to know you find using Wazuh interesting, and we really appreciate your
Apr 9
Alija Nurfarizi
,
Marcel Kemp
2
Apr 9
[INQUIRY] Wazuh Agent Compatibility and Performance Optimization for Oracle Database Appliance (ODA) X9-2 HA & X9-2L
Hi Alija, I'll try to address the main questions you've raised, but please bear in mind that
unread,
[INQUIRY] Wazuh Agent Compatibility and Performance Optimization for Oracle Database Appliance (ODA) X9-2 HA & X9-2L
Hi Alija, I'll try to address the main questions you've raised, but please bear in mind that
Apr 9
exe
,
Stuti Gupta
8
Apr 9
rsyslog and Wazuh
To add to this, we are also implementing Grafana and the time (somehow) needs kafka, thats why we
unread,
rsyslog and Wazuh
To add to this, we are also implementing Grafana and the time (somehow) needs kafka, thats why we
Apr 9
Ali Bajaj
,
Md. Nazmur Sakib
10
Apr 9
Wazuh Server do not collect logs
Hello Nazmur, Everything is restored the problem was the <log_alert_level>3</log_alert_level
unread,
Wazuh Server do not collect logs
Hello Nazmur, Everything is restored the problem was the <log_alert_level>3</log_alert_level
Apr 9
Brenno Garcia
,
Md. Nazmur Sakib
2
Apr 9
Wazuh Indexer
Hi Brenno, You can migrate those indices by taking a snapshot and restoring from the snapshot. Check
unread,
Wazuh Indexer
Hi Brenno, You can migrate those indices by taking a snapshot and restoring from the snapshot. Check
Apr 9
soro pizza
,
Jorge Ardila
2
Apr 8
Vulnerability Detection is not working on some agents
Good day Soro. Just to be sure, Could you confirm the following for the affected agents: Do the
unread,
Vulnerability Detection is not working on some agents
Good day Soro. Just to be sure, Could you confirm the following for the affected agents: Do the
Apr 8
Emar Flix
,
J. Rome
2
Apr 8
Wazuh proxy server
Hello, Yes, that setup is possible. What you would need is a TCP forwarding proxy or load balancer,
unread,
Wazuh proxy server
Hello, Yes, that setup is possible. What you would need is a TCP forwarding proxy or load balancer,
Apr 8
German DiCasas
,
Olamilekan Abdullateef Ajani
4
Apr 8
wauzh requirements
Hello German, There is no hard limit. You can give an all-in-one more resources, and it will work
unread,
wauzh requirements
Hello German, There is no hard limit. You can give an all-in-one more resources, and it will work
Apr 8
Jack Martin
,
Bony V John
5
Apr 8
Clarification on Active Response Scalability in Wazuh EDR
Dear Sir, Thank you for your guidance in resolving the Wazuh issue. Your support helped me solve the
unread,
Clarification on Active Response Scalability in Wazuh EDR
Dear Sir, Thank you for your guidance in resolving the Wazuh issue. Your support helped me solve the
Apr 8
Stefano Raspadori
,
Stuti Gupta
7
Apr 8
Veeam Backup & Replication vulnerabilities not updated after patching
You are right, and this is the reason why you are still seeing the old version-related vulnerability
unread,
Veeam Backup & Replication vulnerabilities not updated after patching
You are right, and this is the reason why you are still seeing the old version-related vulnerability
Apr 8
Brenno Garcia
,
hasitha.u...@wazuh.com
4
Apr 8
Wazuh Proxy?
Hi Brenno At the moment, I could not find this exact configuration described in the documentation.
unread,
Wazuh Proxy?
Hi Brenno At the moment, I could not find this exact configuration described in the documentation.
Apr 8
Max
,
Ayooluwa Paul Akindeko
9
Apr 8
Wazuh Multi Tenancy inquiry
- In order to backup your logs, You can configure <syslog_output> blocks in ossec.conf to
unread,
Wazuh Multi Tenancy inquiry
- In order to backup your logs, You can configure <syslog_output> blocks in ossec.conf to
Apr 8