Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 15594
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Bayu Sangkaya (bayusky.labs)
,
Henadence Anyam
2
9:37 AM
Vcenter decoders
Hi Bayu Sangkaya, Your children decoders should use the same name. For example, I have changed the
unread,
Vcenter decoders
Hi Bayu Sangkaya, Your children decoders should use the same name. For example, I have changed the
9:37 AM
Paulo Ricardo Bruck
9:14 AM
35748 Ensure kernel module loading unloading and modification is collected
Hi Ubuntu 24.04 ands wazuh 4.12.0-1 At my dashboard this rule is marked as failed. my rule: # cat /
unread,
35748 Ensure kernel module loading unloading and modification is collected
Hi Ubuntu 24.04 ands wazuh 4.12.0-1 At my dashboard this rule is marked as failed. my rule: # cat /
9:14 AM
Paulo Ricardo Bruck
,
hasitha.u...@wazuh.com
3
9:14 AM
35775 Ensure audit tools mode is configured.
Hy Hashita after removing 755 and restarting rule is ok now. thanks I open a ticket at git hub 😁 Em
unread,
35775 Ensure audit tools mode is configured.
Hy Hashita after removing 755 and restarting rule is ok now. thanks I open a ticket at git hub 😁 Em
9:14 AM
Anand Kumar
9:14 AM
Custom Decoders Configuration
Dear Team, I want to achieve a specific log format that makes it easier to run queries. Since we have
unread,
Custom Decoders Configuration
Dear Team, I want to achieve a specific log format that makes it easier to run queries. Since we have
9:14 AM
Basim Ibrahim
2:29 AM
Wazuh not getting installed
Hi Team, wazuh agent is not getting installed in my endpoint, this was installed before (6 months)
unread,
Wazuh not getting installed
Hi Team, wazuh agent is not getting installed in my endpoint, this was installed before (6 months)
2:29 AM
Dex Perry
,
Bony V John
3
Sep 6
Fortigate Syslog Not Showing in Wazuh Dashboard (Packets Seen via Tcpdump)
Hi Bony, Thanks for your earlier guidance — it helped a lot. I've confirmed that FortiGate logs
unread,
Fortigate Syslog Not Showing in Wazuh Dashboard (Packets Seen via Tcpdump)
Hi Bony, Thanks for your earlier guidance — it helped a lot. I've confirmed that FortiGate logs
Sep 6
Amin
,
Javier Medeot
2
Sep 5
Recommended Kubernetes Architecture
Hi Amin. Your proposed architecture sounds right for your environment. Running Wazuh on Kubernetes
unread,
Recommended Kubernetes Architecture
Hi Amin. Your proposed architecture sounds right for your environment. Running Wazuh on Kubernetes
Sep 5
Romain Hennebois
,
esteban...@wazuh.com
2
Sep 5
Optimisation helps
Hello Romain , This is not an standard way to do it , but what i really suggest you maybe it would be
unread,
Optimisation helps
Hello Romain , This is not an standard way to do it , but what i really suggest you maybe it would be
Sep 5
felixm
,
Nicolas Zapata
3
Sep 4
Clean up after removing indexes from dash board
Additionally, if the indexes are being deleted manually from the dashboard, it would be advisable to
unread,
Clean up after removing indexes from dash board
Additionally, if the indexes are being deleted manually from the dashboard, it would be advisable to
Sep 4
bilal
,
Olamilekan Abdullateef Ajani
2
Sep 4
Monitor renamed fils on windows
Hello Bilal, This is possible with the use of wazuh FIM with the aid of syscheck. When you have a
unread,
Monitor renamed fils on windows
Hello Bilal, This is possible with the use of wazuh FIM with the aid of syscheck. When you have a
Sep 4
Rei Gjata
,
Stuti Gupta
3
Sep 4
Filebeat not creating Indexes
Hi Stuti Its an all in one environment , version 4.11.2 Output of the cluster health ----------------
unread,
Filebeat not creating Indexes
Hi Stuti Its an all in one environment , version 4.11.2 Output of the cluster health ----------------
Sep 4
Facu Basgall
,
Juan Felipe González Ortiz
9
Sep 4
Slow performance with LDAP user.
Hi, most likely the poor performance is due to the users and groups issue. I'm going to set up an
unread,
Slow performance with LDAP user.
Hi, most likely the poor performance is due to the users and groups issue. I'm going to set up an
Sep 4
Felix Andorfer
,
Olamilekan Abdullateef Ajani
6
Sep 3
Agent reconnect issue when switching networks
Hello Felix, Based on my test, you should not get so many warnings and so much information from the
unread,
Agent reconnect issue when switching networks
Hello Felix, Based on my test, you should not get so many warnings and so much information from the
Sep 3
Facu Basgall
,
Olamilekan Abdullateef Ajani
2
Sep 3
Modify rules by agent
Hello, One way to do this is if you have a specific field in the alert that is commong to all or some
unread,
Modify rules by agent
Hello, One way to do this is if you have a specific field in the alert that is commong to all or some
Sep 3
Henry Valero
,
Md. Nazmur Sakib
4
Sep 3
Error in the dashboard, the data is not displayed
Hello Nazmur, I made the suggested changes and ran the indicated commands, these are the results of
unread,
Error in the dashboard, the data is not displayed
Hello Nazmur, I made the suggested changes and ran the indicated commands, these are the results of
Sep 3
Gokul Suresh
Sep 3
Azure Load balancer integration with wazuh
Hi team, I have to integrate azure load balancer logs into wazuh for monitoring. I have to monitor
unread,
Azure Load balancer integration with wazuh
Hi team, I have to integrate azure load balancer logs into wazuh for monitoring. I have to monitor
Sep 3
Yossif Helmy
,
Benjamin Nworah
9
Sep 3
Fields not being refreshed
Thank you, Benjamin. I would like to close the ticket. On Wednesday, September 3, 2025 at 4:00:40 PM
unread,
Fields not being refreshed
Thank you, Benjamin. I would like to close the ticket. On Wednesday, September 3, 2025 at 4:00:40 PM
Sep 3
Singh Satish
,
Md. Nazmur Sakib
3
Sep 3
child decoder of windows_eventchannel
Based on my findings at this moment, it is not possible to write sibling decoders for the Windows
unread,
child decoder of windows_eventchannel
Based on my findings at this moment, it is not possible to write sibling decoders for the Windows
Sep 3
하프사
,
ismail....@wazuh.com
2
Sep 3
Custom Log Storage & Alerting on Disk Usage in Lab
Hi, Wazuh generates several internal log files, including alerts.log, archives.log, alerts.json, and
unread,
Custom Log Storage & Alerting on Disk Usage in Lab
Hi, Wazuh generates several internal log files, including alerts.log, archives.log, alerts.json, and
Sep 3
Julio Cesar
,
diego....@wazuh.com
5
Sep 3
Combining pfSense Agent and Syslog Log Collection
Hi, That configuration is performed in Suricata. Wazuh is now configured to receive the logs you
unread,
Combining pfSense Agent and Syslog Log Collection
Hi, That configuration is performed in Suricata. Wazuh is now configured to receive the logs you
Sep 3
Aayush Shrivastava
,
Adedamola Okelola
6
Sep 3
Agent Communication
still the same issue I deployed the new wazuh instance but the issue remanis same Connected 50+
unread,
Agent Communication
still the same issue I deployed the new wazuh instance but the issue remanis same Connected 50+
Sep 3
stefanny chavez anto
,
Javier Rosas
6
Sep 2
ERROR: CANNOT INITIALIZE WAZUH INDEXER CLUSTER
Mira que en la documentación que me mandas del quick start indica que se necesitan al menos 8 GB de
unread,
ERROR: CANNOT INITIALIZE WAZUH INDEXER CLUSTER
Mira que en la documentación que me mandas del quick start indica que se necesitan al menos 8 GB de
Sep 2
Facu Basgall
,
Héctor Gómez
5
Sep 2
Problem installing the agent.
Did you have any luck with this? Were you able to install the agent? On Thursday, August 28, 2025 at
unread,
Problem installing the agent.
Did you have any luck with this? Were you able to install the agent? On Thursday, August 28, 2025 at
Sep 2
Leonardo Ventura
,
Rolly Davany Mougoue Kakanou
2
Sep 2
MISP Integration help
Hello Leonardo, Could you please share the complete alert, ensuring that any sensitive information is
unread,
MISP Integration help
Hello Leonardo, Could you please share the complete alert, ensuring that any sensitive information is
Sep 2
Lucas
,
Leonardo López
4
Sep 2
CloudTrail Log Collection to Central S3 (Log Archive Account) Is Failing
Hello Lucas, I don't think that the issue is the bucket name, but try it if you can. Can you
unread,
CloudTrail Log Collection to Central S3 (Log Archive Account) Is Failing
Hello Lucas, I don't think that the issue is the bucket name, but try it if you can. Can you
Sep 2
avkby445h 24
,
Olamilekan Abdullateef Ajani
2
Sep 2
Cisco-ASA default decoder and rules not working
Hello, If I understand you clearly, you mean the logs are not decoded properly. I feel the way you
unread,
Cisco-ASA default decoder and rules not working
Hello, If I understand you clearly, you mean the logs are not decoded properly. I feel the way you
Sep 2
ShtrudelMan
,
Md. Nazmur Sakib
14
Sep 2
Restoring old logs in the Wazuh Dashboard
Good afternoon! The problem is solved. I did not specify the parameters correctly when running the
unread,
Restoring old logs in the Wazuh Dashboard
Good afternoon! The problem is solved. I did not specify the parameters correctly when running the
Sep 2
Jorge Moya Albarran
,
Isaac Yusuf
2
Sep 2
Close Indexes
Hello, There is no option to configure a "Close" in the Index Lifecycle Management. But
unread,
Close Indexes
Hello, There is no option to configure a "Close" in the Index Lifecycle Management. But
Sep 2
German DiCasas
,
Alberto Marcelino Zárate
3
Sep 2
LDAP user access issue
How can I avoid that the user login? I mean, How is the configuration to check only if the user is
unread,
LDAP user access issue
How can I avoid that the user login? I mean, How is the configuration to check only if the user is
Sep 2
chachab
, …
Singh Satish
7
Sep 2
Help Decoder for MS SQL eventchannel - Application
Hi, Can you please share what exact you did to resolve above issue. On Thursday, June 5, 2025 at 3:41
unread,
Help Decoder for MS SQL eventchannel - Application
Hi, Can you please share what exact you did to resolve above issue. On Thursday, June 5, 2025 at 3:41
Sep 2