Have you seen this message on the master and workers? How did you detect that it has not been updated?
--
You received this message because you are subscribed to the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/6178da01-634c-45d0-a3d1-9c16b23f4ea9n%40googlegroups.com.
I see that in the master you have the logs for `Reloading ruleset` and `INFO Ruleset reloaded successfully`, but you didn't share them in the workers.
It may take a while for the workers to synchronize, but eventually you should see those logs.
Until you see the log `INFO Ruleset reloaded successfully` on the workers, the workers will continue to process events with the old ruleset.
Can you check if you see those logs on the workers?
To view this discussion visit https://groups.google.com/d/msgid/wazuh/d4f5fbf9-8015-4832-b431-8311f99ac9aen%40googlegroups.com.
What could be the cause and how can I fix it?
If this log does not appear in the workers, it is because you have not attempted to reload. It would be helpful if you could analyze or share the cluster.log (located in /var/ossec/logs), as there may be information of interest in the next few minutes after reloading the rules on the master.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/06e81b7e-929a-4487-aa23-716462ea4140n%40googlegroups.com.
There is a synchronization problem, which is why the ruleset is not reloading on the workers.
Could you create an issue at github.com/wazuh/wazuh/issues with the necessary information to replicate it?
OS version, Wazuh version, number of workers, steps you followed to update the Wazuh version, which version you were using before, etc.
This will allow the development team to evaluate it and find a solution to this problem.
Regards
To view this discussion visit https://groups.google.com/d/msgid/wazuh/32c2809f-a9ee-4cbb-ade8-f68134480a3dn%40googlegroups.com.
Thanks for the PR, we've already merged it and the change will be in production in the next release patch.
ref: https://github.com/wazuh/wazuh/issues/34174To view this discussion visit https://groups.google.com/d/msgid/wazuh/123d97c9-e3b1-4ce0-b89c-8c0be5c08267n%40googlegroups.com.