Hi Wazuh Team,
I've been getting familiar with Wazuh 5.0 since last week. I followed a guide on creating decoders, rules, etc., and then started writing and promoting my own.
A few days ago, I wanted to perform a complete reset and delete all custom rules, decoders, and related objects.
In Security Analytics → Overview → Integrations, I deleted the corresponding entries in the Draft space. However, they still exist in the Test and Custom spaces. Unfortunately, I can no longer delete these rules in the Test or Custom spaces because deletion is only allowed in the Draft space.
How can I completely remove all rules and decoders?
I also noticed that under:
the rules and decoders are no longer present in the Draft space, but they are still visible in the Test and Custom spaces.
I have the impression that after the rules and decoders were indexed, and I immediately deleted them from the Draft space via Overview, some kind of internal ID or reference may have been lost. As a result, the objects still exist in the Test and Custom spaces, but they can no longer be managed or deleted.
I also searched through the indices to try to locate the corresponding rule and decoder documents so I could delete them manually using curl, but I couldn't find any of them.
Am I simply overlooking something, or is this a known issue because Wazuh 5.0 is currently still in beta? 🙂
Best regards,









--
You received this message because you are subscribed to the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/0f89cb4c-f48d-4d0c-98c4-8796e7afa260n%40googlegroups.com.
Hi Marcel,
Thank you very much for your quick response and for the clarification.
Next week I'll create a few test rules and decoders again and carefully go through the recommended workflow instead of simply deleting them as I did before.
I just have one question. If I delete a rule from the Draft space, it disappears immediately and I can no longer promote it. Could you clarify whether deleting a rule in Draft should create a pending deletion that can then be promoted to Test and Custom, or am I missing a step in the workflow?
Thanks again for your help!
Best regards,
Jörg
Hi Ankit,
What exactly do you mean by a full-length report?
Wazuh 5.0 includes a PDF export feature in the Wazuh Dashboards for agent-related views. However, from what I've seen so far, it appears to generate more of a snapshot of the current dashboard view (e.g., Agent Alerts, Vulnerabilities, etc.). I haven't had much time to explore this feature in detail yet.
Apart from that, the OpenSearch version used by the Wazuh Indexer should also provide reporting capabilities, including PDF generation and email delivery. However, as far as I know, this functionality needs to be configured first.
Best regards,
Jörg