Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 15747
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Владмир Пупкин
, …
Matías Mercado
5
7:07 AM
setting filebeat wazuh docker
Thanks, everything worked !!! пятница, 10 октября 2025 г. в 00:23:40 UTC+3, Matías Mercado: Hello,
unread,
setting filebeat wazuh docker
Thanks, everything worked !!! пятница, 10 октября 2025 г. в 00:23:40 UTC+3, Matías Mercado: Hello,
7:07 AM
artem frolov
7:04 AM
rule id 61102 dublications
Hello, can u clarify some strange things with rule 61102. When i get csv file with all events (data.
unread,
rule id 61102 dublications
Hello, can u clarify some strange things with rule 61102. When i get csv file with all events (data.
7:04 AM
Chandra pal singh Chauhan
,
Pedro De Castro
2
5:55 AM
wazuh gives multiple error when i logged in.
Hi Anurudra, I can't say too much just looking at the errors you have sent, it will be nice if
unread,
wazuh gives multiple error when i logged in.
Hi Anurudra, I can't say too much just looking at the errors you have sent, it will be nice if
5:55 AM
Riccardo Olivetto
,
Federico Ramos
3
5:21 AM
Modify Full log
I refer to this article: https://documentation.wazuh.com/current/proof-of-concept-guide/leveraging-
unread,
Modify Full log
I refer to this article: https://documentation.wazuh.com/current/proof-of-concept-guide/leveraging-
5:21 AM
john
,
Stuti Gupta
4
4:53 AM
Wazuh Discover dashboard empty (wazuh-alerts-* missing)
From the cluster health, it seems that the shards are full (default shard limit is 1000), which will
unread,
Wazuh Discover dashboard empty (wazuh-alerts-* missing)
From the cluster health, it seems that the shards are full (default shard limit is 1000), which will
4:53 AM
Nathan D.
,
jesusd...@wazuh.com
5
4:47 AM
MISP Integration
Thank you for your reply. I run all my commands on the server that hosts the manager. For the command
unread,
MISP Integration
Thank you for your reply. I run all my commands on the server that hosts the manager. For the command
4:47 AM
Somer Rabee
, …
Matías Mercado
8
Oct 9
no permissions for [] and User [name=admin, backend_roles=[admin], requestedTenant=null]
Hi Somer, You should change the option to "false", make your changes, and then rollback to
unread,
no permissions for [] and User [name=admin, backend_roles=[admin], requestedTenant=null]
Hi Somer, You should change the option to "false", make your changes, and then rollback to
Oct 9
Szymon
,
Fabian Ruiz
3
Oct 9
Wazuh Dashboard Server is not ready yet
Thanks Fabian, This is the result: [2025-05-20T00:00:01234][WARN ][oocraAllocationService] [node-1]
unread,
Wazuh Dashboard Server is not ready yet
Thanks Fabian, This is the result: [2025-05-20T00:00:01234][WARN ][oocraAllocationService] [node-1]
Oct 9
Isaac
,
Stuti Gupta
3
Oct 9
internal server error 500 in wazuh-dashboard after change indexer users passwords
Hi Stuti Thank you for the information. The problem was solved changing the password of "
unread,
internal server error 500 in wazuh-dashboard after change indexer users passwords
Hi Stuti Thank you for the information. The problem was solved changing the password of "
Oct 9
Felix Andorfer
,
Olamilekan Abdullateef Ajani
17
Oct 9
Agent reconnect issue when switching networks
Hello Felix, I apologize this has took so long. Unfortunately I do not think you can disable that
unread,
Agent reconnect issue when switching networks
Hello Felix, I apologize this has took so long. Unfortunately I do not think you can disable that
Oct 9
avkby445h 24
,
jorge....@wazuh.com
4
Oct 9
Wazuh Server /var keeps on filling up
Hi avkby445h 24, Glad to hear that, If you have any other problem don't doubt to open a new
unread,
Wazuh Server /var keeps on filling up
Hi avkby445h 24, Glad to hear that, If you have any other problem don't doubt to open a new
Oct 9
Ali Holmes
,
Olamilekan Abdullateef Ajani
2
Oct 9
WatchGuard Firewall Decoder
Hello Ali, I see you have completed the integration which is good. I would be able to provide more
unread,
WatchGuard Firewall Decoder
Hello Ali, I see you have completed the integration which is good. I would be able to provide more
Oct 9
No Data
,
Damian Alfredo Mangold
6
Oct 9
CVE-2025-49844 not in offline ZIP VULN Database but in CTI
I'll forward your suggestion to the documentation team so they can consider clarifying the
unread,
CVE-2025-49844 not in offline ZIP VULN Database but in CTI
I'll forward your suggestion to the documentation team so they can consider clarifying the
Oct 9
Roman S
,
Md. Nazmur Sakib
2
Oct 9
Disk space utilization local rules
Hi Roman, In this scenario, command monitoring is running this command. Get-Volume -DriveLetter C |
unread,
Disk space utilization local rules
Hi Roman, In this scenario, command monitoring is running this command. Get-Volume -DriveLetter C |
Oct 9
Bayu Sangkaya (bayusky.labs)
,
Bony V John
3
Oct 9
Sibling decoder does not records value
Hi, I have tested your custom decoder using the sample log you shared, and it seems that the hostname
unread,
Sibling decoder does not records value
Hi, I have tested your custom decoder using the sample log you shared, and it seems that the hostname
Oct 9
MaP
Oct 9
Syslog-Forwarding: wazuh-csyslogd ERROR date or location not NULL or p is NULL
Hello everyone, I've checked my ossec.log for the first time in a while (I know I should do this
unread,
Syslog-Forwarding: wazuh-csyslogd ERROR date or location not NULL or p is NULL
Hello everyone, I've checked my ossec.log for the first time in a while (I know I should do this
Oct 9
Gokul Suresh
,
Manuel Jose Cano Rojo
2
Oct 9
Index Mapping Issue
Hi Gokul, This behavior is expected and occurs mainly for two reasons: Office 365 fields are included
unread,
Index Mapping Issue
Hi Gokul, This behavior is expected and occurs mainly for two reasons: Office 365 fields are included
Oct 9
CJK
,
Nicolas Stefani
2
Oct 9
Wordpress plugin update monitoring with Wazuh
Hi, How do you get these logs? Do you have a way to export them? One option could be to put the logs
unread,
Wordpress plugin update monitoring with Wazuh
Hi, How do you get these logs? Do you have a way to export them? One option could be to put the logs
Oct 9
Mikayel Mikayelyan
,
Md. Nazmur Sakib
4
Oct 9
Cisco Firepower SF-IMS syslog
You do not need to create a decoder for every log. You should write decoders based on the format of
unread,
Cisco Firepower SF-IMS syslog
You do not need to create a decoder for every log. You should write decoders based on the format of
Oct 9
Gokul Suresh
,
Hernan Matias Villan
6
Oct 9
High Index pattern mappings
Thank you Hernan for your reply. But still the issue is not solved. On Wednesday, October 1, 2025 at
unread,
High Index pattern mappings
Thank you Hernan for your reply. But still the issue is not solved. On Wednesday, October 1, 2025 at
Oct 9
Fernando Torrijos
,
Rafael Bailon Robles
3
Oct 9
Wazuh syslog alerts not showing in Discover
I received information privately. The conversation should continue in the public chat. Below is the
unread,
Wazuh syslog alerts not showing in Discover
I received information privately. The conversation should continue in the public chat. Below is the
Oct 9
Bob Barrett
,
Stuti Gupta
6
Oct 9
Wazuh Keycloak SAML
Still not having any luck. Here's my config.yml --- _meta: type: "config"
unread,
Wazuh Keycloak SAML
Still not having any luck. Here's my config.yml --- _meta: type: "config"
Oct 9
Alan Jackson
,
hasitha.u...@wazuh.com
3
Oct 8
4.12->4.13.1 'archives' no longer being indexed (but 'alerts' are working fine)
Hello! I can confirm all those settings were correct & as expected. Interestingly, after HOURS of
unread,
4.12->4.13.1 'archives' no longer being indexed (but 'alerts' are working fine)
Hello! I can confirm all those settings were correct & as expected. Interestingly, after HOURS of
Oct 8
Elias Morais Pereira
,
pdnb
4
Oct 8
Custom decoder with weird json structure
hello, The only decoder that "worked" for this type of log is the one below: <decoder
unread,
Custom decoder with weird json structure
hello, The only decoder that "worked" for this type of log is the one below: <decoder
Oct 8
pdnb
,
Luis Enrique Chico Capistrano
9
Oct 8
IT Hygiene
You could also add permissions to wazuh-monitoring*. For more information, please refer to the
unread,
IT Hygiene
You could also add permissions to wazuh-monitoring*. For more information, please refer to the
Oct 8
Kamil Tańcula
, …
Kamil Tańcula
3
Oct 8
No data on dashboard, but data present in log files
Yes, that's right, it's about the shard limit. The filebeat log contains the following
unread,
No data on dashboard, but data present in log files
Yes, that's right, it's about the shard limit. The filebeat log contains the following
Oct 8
Facu Basgall
,
Juan Felipe González Ortiz
13
Oct 8
Slow performance with LDAP user.
Hi! Thanks for waiting This slowdown occurs when browsing the Wazuh dashabord Unfortunately I don
unread,
Slow performance with LDAP user.
Hi! Thanks for waiting This slowdown occurs when browsing the Wazuh dashabord Unfortunately I don
Oct 8
Max
,
Samson Olugbenga Idowu
6
Oct 8
Wazuh API Status Offline Error after upgrades
Hi Samson, So I've tried what you've said: Please restart your Wazuh dashboard service using:
unread,
Wazuh API Status Offline Error after upgrades
Hi Samson, So I've tried what you've said: Please restart your Wazuh dashboard service using:
Oct 8
Fernando Torrijos
Oct 8
Wazuh Alerts not ingesting in Discover/Dashboards
Hello, I am trying to configure a custom decoder+rule and these seem to be working correctly, however
unread,
Wazuh Alerts not ingesting in Discover/Dashboards
Hello, I am trying to configure a custom decoder+rule and these seem to be working correctly, however
Oct 8
Romain Hennebois
,
esteban...@wazuh.com
9
Oct 8
Optimisation helps
However, when I look at the log in the wazuh-alerts-* index, I can see that my log is in the correct
unread,
Optimisation helps
However, when I look at the log in the wazuh-alerts-* index, I can see that my log is in the correct
Oct 8