Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16008
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Jorge Moya Albarran
6:15 AM
Logs Auditd
Good morning, I am writing because I have enrolled a Debian machine in Wazuh and we are sending logs
unread,
Logs Auditd
Good morning, I am writing because I have enrolled a Debian machine in Wazuh and we are sending logs
6:15 AM
Narasimha Naidu B
6:15 AM
IT Hygiene issue
Dear Wazuh Team I am having the issue with IT Hygiene where no data is being displayed. Could you
unread,
IT Hygiene issue
Dear Wazuh Team I am having the issue with IT Hygiene where no data is being displayed. Could you
6:15 AM
Julián Lliteras
5:58 AM
Auto deploy agent scripts
I want to deploy agents scripts in the manager shared folder and then create active reponse with
unread,
Auto deploy agent scripts
I want to deploy agents scripts in the manager shared folder and then create active reponse with
5:58 AM
Sergio
5:57 AM
Decoder for Hirschmann switches not working
Hi, I'm working on a decoder for events from Hirschmann switches. I don't know what I'm
unread,
Decoder for Hirschmann switches not working
Hi, I'm working on a decoder for events from Hirschmann switches. I don't know what I'm
5:57 AM
Yogi Valentino
,
hariha...@wazuh.com
4
5:52 AM
Integration VirusTotal
Hello Harihar, Do you know where do i get the Restored Virustotal files? I can't just reinstalled
unread,
Integration VirusTotal
Hello Harihar, Do you know where do i get the Restored Virustotal files? I can't just reinstalled
5:52 AM
amjad...@gmail.com
,
Md. Nazmur Sakib
4
5:52 AM
Unable to monitor >100,000 files — <file_limit> appears ignored on Windows agent (FIM / syscheck)
Dear Md. Nazmur Sakib, As requested, I have checked the agent configuration and restarted the agent
unread,
Unable to monitor >100,000 files — <file_limit> appears ignored on Windows agent (FIM / syscheck)
Dear Md. Nazmur Sakib, As requested, I have checked the agent configuration and restarted the agent
5:52 AM
Yogi Valentino
5:21 AM
Wazuh Rules for Active Response
Hi Community, I was trying to make a rule for Active Response, The Active Response works fine. This
unread,
Wazuh Rules for Active Response
Hi Community, I was trying to make a rule for Active Response, The Active Response works fine. This
5:21 AM
Fear cube_A
,
Ifeanyi Onyia Odike
2
5:17 AM
Enabling Geolocation Pre-rule processing on Wazuh 4.12 (again)
Hi Reinstall Wazuh from sources and perform the following to include GeoLite2 database: Install
unread,
Enabling Geolocation Pre-rule processing on Wazuh 4.12 (again)
Hi Reinstall Wazuh from sources and perform the following to include GeoLite2 database: Install
5:17 AM
m mun
,
victor....@wazuh.com
4
4:46 AM
Alerts and Archives logs doesn't appear on dashboard and indexes
Perfect. Let's take a deeper look into your environment. Verify that the Wazuh manager is
unread,
Alerts and Archives logs doesn't appear on dashboard and indexes
Perfect. Let's take a deeper look into your environment. Verify that the Wazuh manager is
4:46 AM
Sakai Edit
,
Rafael Bailon Robles
2
2:42 AM
wazuh to misp issue
Wazuh has official documentation for integrating Suricata: Network IDS integration. I've reviewed
unread,
wazuh to misp issue
Wazuh has official documentation for integrating Suricata: Network IDS integration. I've reviewed
2:42 AM
3
,
Md. Nazmur Sakib
2
2:37 AM
Wazuh Integration with MISP (Threat Intelligence Feed)
Hello, You can integrate MISP to coress check your data from the alerts with MISP IOCs once the
unread,
Wazuh Integration with MISP (Threat Intelligence Feed)
Hello, You can integrate MISP to coress check your data from the alerts with MISP IOCs once the
2:37 AM
Jaswantha Ragesh
,
Carlos Ezequiel Bordon
4
1:54 AM
Vulnerability Detector – Description Not Displaying & Count Mismatch Issues
Hi Carlos, Sorry for not mentioning earlier – our Wazuh version is 4.14. Kind regards, Jaswanth On
unread,
Vulnerability Detector – Description Not Displaying & Count Mismatch Issues
Hi Carlos, Sorry for not mentioning earlier – our Wazuh version is 4.14. Kind regards, Jaswanth On
1:54 AM
Commercial League
,
Fabian Ruiz
10
Nov 30
Wazuh does not populate wazuh-alerts-*
Hi Nikolay You can check the status of the processes of wazuh, Based on what we see, you should have
unread,
Wazuh does not populate wazuh-alerts-*
Hi Nikolay You can check the status of the processes of wazuh, Based on what we see, you should have
Nov 30
João Victor
,
jorge...@wazuh.com
8
Nov 30
Error after upgrading Wazuh-Indexer from version 4.12.0 to 4.14.0
As we couldn't resolve the issue, we performed a backup of the server (hopefully we have this
unread,
Error after upgrading Wazuh-Indexer from version 4.12.0 to 4.14.0
As we couldn't resolve the issue, we performed a backup of the server (hopefully we have this
Nov 30
Bayu Sangkaya (bayusky.labs)
,
Marcos Darío Buslaiman
5
Nov 30
Custom logs not captured
Ah I see, There's a conflict. Now it's all correct. Thanks a lot Marcus. Regards, Bayu
unread,
Custom logs not captured
Ah I see, There's a conflict. Now it's all correct. Thanks a lot Marcus. Regards, Bayu
Nov 30
Lucas Veríssimo
,
hasitha.u...@wazuh.com
2
Nov 29
Regras no WAZUH
Hi Lucas, You can create a custom rule that using a parent rule 40101. To ignore alerts for specific
unread,
Regras no WAZUH
Hi Lucas, You can create a custom rule that using a parent rule 40101. To ignore alerts for specific
Nov 29
Max
, …
ArnaudG
3
Nov 29
Vulnerability Detection 4.14.1
Hello, I"m working with MAx, then let me give you more details. 1/ It is not related to Alerts (
unread,
Vulnerability Detection 4.14.1
Hello, I"m working with MAx, then let me give you more details. 1/ It is not related to Alerts (
Nov 29
stefanny chavez anto
,
Obinna Uchubilo
4
Nov 28
CASO DE USO PARA ID EVENTO 4624
Hello Stefanny, The rules should look like this <group name="windows,logon_unusual_detection,
unread,
CASO DE USO PARA ID EVENTO 4624
Hello Stefanny, The rules should look like this <group name="windows,logon_unusual_detection,
Nov 28
Jonathan kuruppu
, …
Matías Mercado
4
Nov 28
FIM alerts
Jonathan, To archive the logs, you need to enable the archiving following this guide: https://
unread,
FIM alerts
Jonathan, To archive the logs, you need to enable the archiving following this guide: https://
Nov 28
Vanderson Pereira da Silva
,
Felix Bocco
2
Nov 28
Erro indexer-connector: ERROR: HTTP response code said error, status code: 400.
Hi Vanderson, It's hard to tell by just seeing this error. But you can enable the debug mode and
unread,
Erro indexer-connector: ERROR: HTTP response code said error, status code: 400.
Hi Vanderson, It's hard to tell by just seeing this error. But you can enable the debug mode and
Nov 28
Thaynara Soares
,
Jorge Eduardo Molas
10
Nov 28
Communication problem
Are these agents on user workstations that shutdown at the end of the workday? The user can indeed
unread,
Communication problem
Are these agents on user workstations that shutdown at the end of the workday? The user can indeed
Nov 28
German DiCasas
,
diego...@wazuh.com
3
Nov 28
postfix email_from dif auth_mail
Done The problem was the flag <smtp_server>smtp-server.com </smtp_server> over ossec.conf
unread,
postfix email_from dif auth_mail
Done The problem was the flag <smtp_server>smtp-server.com </smtp_server> over ossec.conf
Nov 28
Joaquim António
,
Dennis Ariel Gamboa Veliz
2
Nov 28
Obtaining the total volume usage from last month (or other custom range)
Hi Joaquim, Thank you for your question. Wazuh provides internal statistics, such as remoted.
unread,
Obtaining the total volume usage from last month (or other custom range)
Hi Joaquim, Thank you for your question. Wazuh provides internal statistics, such as remoted.
Nov 28
Valerio Vinci
,
Santiago Padilla Alvarez
2
Nov 28
resync agent logs
Agents use an in-memory leaky bucket buffer to hold events temporarily when the manager is
unread,
resync agent logs
Agents use an in-memory leaky bucket buffer to hold events temporarily when the manager is
Nov 28
MaP
,
Gabriel Emanuel Valenzuela
14
Nov 28
Wazuh 4.12 doesn't generate Vulnerability Events
Hi MaP, The issue you mentioned does not appear to be related to your current problem. If you can run
unread,
Wazuh 4.12 doesn't generate Vulnerability Events
Hi MaP, The issue you mentioned does not appear to be related to your current problem. If you can run
Nov 28
Çınar
Nov 28
Alert timestamps and email notifications always use UTC (+0000) despite local timezone configuration (Docker 4.12.0, Europe/Istanbul)
Wazuh version 4.12.0 Component Wazuh manager Install type Manager Install method Docker Compose (
unread,
Alert timestamps and email notifications always use UTC (+0000) despite local timezone configuration (Docker 4.12.0, Europe/Istanbul)
Wazuh version 4.12.0 Component Wazuh manager Install type Manager Install method Docker Compose (
Nov 28
Nathan D.
,
Nahuel Figueroa
3
Nov 28
Dashboard - custom dashboard metrics clickable
Thanks for the reply Nahuel. But I'm still confused. What do you mean by “our own custom
unread,
Dashboard - custom dashboard metrics clickable
Thanks for the reply Nahuel. But I'm still confused. What do you mean by “our own custom
Nov 28
wazuh
,
Federico Gustavo Galland
6
Nov 28
Tracking MFA enable/disable events through MS-graph integration
Dom, I was not able to find a sample event either. Let us know as soon as you get hold of one so we
unread,
Tracking MFA enable/disable events through MS-graph integration
Dom, I was not able to find a sample event either. Let us know as soon as you get hold of one so we
Nov 28
Veera
,
Mauricio Aguilar
5
Nov 28
wazuh agent v4.14 failed to start in RHEL6
Thanks .. it worked On Wednesday, November 26, 2025 at 11:04:30 PM UTC+5:30 Mauricio Aguilar wrote:
unread,
wazuh agent v4.14 failed to start in RHEL6
Thanks .. it worked On Wednesday, November 26, 2025 at 11:04:30 PM UTC+5:30 Mauricio Aguilar wrote:
Nov 28
Brenno Garcia
,
Bony V John
3
Nov 28
Sysmon Alerts
Hi, Using the shared sample log, I am unable to test it in the Wazuh Logtest tool because it does not
unread,
Sysmon Alerts
Hi, Using the shared sample log, I am unable to test it in the Wazuh Logtest tool because it does not
Nov 28