Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16268
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Creative Wolf (CreativeWolf)
,
Javier Adán Méndez Méndez
9
10:40 AM
Ubuntu 24.04 linux-image-6.8.0-90-generic Vulnerability
Hi Javier, Thanks, I tried this and yet the listing of these vulnerabilities won't go and it
unread,
Ubuntu 24.04 linux-image-6.8.0-90-generic Vulnerability
Hi Javier, Thanks, I tried this and yet the listing of these vulnerabilities won't go and it
10:40 AM
Breathald 's
2
10:40 AM
Extract MD5 hash from win.eventdata.hashes field into a separate field
In principle, custom decoders cannot be applied after the windows_eventchannel decoder because it is
unread,
Extract MD5 hash from win.eventdata.hashes field into a separate field
In principle, custom decoders cannot be applied after the windows_eventchannel decoder because it is
10:40 AM
Andrehens Chicfici
9:54 AM
Sophos XGS Decoder with optional fields
Hey wazuh community, I am trying my luck with a Decoder for Sophos XGS3100 devices. I added this to
unread,
Sophos XGS Decoder with optional fields
Hey wazuh community, I am trying my luck with a Decoder for Sophos XGS3100 devices. I added this to
9:54 AM
Aamir Sohail
,
Francis Timilehin Jeremiah
3
9:49 AM
vulnerability events
Hello, do you have it figured out now? Also, check this documentation for more information - https://
unread,
vulnerability events
Hello, do you have it figured out now? Also, check this documentation for more information - https://
9:49 AM
Facu Basgall
,
Luis Enrique Chico Capistrano
19
9:07 AM
Help with a rule
Hi Facu, We should probably review the event triggering rule 60204. Could you share the raw event so
unread,
Help with a rule
Hi Facu, We should probably review the event triggering rule 60204. Could you share the raw event so
9:07 AM
Tengku Arya Saputra
,
Olamilekan Abdullateef Ajani
4
9:02 AM
kubelet error [7415] very disruptive docker
Hello , The reason your rule did not work is because, from what you shared, you used if_matched_sid
unread,
kubelet error [7415] very disruptive docker
Hello , The reason your rule did not work is because, from what you shared, you used if_matched_sid
9:02 AM
M G
,
tomas....@wazuh.com
3
8:41 AM
srcip - any
Hi, I'd like to clarify a point from my previous response. Since srcip is a static (built-in)
unread,
srcip - any
Hi, I'd like to clarify a point from my previous response. Since srcip is a static (built-in)
8:41 AM
Tengku Arya Saputra
,
John E
10
7:14 AM
False Postive webshell detection
Hi Tengku, The issue you are facing are noise coming from docker, kube8, containerd. You can suppress
unread,
False Postive webshell detection
Hi Tengku, The issue you are facing are noise coming from docker, kube8, containerd. You can suppress
7:14 AM
Gokul Suresh
,
Himanshu Sharma
3
6:05 AM
Virustotal integration errors in ossec.log
Hi Team, I just wanted to follow up on this issue. If you have any further questions or require
unread,
Virustotal integration errors in ossec.log
Hi Team, I just wanted to follow up on this issue. If you have any further questions or require
6:05 AM
Chandra pal singh Chauhan
,
Javier Sanchez Gil
7
5:54 AM
Implementing PostgreSQL Login Monitoring Use Cases in Wazuh (DAM Compliance)
Hi Javier, Thank you for the explanation. I understand what you are trying to convey. Could you
unread,
Implementing PostgreSQL Login Monitoring Use Cases in Wazuh (DAM Compliance)
Hi Javier, Thank you for the explanation. I understand what you are trying to convey. Could you
5:54 AM
Akshay
,
hasitha.u...@wazuh.com
3
5:51 AM
Wazuh Fortigate Integration
Hi Akshay, First of all, verify the FortiGate alerts are generating on the alerts.json file: /var/
unread,
Wazuh Fortigate Integration
Hi Akshay, First of all, verify the FortiGate alerts are generating on the alerts.json file: /var/
5:51 AM
doc dodo
,
John Adewale Olatunde
13
3:25 AM
AD control cinfiguration with SCA
Thanks!! It's really works! вторник, 27 января 2026 г. в 15:40:05 UTC+3, John Adewale Olatunde:
unread,
AD control cinfiguration with SCA
Thanks!! It's really works! вторник, 27 января 2026 г. в 15:40:05 UTC+3, John Adewale Olatunde:
3:25 AM
никита какдела
,
hasitha.u...@wazuh.com
8
2:33 AM
Per_bucket monitor performance
I'm having this problem primarily with this monitor (and similar monitors that aggregate a large
unread,
Per_bucket monitor performance
I'm having this problem primarily with this monitor (and similar monitors that aggregate a large
2:33 AM
Suvadip Ghosh
,
diego....@wazuh.com
6
2:31 AM
AWS RDS-PGSQL Integration with wazuh for monitoring DAM
Hello Suvadip, Here is the new decoder plus some modifications I made to the decoder we had before:
unread,
AWS RDS-PGSQL Integration with wazuh for monitoring DAM
Hello Suvadip, Here is the new decoder plus some modifications I made to the decoder we had before:
2:31 AM
Tengku Arya Saputra
,
Bony V John
5
12:38 AM
Adding the required fields
Hi, Apologies for the late response. For monitoring network-level attacks, you can consider
unread,
Adding the required fields
Hi, Apologies for the late response. For monitoring network-level attacks, you can consider
12:38 AM
Yazid
,
Richmond Aribibia Fimie
13
Feb 1
Wazuh / Symentec Integration
Hello @Richmond, Apologies for the delayed response, and thank you for your reply. Please find below
unread,
Wazuh / Symentec Integration
Hello @Richmond, Apologies for the delayed response, and thank you for your reply. Please find below
Feb 1
Xavier Mertens
,
Marcos Darío Buslaiman
5
Jan 31
Kunai JSON events not ingested?
Hi Marcos, It works! Great! I also applied the same to "filebeat-7.10.2-wazuh-archives-pipeline
unread,
Kunai JSON events not ingested?
Hi Marcos, It works! Great! I also applied the same to "filebeat-7.10.2-wazuh-archives-pipeline
Jan 31
никита какдела
Jan 30
wazuh-cluster.log
Hello, i have ERRORS in my wazuh-cluster.log [2026-01-30T14:11:17378][ERROR][oonct
unread,
wazuh-cluster.log
Hello, i have ERRORS in my wazuh-cluster.log [2026-01-30T14:11:17378][ERROR][oonct
Jan 30
Veera
,
Pablo Ariel Gonzalez
18
Jan 30
fim.db management
Veera: Thanks for the detailed explanation of both cases. When should FIM events be expected after a
unread,
fim.db management
Veera: Thanks for the detailed explanation of both cases. When should FIM events be expected after a
Jan 30
Andrehens Chicfici
,
diego....@wazuh.com
4
Jan 30
Local_rules.xml XML-Validator/Validation Tool
Hello, Glad to help! I tried this validator and it seemed to work -> https://www.liquid-
unread,
Local_rules.xml XML-Validator/Validation Tool
Hello, Glad to help! I tried this validator and it seemed to work -> https://www.liquid-
Jan 30
DK
,
Julián Morales
10
Jan 30
ruleset hot reload problem
Good catch DK!! Thanks for the PR, we've already merged it and the change will be in production
unread,
ruleset hot reload problem
Good catch DK!! Thanks for the PR, we've already merged it and the change will be in production
Jan 30
Hari Sapte
,
Md. Nazmur Sakib
2
Jan 30
Help required with CheckPoint Decoder
Hi Hari, The format of the decoders is not correct. AI tools can be helpful for writing decoders and
unread,
Help required with CheckPoint Decoder
Hi Hari, The format of the decoders is not correct. AI tools can be helpful for writing decoders and
Jan 30
Ricardo Barros
,
Md. Nazmur Sakib
8
Jan 30
No cached mapping for this field. Refresh field list
I am checking this internaly I will let you know the update if we can provide you with any possible
unread,
No cached mapping for this field. Refresh field list
I am checking this internaly I will let you know the update if we can provide you with any possible
Jan 30
Xavier Mertens
,
Nicolás Edgardo Rocca
3
Jan 30
RBAC for indices?
Hi Nicolas, Sorry for re-activating this thread... I forgot to follow up but now, I'm still have
unread,
RBAC for indices?
Hi Nicolas, Sorry for re-activating this thread... I forgot to follow up but now, I'm still have
Jan 30
Eric J
,
Olamilekan Abdullateef Ajani
6
Jan 30
Custom rules issue with frequency
Hello, Thank you very much for your reply. Best Regards Le jeudi 29 janvier 2026 à 21:54:07 UTC+1,
unread,
Custom rules issue with frequency
Hello, Thank you very much for your reply. Best Regards Le jeudi 29 janvier 2026 à 21:54:07 UTC+1,
Jan 30
Third Nht
,
Francis Timilehin Jeremiah
5
Jan 29
Wazuh Agent on Windows Server 2016 not reading IIS logs (No "Analyzing file" in ossec.log)
Hi, the issue seems to be because your Windows endpoint is not showing the full file extension,
unread,
Wazuh Agent on Windows Server 2016 not reading IIS logs (No "Analyzing file" in ossec.log)
Hi, the issue seems to be because your Windows endpoint is not showing the full file extension,
Jan 29
Thierry Bugier
,
Nicolas Zapata
4
Jan 29
IDMEFv2 connector for Wazuh
You're welcome, and thanks again for sharing your work. If at any point you'd like to
unread,
IDMEFv2 connector for Wazuh
You're welcome, and thanks again for sharing your work. If at any point you'd like to
Jan 29
Andrehens Chicfici
,
Cedrick Foko
4
Jan 29
Vulnerability Scanner triggering hundreds of false positives at the same tim
Hello, If you are still getting alerts after resetting the VD module, you can create a custom rule as
unread,
Vulnerability Scanner triggering hundreds of false positives at the same tim
Hello, If you are still getting alerts after resetting the VD module, you can create a custom rule as
Jan 29
Mahad Mansoor
,
Olamilekan Abdullateef Ajani
2
Jan 29
How to see Wazuh manager agent on dashboard?
Hello Mahad, When you install the Wazuh manager, it also runs an internal agent on the same host, but
unread,
How to see Wazuh manager agent on dashboard?
Hello Mahad, When you install the Wazuh manager, it also runs an internal agent on the same host, but
Jan 29
никита какдела
2
Jan 29
Wazuh .evtx
I am facing a problem with logging 4104 events (Microsoft-Windows-PowerShell/Operational) For some
unread,
Wazuh .evtx
I am facing a problem with logging 4104 events (Microsoft-Windows-PowerShell/Operational) For some
Jan 29