Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16353
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Tengku Arya Saputra
,
Bony V John
4
3:47 PM
error indeer template
Hello Bony, I will give you my old indexer, which has no errors, at the end of 2025, and the new one,
unread,
error indeer template
Hello Bony, I will give you my old indexer, which has no errors, at the end of 2025, and the new one,
3:47 PM
никита какдела
,
Isaiah Daboh
3
1:15 PM
Monitor performance
Hello, The current query has huge query load (10k events) because despite having the top-level "
unread,
Monitor performance
Hello, The current query has huge query load (10k events) because despite having the top-level "
1:15 PM
Márcio Cordeiro
,
Olamilekan Abdullateef Ajani
3
10:50 AM
Request for Guidance on Monitoring the Creation, Deletion, and Download of Files on Windows 11 Workstations
Hello Marciocordeiro, From an auditing perspective and your use case (file creation, deletion, and
unread,
Request for Guidance on Monitoring the Creation, Deletion, and Download of Files on Windows 11 Workstations
Hello Marciocordeiro, From an auditing perspective and your use case (file creation, deletion, and
10:50 AM
Emar Flix
,
Pedro Maximiliano Tolosa
4
10:16 AM
Wazuh CCR FailBack
Hi Emar, No, you only need to add it on the PR node where you will send the reindex request, not on
unread,
Wazuh CCR FailBack
Hi Emar, No, you only need to add it on the PR node where you will send the reindex request, not on
10:16 AM
exe
,
Stuti Gupta
4
9:42 AM
rsyslog and Wazuh
Hello there, i dont know if the last reply was sent, but to be safe i will send it again. First of
unread,
rsyslog and Wazuh
Hello there, i dont know if the last reply was sent, but to be safe i will send it again. First of
9:42 AM
Julien Bard
,
Nahuel Figueroa
10
8:33 AM
Got the log but no alert
To be more specific, you are introducing a pre-processed alert (JSON produced by Wazuh) into wazuh-
unread,
Got the log but no alert
To be more specific, you are introducing a pre-processed alert (JSON produced by Wazuh) into wazuh-
8:33 AM
Roman
,
Stuti Gupta
3
6:29 AM
Rule only works for limited number of events
Hi, thank you for quick response > If you want all 110070 alerts generated during the backup
unread,
Rule only works for limited number of events
Hi, thank you for quick response > If you want all 110070 alerts generated during the backup
6:29 AM
Ivan Martinez
,
Isaiah Daboh
14
5:49 AM
MS SQLServer Monitoring and active response
Hi Ivan, Please just to be sure. when you change to winEventChannel on the agent, the executable is
unread,
MS SQLServer Monitoring and active response
Hi Ivan, Please just to be sure. when you change to winEventChannel on the agent, the executable is
5:49 AM
Dmitry Mikheev
,
Stuti Gupta
12
5:33 AM
Duplicate agent name:
Dmitry, Your issue is not caused by duplicate names or leftover keys anymore. The behaviour you see
unread,
Duplicate agent name:
Dmitry, Your issue is not caused by duplicate names or leftover keys anymore. The behaviour you see
5:33 AM
Dhiren Chavda
,
Stuti Gupta
3
4:23 AM
Not able to see alerts in dashboard
Hi Dhiren Since the new index was created successfully and the alert count is visible in the overview
unread,
Not able to see alerts in dashboard
Hi Dhiren Since the new index was created successfully and the alert count is visible in the overview
4:23 AM
Robby Hunters
,
Md. Nazmur Sakib
3
4:07 AM
wazuh-modulesd WARNING Response buffer size limit reached.
Hi Nazmur, Sorry... Since I couldn't find a solution in the documentation, I asked ChatGPT, and
unread,
wazuh-modulesd WARNING Response buffer size limit reached.
Hi Nazmur, Sorry... Since I couldn't find a solution in the documentation, I asked ChatGPT, and
4:07 AM
hvn4k.
,
Md. Nazmur Sakib
6
2:03 AM
Wazuh rules fine tuning.
I did some tests with your logs. Check for rule.firedtimes field, if you see that it is resetting to
unread,
Wazuh rules fine tuning.
I did some tests with your logs. Check for rule.firedtimes field, if you see that it is resetting to
2:03 AM
Jacob Molland
,
Bony V John
4
Feb 24
Wazuh using Keycloak as an IdP (OIDC)
Hi, If you are encountering any errors while following the official Wazuh documentation, please share
unread,
Wazuh using Keycloak as an IdP (OIDC)
Hi, If you are encountering any errors while following the official Wazuh documentation, please share
Feb 24
Xavier Mertens
,
Olamilekan Abdullateef Ajani
7
Feb 24
Flooded with alerts 99901
Hello Xmertens, I did some research, and apparently the hash that ends with 855 is the SHA256 hash of
unread,
Flooded with alerts 99901
Hello Xmertens, I did some research, and apparently the hash that ends with 855 is the SHA256 hash of
Feb 24
Henry Valero
,
hasitha.u...@wazuh.com
6
Feb 24
Remote command execution is not working on Wazuh 4.14.3
Hi! If I save the information to agent.conf, why do I then check the client files and see that the
unread,
Remote command execution is not working on Wazuh 4.14.3
Hi! If I save the information to agent.conf, why do I then check the client files and see that the
Feb 24
Shihab Hossain Shifat
,
musbau....@wazuh.com
6
Feb 24
Wazuh_Terraform_Setup
Hi, I have resolved the previous issue. It was caused by directory permissions changing each time
unread,
Wazuh_Terraform_Setup
Hi, I have resolved the previous issue. It was caused by directory permissions changing each time
Feb 24
jack
,
hasitha.u...@wazuh.com
3
Feb 24
wazuh real HA
Hi Jack, What you experienced is actually expected behavior based on how the Wazuh server cluster is
unread,
wazuh real HA
Hi Jack, What you experienced is actually expected behavior based on how the Wazuh server cluster is
Feb 24
Xavier Mertens
,
Bony V John
4
Feb 23
Server upgraded but still listed as running the old OS
Hi, If the issue still persists, please check the <wodle name="syscollector">
unread,
Server upgraded but still listed as running the old OS
Hi, If the issue still persists, please check the <wodle name="syscollector">
Feb 23
Denis Grilli
,
Federico Gustavo Caffieri
3
Feb 23
Error changing the selected API - wazuh-dashboard
Thanks for your reply. My setup is using wazuh 4.14.3 and is formed by two indexer node in a cluster
unread,
Error changing the selected API - wazuh-dashboard
Thanks for your reply. My setup is using wazuh 4.14.3 and is formed by two indexer node in a cluster
Feb 23
Third Nht
,
Anthony Faruna
2
Feb 23
Is this log entry a threat? Looking for a Custom Rule to detect Web Shell activity in static paths.
Hello, Thank you for sharing the log samples and your observations. Based on what you've provided
unread,
Is this log entry a threat? Looking for a Custom Rule to detect Web Shell activity in static paths.
Hello, Thank you for sharing the log samples and your observations. Based on what you've provided
Feb 23
Yazid
, …
MaP
17
Feb 23
Wazuh / Symentec Integration
Hi Yazid, I suspect your data isn't being decoded correctly. Which file is displayed in the
unread,
Wazuh / Symentec Integration
Hi Yazid, I suspect your data isn't being decoded correctly. Which file is displayed in the
Feb 23
MSS
,
Gabriel Diaz Lopez de la Llave
6
Feb 23
Distributed Wazuh 4.13 Sizing
Hello! The final destination is the indexer, so that will be the requirement for the indexer cluster,
unread,
Distributed Wazuh 4.13 Sizing
Hello! The final destination is the indexer, so that will be the requirement for the indexer cluster,
Feb 23
dwight c
,
Nikhil Gurjar
4
Feb 22
Entra mfa/sso configuration
Hi dwight c, Glad to hear that it is working as expected. Please don't hesitate to contact us if
unread,
Entra mfa/sso configuration
Hi dwight c, Glad to hear that it is working as expected. Please don't hesitate to contact us if
Feb 22
Andrehens Chicfici
,
hasitha.u...@wazuh.com
12
Feb 22
Nessus triggers the same Shellshock-Attack Mails/Alerts hundred times daily
Hi Andrehens, That's okay, let me know if you need any further help with this, and we can look
unread,
Nessus triggers the same Shellshock-Attack Mails/Alerts hundred times daily
Hi Andrehens, That's okay, let me know if you need any further help with this, and we can look
Feb 22
Muhammad Ali Khan
,
hasitha.u...@wazuh.com
8
Feb 22
Suppress Default Wazuh Rules Using CDB-Based Custom Rule
Hi Muhammad You can exclude all Windows logs. If the agent is a Windows machine, you can comment out
unread,
Suppress Default Wazuh Rules Using CDB-Based Custom Rule
Hi Muhammad You can exclude all Windows logs. If the agent is a Windows machine, you can comment out
Feb 22
Veera
,
Pablo Ariel Gonzalez
19
Feb 21
fim.db management
Thanks .. That worked and I am able to receive results and adjust the timings accordingly.. On Friday
unread,
fim.db management
Thanks .. That worked and I am able to receive results and adjust the timings accordingly.. On Friday
Feb 21
Yogi Valentino
,
Julián Morales
3
Feb 21
Wazuh 0 Logs
Hi Julián I've solved the problem, I'm resetup Certificate for all of the wazuh components.
unread,
Wazuh 0 Logs
Hi Julián I've solved the problem, I'm resetup Certificate for all of the wazuh components.
Feb 21
Emar Flix
,
Olamilekan Abdullateef Ajani
5
Feb 20
Wazuh Csross-Cluster Replication (Failover).
Hello again, So from looking at that documentation, it says, "Once you run _stop on a follower
unread,
Wazuh Csross-Cluster Replication (Failover).
Hello again, So from looking at that documentation, it says, "Once you run _stop on a follower
Feb 20
Andrehens Chicfici
,
gonzalo....@wazuh.com
2
Feb 20
Multigroup modified
Hi Andrehens! If you're actively making changes, seeing that warning from time to time is normal.
unread,
Multigroup modified
Hi Andrehens! If you're actively making changes, seeing that warning from time to time is normal.
Feb 20
perps grace
,
Olamilekan Abdullateef Ajani
2
Feb 20
Trend Vision one Decoders
Hello Perps, I have created a sample decoder and matching rule for you below. Feel free to modify
unread,
Trend Vision one Decoders
Hello Perps, I have created a sample decoder and matching rule for you below. Feel free to modify
Feb 20