Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 15649
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Gokul Suresh
,
Hernan Matias Villan
2
4:38 PM
High Index pattern mappings
Hello, Gokul The field mappings in your wazuh-alerts-* index pattern are derived from the mappings of
unread,
High Index pattern mappings
Hello, Gokul The field mappings in your wazuh-alerts-* index pattern are derived from the mappings of
4:38 PM
Mian Muzammil
,
Federico Gustavo Galland
4
10:01 AM
Correlate callerProcessID (Windows EventChannel) with processId (Sysmon) when decoder can't be changed
In the steps above, we are basically setting up the following workflow: When custom rule 100600 is
unread,
Correlate callerProcessID (Windows EventChannel) with processId (Sysmon) when decoder can't be changed
In the steps above, we are basically setting up the following workflow: When custom rule 100600 is
10:01 AM
Brad Nelson
,
Dennis Ariel Gamboa Veliz
3
8:59 AM
Admn Password to my Wazuh servers keep changing.
Dennis, I got it fixed on both. The error message (invalid username or password is VERY misleading)
unread,
Admn Password to my Wazuh servers keep changing.
Dennis, I got it fixed on both. The error message (invalid username or password is VERY misleading)
8:59 AM
Jerome Laroche
,
Ian Yenien Serrano
8
8:40 AM
No log collected via syslog with network equipment
Here's the begining of the ossec.conf: <ossec_config> <global> <jsonout_output>
unread,
No log collected via syslog with network equipment
Here's the begining of the ossec.conf: <ossec_config> <global> <jsonout_output>
8:40 AM
T. Omer
,
Stuti Gupta
6
7:34 AM
Support Request – Wazuh v4.8.1 Stopped Displaying Alerts in Dashboard
Hi In the logs you shared, we can see the following warning: [WARN ][oomjJvmGcMonitorService] [node-1
unread,
Support Request – Wazuh v4.8.1 Stopped Displaying Alerts in Dashboard
Hi In the logs you shared, we can see the following warning: [WARN ][oomjJvmGcMonitorService] [node-1
7:34 AM
suricata
,
Bony V John
5
7:02 AM
About Wazuh blog post: "Leveraging artificial intelligence for threat hunting in Wazuh"
Hí, I'll review all of that. For now: Ollama is running remotely. I execute the script on the
unread,
About Wazuh blog post: "Leveraging artificial intelligence for threat hunting in Wazuh"
Hí, I'll review all of that. For now: Ollama is running remotely. I execute the script on the
7:02 AM
Idefix RC
,
Md. Nazmur Sakib
3
3:40 AM
Virustotal custom rule set for >1 positive
You Sir, are an absolute legend !!! Thanks a million 🥳 On Fri, Sep 19, 2025 at 1:10 PM 'Md.
unread,
Virustotal custom rule set for >1 positive
You Sir, are an absolute legend !!! Thanks a million 🥳 On Fri, Sep 19, 2025 at 1:10 PM 'Md.
3:40 AM
Mithun Haridas
3:26 AM
Issue with the Plugin Decoder
I have created a custom decoder for Azure JSON logs using the <plugin_decoder>JSON_Decoder</
unread,
Issue with the Plugin Decoder
I have created a custom decoder for Azure JSON logs using the <plugin_decoder>JSON_Decoder</
3:26 AM
David Brindley
,
musbau....@wazuh.com
7
Sep 18
365 logs not ingested to Wazuh
Hi Musbau, I checked the logs again after a reboot and haven't seen anything relevant. Also re-
unread,
365 logs not ingested to Wazuh
Hi Musbau, I checked the logs again after a reboot and haven't seen anything relevant. Also re-
Sep 18
Sylvain Maret
,
Javier Adán Méndez Méndez
2
Sep 18
Need help with wazuh-ansible
Hi Sylvain Before we dig in — could you tell me which OS and version you installed on (eg, Ubuntu
unread,
Need help with wazuh-ansible
Hi Sylvain Before we dig in — could you tell me which OS and version you installed on (eg, Ubuntu
Sep 18
Arun Ramesh Hundaragi
,
Olamilekan Abdullateef Ajani
6
Sep 17
Assistance with RDS Authentication Logs, Decoders, and Rule Sets
Hello Arun, I believe some of the things you asked were answered in my previous response, however, I
unread,
Assistance with RDS Authentication Logs, Decoders, and Rule Sets
Hello Arun, I believe some of the things you asked were answered in my previous response, however, I
Sep 17
Hein Khant Shane
,
hasitha.u...@wazuh.com
4
Sep 17
YARA Integration on Windows Endpoints
Hi Hein, I successfully configured the Yara integration for Windows by following the documentation.
unread,
YARA Integration on Windows Endpoints
Hi Hein, I successfully configured the Yara integration for Windows by following the documentation.
Sep 17
Harish kannan
,
Md. Nazmur Sakib
2
Sep 17
Exploring Wazuh: Request for Detailed Explanation of Real-Time Use
Hello Harish, Wazuh is a SIEM and XDR. To understand Wazuh, you need to understand what SIEM and XDR
unread,
Exploring Wazuh: Request for Detailed Explanation of Real-Time Use
Hello Harish, Wazuh is a SIEM and XDR. To understand Wazuh, you need to understand what SIEM and XDR
Sep 17
QC L
,
Manuel Jose Cano Rojo
2
Sep 17
Memory usage of the Vulnerability Detection module
Hi QC! You can consult the introduced changes and improvements in each version in the public Wazuh
unread,
Memory usage of the Vulnerability Detection module
Hi QC! You can consult the introduced changes and improvements in each version in the public Wazuh
Sep 17
Ethan Thompson
,
hasitha.u...@wazuh.com
6
Sep 17
worker node agent upgrade issue
hello, team CLI-based upgrades don't work the same way on other server versions. I solved this
unread,
worker node agent upgrade issue
hello, team CLI-based upgrades don't work the same way on other server versions. I solved this
Sep 17
Somer Rabee
,
hasitha.u...@wazuh.com
4
Sep 17
llama3 model deployment with error
Any suggestion ...? On Monday, September 15, 2025 at 11:41:46 AM UTC+3 Somer Rabee wrote: Hi Hasitha,
unread,
llama3 model deployment with error
Any suggestion ...? On Monday, September 15, 2025 at 11:41:46 AM UTC+3 Somer Rabee wrote: Hi Hasitha,
Sep 17
Facu Basgall
,
Md. Nazmur Sakib
4
Sep 17
MS Teams Integration
It is difficult for me to replicate this as I do not have access to an MS Teams subscription. "
unread,
MS Teams Integration
It is difficult for me to replicate this as I do not have access to an MS Teams subscription. "
Sep 17
Facu Basgall
,
Juan Felipe González Ortiz
12
Sep 16
Slow performance with LDAP user.
We've been running some tests on our side to better understand the behavior you described with
unread,
Slow performance with LDAP user.
We've been running some tests on our side to better understand the behavior you described with
Sep 16
Ga Mac
,
Olamilekan Abdullateef Ajani
3
Sep 16
Suricata logs not giving me the full log? integration with wazuh
Hello Gabriel, I apologize for the delayed response. I have replicated this and I can confirm to you
unread,
Suricata logs not giving me the full log? integration with wazuh
Hello Gabriel, I apologize for the delayed response. I have replicated this and I can confirm to you
Sep 16
Facu Basgall
,
Héctor Gómez
10
Sep 16
Problem installing the agent.
You can try performing the installation with verbose mode enabled to obtain the log and share it,
unread,
Problem installing the agent.
You can try performing the installation with verbose mode enabled to obtain the log and share it,
Sep 16
LUAN BRAZ
,
Md. Nazmur Sakib
5
Sep 16
Wazuh dashboard has stopped receiving and displaying logs.
Your information was very helpful. The problem was solved. Thank you very much! Em ter., 16 de set.
unread,
Wazuh dashboard has stopped receiving and displaying logs.
Your information was very helpful. The problem was solved. Thank you very much! Em ter., 16 de set.
Sep 16
하프사
,
Olamilekan Abdullateef Ajani
3
Sep 16
Storage monitoring and alerts in Wazuh
Thank you Olamilekan, This is precisely what I needed. On Monday, 15 September 2025 at 14:50:30 UTC+1
unread,
Storage monitoring and alerts in Wazuh
Thank you Olamilekan, This is precisely what I needed. On Monday, 15 September 2025 at 14:50:30 UTC+1
Sep 16
하프사
,
Federico Rodriguez
6
Sep 16
About Reformating Syscheck Fields
I created an issue to fix the duplicate entries. You can track the process here: https://github.com/
unread,
About Reformating Syscheck Fields
I created an issue to fix the duplicate entries. You can track the process here: https://github.com/
Sep 16
Alen Mustafic
,
Franco Giovanolli
4
Sep 16
Event Log Service Shutdown(Event ID 1100) not present in Wazuh logs
Hi Alen, Sorry for the delay in my response. I'll reach out to the team in charge of the agent to
unread,
Event Log Service Shutdown(Event ID 1100) not present in Wazuh logs
Hi Alen, Sorry for the delay in my response. I'll reach out to the team in charge of the agent to
Sep 16
Sumit Kumawat
,
Pedro De Castro
2
Sep 16
"Subscription-based Wazuh Dashboard Access Control with Razorpay Integration
hey Kumawat, how are you? Looks like to me that you are asking essentially how to build a Wazuh SaaS
unread,
"Subscription-based Wazuh Dashboard Access Control with Razorpay Integration
hey Kumawat, how are you? Looks like to me that you are asking essentially how to build a Wazuh SaaS
Sep 16
Sumit Kumawat
, …
J. Rome
4
Sep 16
Custom macOS agent
I want to build the macOS agent from scratch for my org. Need my branding: agent name Agent-ABC, my
unread,
Custom macOS agent
I want to build the macOS agent from scratch for my org. Need my branding: agent name Agent-ABC, my
Sep 16
Chris Ark
, …
WENWEN H
3
Sep 16
Wazuh 4.12 Vulnerability Detection Not Working. Im at a loss : Please help
Hello, both of you. I also encountered the same situation. However, I found a vulnerability in "
unread,
Wazuh 4.12 Vulnerability Detection Not Working. Im at a loss : Please help
Hello, both of you. I also encountered the same situation. However, I found a vulnerability in "
Sep 16
felixm
,
Jose Camargo
4
Sep 15
Log_all not logging all
Here is my ossec.conf file: The log files are being generated, I even turned logging off and the
unread,
Log_all not logging all
Here is my ossec.conf file: The log files are being generated, I even turned logging off and the
Sep 15
Joaquim António
,
Olamilekan Abdullateef Ajani
3
Sep 15
Customize email alert
Hello Olamilekan, Thank you! Best regards, Joaquim António A segunda-feira, 15 de setembro de 2025 à(
unread,
Customize email alert
Hello Olamilekan, Thank you! Best regards, Joaquim António A segunda-feira, 15 de setembro de 2025 à(
Sep 15
Nikita Rousseau
,
Isaac Yusuf
4
Sep 15
Update Rocky Linux 9 RULESET to meet CIS Benchmark v2.0.0 - 06-25-2024
Hi, Thank you Yusuf for your message ! :) Indeed, the effort is quite substantial, but validating the
unread,
Update Rocky Linux 9 RULESET to meet CIS Benchmark v2.0.0 - 06-25-2024
Hi, Thank you Yusuf for your message ! :) Indeed, the effort is quite substantial, but validating the
Sep 15