Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16012
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Sakai Edit
,
Rafael Bailon Robles
6
2:35 AM
wazuh to misp issue
Wazuh and Sysmon are two different products. You can have both installed without any issues. In fact,
unread,
wazuh to misp issue
Wazuh and Sysmon are two different products. You can have both installed without any issues. In fact,
2:35 AM
j885...@gmail.com
,
Awwal Ishiaku
5
2:31 AM
.opendistro-anomaly-results-history number of replicas
It's a system index, so you can't modify directly from the dashboard. Run the following
unread,
.opendistro-anomaly-results-history number of replicas
It's a system index, so you can't modify directly from the dashboard. Run the following
2:31 AM
amjad...@gmail.com
,
Md. Nazmur Sakib
5
1:32 AM
Unable to monitor >100,000 files — <file_limit> appears ignored on Windows agent (FIM / syscheck)
In your agent.conf(agent group configuration), I can see this configuration. <alert_new_files>
unread,
Unable to monitor >100,000 files — <file_limit> appears ignored on Windows agent (FIM / syscheck)
In your agent.conf(agent group configuration), I can see this configuration. <alert_new_files>
1:32 AM
Johny Novent
,
Natalia Castillo
2
1:28 AM
Vulnerability detector details condition field missing
Hi Johny, You are completely correct in your observation. The condition field (eg, "Package less
unread,
Vulnerability detector details condition field missing
Hi Johny, You are completely correct in your observation. The condition field (eg, "Package less
1:28 AM
Yogi Valentino
,
hariha...@wazuh.com
5
12:57 AM
Integration VirusTotal
I still have the same error root@ubuntu-wazuh:/var/ossec/integrations# ls -l total 76 -rwxr-x--- 1
unread,
Integration VirusTotal
I still have the same error root@ubuntu-wazuh:/var/ossec/integrations# ls -l total 76 -rwxr-x--- 1
12:57 AM
Paul Charran
,
fabio.c...@wazuh.com
2
Dec 1
Change password is failing
Hello Paul, Thanks for reporting this. To help you best, I need a little more context about your
unread,
Change password is failing
Hello Paul, Thanks for reporting this. To help you best, I need a little more context about your
Dec 1
Julián Lliteras
,
Olamilekan Abdullateef Ajani
2
Dec 1
Fortinet syslog on worker
Hello Yartax, To clarify your statement, are you saying that you installed rsyslog directly on the
unread,
Fortinet syslog on worker
Hello Yartax, To clarify your statement, are you saying that you installed rsyslog directly on the
Dec 1
Julián Lliteras
,
Diego Cappri
4
Dec 1
Auto deploy agent scripts
Thanks for sharing your thoughts, I totally understand your point. Having the manager deploy scripts
unread,
Auto deploy agent scripts
Thanks for sharing your thoughts, I totally understand your point. Having the manager deploy scripts
Dec 1
WiFi
,
Olamilekan Abdullateef Ajani
2
Dec 1
Custom rules
Hello devs, I believe you need to expand the scope of your current rule setup to correlate events for
unread,
Custom rules
Hello devs, I believe you need to expand the scope of your current rule setup to correlate events for
Dec 1
Jaswantha Ragesh
,
Carlos Ezequiel Bordon
5
Dec 1
Vulnerability Detector – Description Not Displaying & Count Mismatch Issues
Thank you for the information. I'm going to request more details: 1: I need you to share the OS
unread,
Vulnerability Detector – Description Not Displaying & Count Mismatch Issues
Thank you for the information. I'm going to request more details: 1: I need you to share the OS
Dec 1
Jorge Moya Albarran
,
Nicolas Zapata
2
Dec 1
Logs Auditd
Hello, Auditd can generate multiple records for a single action, especially when a syscall triggers
unread,
Logs Auditd
Hello, Auditd can generate multiple records for a single action, especially when a syscall triggers
Dec 1
Yogi Valentino
,
Anthony Faruna
2
Dec 1
Wazuh Rules for Active Response
Hello Yogi, Please try the rule below and let me know if it works for you. <rule id="11000
unread,
Wazuh Rules for Active Response
Hello Yogi, Please try the rule below and let me know if it works for you. <rule id="11000
Dec 1
Bayu Sangkaya (bayusky.labs)
,
Marcos Darío Buslaiman
6
Dec 1
Custom logs not captured
Excellent Bayu!! On Sunday, November 30, 2025 at 2:54:12 AM UTC-3 Bayu Sangkaya wrote: Ah I see,
unread,
Custom logs not captured
Excellent Bayu!! On Sunday, November 30, 2025 at 2:54:12 AM UTC-3 Bayu Sangkaya wrote: Ah I see,
Dec 1
Narasimha Naidu B
Dec 1
IT Hygiene issue
Dear Wazuh Team I am having the issue with IT Hygiene where no data is being displayed. Could you
unread,
IT Hygiene issue
Dear Wazuh Team I am having the issue with IT Hygiene where no data is being displayed. Could you
Dec 1
Sergio
Dec 1
Decoder for Hirschmann switches not working
Hi, I'm working on a decoder for events from Hirschmann switches. I don't know what I'm
unread,
Decoder for Hirschmann switches not working
Hi, I'm working on a decoder for events from Hirschmann switches. I don't know what I'm
Dec 1
Fear cube_A
,
Ifeanyi Onyia Odike
2
Dec 1
Enabling Geolocation Pre-rule processing on Wazuh 4.12 (again)
Hi Reinstall Wazuh from sources and perform the following to include GeoLite2 database: Install
unread,
Enabling Geolocation Pre-rule processing on Wazuh 4.12 (again)
Hi Reinstall Wazuh from sources and perform the following to include GeoLite2 database: Install
Dec 1
m mun
,
victor....@wazuh.com
4
Dec 1
Alerts and Archives logs doesn't appear on dashboard and indexes
Perfect. Let's take a deeper look into your environment. Verify that the Wazuh manager is
unread,
Alerts and Archives logs doesn't appear on dashboard and indexes
Perfect. Let's take a deeper look into your environment. Verify that the Wazuh manager is
Dec 1
3
,
Md. Nazmur Sakib
2
Dec 1
Wazuh Integration with MISP (Threat Intelligence Feed)
Hello, You can integrate MISP to coress check your data from the alerts with MISP IOCs once the
unread,
Wazuh Integration with MISP (Threat Intelligence Feed)
Hello, You can integrate MISP to coress check your data from the alerts with MISP IOCs once the
Dec 1
Commercial League
,
Fabian Ruiz
10
Nov 30
Wazuh does not populate wazuh-alerts-*
Hi Nikolay You can check the status of the processes of wazuh, Based on what we see, you should have
unread,
Wazuh does not populate wazuh-alerts-*
Hi Nikolay You can check the status of the processes of wazuh, Based on what we see, you should have
Nov 30
João Victor
,
jorge...@wazuh.com
8
Nov 30
Error after upgrading Wazuh-Indexer from version 4.12.0 to 4.14.0
As we couldn't resolve the issue, we performed a backup of the server (hopefully we have this
unread,
Error after upgrading Wazuh-Indexer from version 4.12.0 to 4.14.0
As we couldn't resolve the issue, we performed a backup of the server (hopefully we have this
Nov 30
Lucas Veríssimo
,
hasitha.u...@wazuh.com
2
Nov 29
Regras no WAZUH
Hi Lucas, You can create a custom rule that using a parent rule 40101. To ignore alerts for specific
unread,
Regras no WAZUH
Hi Lucas, You can create a custom rule that using a parent rule 40101. To ignore alerts for specific
Nov 29
Max
, …
ArnaudG
3
Nov 29
Vulnerability Detection 4.14.1
Hello, I"m working with MAx, then let me give you more details. 1/ It is not related to Alerts (
unread,
Vulnerability Detection 4.14.1
Hello, I"m working with MAx, then let me give you more details. 1/ It is not related to Alerts (
Nov 29
stefanny chavez anto
,
Obinna Uchubilo
4
Nov 28
CASO DE USO PARA ID EVENTO 4624
Hello Stefanny, The rules should look like this <group name="windows,logon_unusual_detection,
unread,
CASO DE USO PARA ID EVENTO 4624
Hello Stefanny, The rules should look like this <group name="windows,logon_unusual_detection,
Nov 28
Jonathan kuruppu
, …
Matías Mercado
4
Nov 28
FIM alerts
Jonathan, To archive the logs, you need to enable the archiving following this guide: https://
unread,
FIM alerts
Jonathan, To archive the logs, you need to enable the archiving following this guide: https://
Nov 28
Vanderson Pereira da Silva
,
Felix Bocco
2
Nov 28
Erro indexer-connector: ERROR: HTTP response code said error, status code: 400.
Hi Vanderson, It's hard to tell by just seeing this error. But you can enable the debug mode and
unread,
Erro indexer-connector: ERROR: HTTP response code said error, status code: 400.
Hi Vanderson, It's hard to tell by just seeing this error. But you can enable the debug mode and
Nov 28
Thaynara Soares
,
Jorge Eduardo Molas
10
Nov 28
Communication problem
Are these agents on user workstations that shutdown at the end of the workday? The user can indeed
unread,
Communication problem
Are these agents on user workstations that shutdown at the end of the workday? The user can indeed
Nov 28
German DiCasas
,
diego...@wazuh.com
3
Nov 28
postfix email_from dif auth_mail
Done The problem was the flag <smtp_server>smtp-server.com </smtp_server> over ossec.conf
unread,
postfix email_from dif auth_mail
Done The problem was the flag <smtp_server>smtp-server.com </smtp_server> over ossec.conf
Nov 28
Joaquim António
,
Dennis Ariel Gamboa Veliz
2
Nov 28
Obtaining the total volume usage from last month (or other custom range)
Hi Joaquim, Thank you for your question. Wazuh provides internal statistics, such as remoted.
unread,
Obtaining the total volume usage from last month (or other custom range)
Hi Joaquim, Thank you for your question. Wazuh provides internal statistics, such as remoted.
Nov 28
Valerio Vinci
,
Santiago Padilla Alvarez
2
Nov 28
resync agent logs
Agents use an in-memory leaky bucket buffer to hold events temporarily when the manager is
unread,
resync agent logs
Agents use an in-memory leaky bucket buffer to hold events temporarily when the manager is
Nov 28
MaP
,
Gabriel Emanuel Valenzuela
14
Nov 28
Wazuh 4.12 doesn't generate Vulnerability Events
Hi MaP, The issue you mentioned does not appear to be related to your current problem. If you can run
unread,
Wazuh 4.12 doesn't generate Vulnerability Events
Hi MaP, The issue you mentioned does not appear to be related to your current problem. If you can run
Nov 28