Groups
Groups
Conversations
All groups and messages
Send feedback to Google
Help
Training
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Wazuh | Mailing List
Contact owners and managers
1–30 of 16232
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Martin Krastev
,
Bony V John
6
9:45 AM
Missing logs/alerts in the Events
Hello Bony, Thank you for you reply! The previous WARN message is not showing anymore after I did
unread,
Missing logs/alerts in the Events
Hello Bony, Thank you for you reply! The previous WARN message is not showing anymore after I did
9:45 AM
Malakay
9:45 AM
Configure endpoint monitor
Hello everyone, I've been trying to configure an API endpoint check in Wazuh 4.14.1 rc2 for a few
unread,
Configure endpoint monitor
Hello everyone, I've been trying to configure an API endpoint check in Wazuh 4.14.1 rc2 for a few
9:45 AM
DK
,
Julián Morales
4
9:12 AM
ruleset hot reload problem
Hi laboulle1987, I see that in the master you have the logs for `Reloading ruleset` and `INFO Ruleset
unread,
ruleset hot reload problem
Hi laboulle1987, I see that in the master you have the logs for `Reloading ruleset` and `INFO Ruleset
9:12 AM
Facu Basgall
,
Luis Enrique Chico Capistrano
15
8:59 AM
Help with a rule
Sorry, the rule I used was: <rule id="101203" level="10"> <if_sid>
unread,
Help with a rule
Sorry, the rule I used was: <rule id="101203" level="10"> <if_sid>
8:59 AM
Thierry Bugier
,
Nicolas Zapata
3
8:54 AM
IDMEFv2 connector for Wazuh
Hello Nicolas, Thank you very much to spread the word about our project. Best regards, Le mardi 20
unread,
IDMEFv2 connector for Wazuh
Hello Nicolas, Thank you very much to spread the word about our project. Best regards, Le mardi 20
8:54 AM
Slavica SL
,
Olamilekan Abdullateef Ajani
2
8:53 AM
CEF Format Decoder Needed_Safeguard log
Dear Slavica, I made a sample decoder below for your reference as requested. <decoder name="
unread,
CEF Format Decoder Needed_Safeguard log
Dear Slavica, I made a sample decoder below for your reference as requested. <decoder name="
8:53 AM
никита какдела
,
musbau....@wazuh.com
20
7:57 AM
Per Bucket monitor Error.
Let's use an example. I have one of the logs. What command in Dev Tools can I use to find this
unread,
Per Bucket monitor Error.
Let's use an example. I have one of the logs. What command in Dev Tools can I use to find this
7:57 AM
Ricardo Barros
,
Md. Nazmur Sakib
3
7:40 AM
No cached mapping for this field. Refresh field list
I have already completed this activity, but I was not successful. Em quinta-feira, 22 de janeiro de
unread,
No cached mapping for this field. Refresh field list
I have already completed this activity, but I was not successful. Em quinta-feira, 22 de janeiro de
7:40 AM
exe
,
Pablo Moliz Arias
12
7:06 AM
Vulnerability Detection List not updating
Hello Pablo, in the meantime i fixed the issue. It was a network problem, the docker container had
unread,
Vulnerability Detection List not updating
Hello Pablo, in the meantime i fixed the issue. It was a network problem, the docker container had
7:06 AM
никита какдела
7:06 AM
Per_bucket monitor performance
Hi! I've noticed that sometimes I don't receive a notification for a triggered alert, meaning
unread,
Per_bucket monitor performance
Hi! I've noticed that sometimes I don't receive a notification for a triggered alert, meaning
7:06 AM
Andrehens Chicfici
,
Cedrick Foko
2
7:02 AM
Vulnerability Scanner triggering hundreds of false positives at the same tim
Hello, The issue you describe is caused by one of the followings: There are multiple versions of the
unread,
Vulnerability Scanner triggering hundreds of false positives at the same tim
Hello, The issue you describe is caused by one of the followings: There are multiple versions of the
7:02 AM
Yazid
,
Richmond Aribibia Fimie
10
6:28 AM
Wazuh / Symentec Integration
Hello @Yazid Thank you for sharing the results, I'll run some tests on my end to validate the
unread,
Wazuh / Symentec Integration
Hello @Yazid Thank you for sharing the results, I'll run some tests on my end to validate the
6:28 AM
mariano hinjos
,
Dennis Ariel Gamboa Veliz
4
6:27 AM
Threat Hunting is empty
Hi mariano, This is expected behavior. Wazuh creates daily alert indices (wazuh-alerts-4.x-YYYY.MM.DD
unread,
Threat Hunting is empty
Hi mariano, This is expected behavior. Wazuh creates daily alert indices (wazuh-alerts-4.x-YYYY.MM.DD
6:27 AM
Gabriele Ventura
,
Natalia Castillo
5
5:52 AM
Wazuh quickstart works initially but dashboard loses events over time on small single-node setup (disk pressure?)
Hi Natalia, Thanks, this clarifies a lot and matches what I observed in practice. I appreciate the
unread,
Wazuh quickstart works initially but dashboard loses events over time on small single-node setup (disk pressure?)
Hi Natalia, Thanks, this clarifies a lot and matches what I observed in practice. I appreciate the
5:52 AM
Bayu Sangkaya (bayusky.labs)
,
Stuti Gupta
3
5:34 AM
Always invalid parent
Hi Stuti, this is the log {"schemaVersion": "1.21", "id": "WB-
unread,
Always invalid parent
Hi Stuti, this is the log {"schemaVersion": "1.21", "id": "WB-
5:34 AM
Muhammad Ali Khan
,
Hossam El Amraoui
5
4:27 AM
Decoder Pre-match issue
I have modified the decoders to adapt them well. The decoders should look like this: ``` <decoder
unread,
Decoder Pre-match issue
I have modified the decoders to adapt them well. The decoders should look like this: ``` <decoder
4:27 AM
doc dodo
,
John Adewale Olatunde
11
3:30 AM
AD control cinfiguration with SCA
Hello, John. Yes, OS language is English. Debug logs show empty result of the command: 2026/01/22 11:
unread,
AD control cinfiguration with SCA
Hello, John. Yes, OS language is English. Debug logs show empty result of the command: 2026/01/22 11:
3:30 AM
wazuh
,
Federico Gustavo Galland
7
3:15 AM
Tracking MFA enable/disable events through MS-graph integration
Hi again, i was finally able to get my hands on a test environment for this issue. so now with the
unread,
Tracking MFA enable/disable events through MS-graph integration
Hi again, i was finally able to get my hands on a test environment for this issue. so now with the
3:15 AM
David Lima
,
josue....@wazuh.com
2
1:10 AM
No Integratord logs
Hi David, To help us confirm the behavior you're observing, could you please help us validate the
unread,
No Integratord logs
Hi David, To help us confirm the behavior you're observing, could you please help us validate the
1:10 AM
Ham Somalyvann
,
Bony V John
3
1:03 AM
Monitoring Email Security and Phishing Detection
Hi, Wazuh can help detect phishing emails by correlating email-related events with threat
unread,
Monitoring Email Security and Phishing Detection
Hi, Wazuh can help detect phishing emails by correlating email-related events with threat
1:03 AM
никита какдела
,
Md. Nazmur Sakib
6
12:43 AM
New SCA policies
This can happen due to a connectivity issue or if the agent cannot properly communicate with the
unread,
New SCA policies
This can happen due to a connectivity issue or if the agent cannot properly communicate with the
12:43 AM
DK
Jan 21
rulest hot reload problem
Hello! I updated wazuh to version 4.14.2 and encountered an issue when changing rules. When I change
unread,
rulest hot reload problem
Hello! I updated wazuh to version 4.14.2 and encountered an issue when changing rules. When I change
Jan 21
Joaquim António
,
Isaiah Daboh
10
Jan 21
Can't get ms-graph to obtain logs
Hello, After changing the frequency of the queries, from <interval>5m</interval> to <
unread,
Can't get ms-graph to obtain logs
Hello, After changing the frequency of the queries, from <interval>5m</interval> to <
Jan 21
Jacob Molland
,
raul....@wazuh.com
4
Jan 21
Using Keycloak as an IdP
Hi jacob As you mentioned earlier, you followed the https://documentation.wazuh.com/current/user-
unread,
Using Keycloak as an IdP
Hi jacob As you mentioned earlier, you followed the https://documentation.wazuh.com/current/user-
Jan 21
German DiCasas
,
juanjos...@wazuh.com
6
Jan 21
Alerts Logs
Hi German You can follow https://wazuh.com/blog/recover-your-data-using-wazuh-alert-backups/ the same
unread,
Alerts Logs
Hi German You can follow https://wazuh.com/blog/recover-your-data-using-wazuh-alert-backups/ the same
Jan 21
Facu Basgall
,
Nicolas Stefani
3
Jan 21
Help with custom Windows rule
The rule 101806 works fine as I sent it and no match is necessary. The following rules do not work
unread,
Help with custom Windows rule
The rule 101806 works fine as I sent it and no match is necessary. The following rules do not work
Jan 21
HALELUJAH
,
Nicolás Edgardo Rocca
2
Jan 21
Can not save rule file after edit
Hi, We'll need a little more information about the rule you're trying to create and how you
unread,
Can not save rule file after edit
Hi, We'll need a little more information about the rule you're trying to create and how you
Jan 21
Nyengka Prosper
,
Federico Gustavo Caffieri
2
Jan 21
macOS FIM rules causing the cluster crash after a configuration(modifying a rule file) modification is made
The timeout and cluster crashes you're experiencing with custom FIM rules in 4.13.1 could be
unread,
macOS FIM rules causing the cluster crash after a configuration(modifying a rule file) modification is made
The timeout and cluster crashes you're experiencing with custom FIM rules in 4.13.1 could be
Jan 21
David Lima
,
Ifeanyi Onyia Odike
7
Jan 21
Custom Fortimail Rule not abiding by the 200 frequency option
Hi David Regarding your question: "Do you have any tips on how to extract each TO field from
unread,
Custom Fortimail Rule not abiding by the 200 frequency option
Hi David Regarding your question: "Do you have any tips on how to extract each TO field from
Jan 21
Yogi Valentino
,
hasitha.u...@wazuh.com
3
Jan 21
Wazuh Sysmon Installation Detection
Hi Yogi, I've tested this rule and identified the problem. The regex type isn't defined in
unread,
Wazuh Sysmon Installation Detection
Hi Yogi, I've tested this rule and identified the problem. The regex type isn't defined in
Jan 21