Hi Wazuh team,
i enabled wazuh module FIM on Windows Server2016 x64 in order to monitoring folder.
my environment:
Server Centos 9 stream : Wazuh Manager, Wazuh Indexer and Wazuh Dashboard (Wazuh 4.5.2)
Agent: Windows 2016 x64 - Agent version 4.5.2.
FIM configuration in attachment.
1 - Could you please help verify my FIM configuration, is there something wrong in configuration ?
2 - After FIM scan for some hours the wazuh agent crash and stop working ( Please see attachment )
-------------------------------------------------------------------------------------
Fault bucket , type 0
Event Name: APPCRASH
Response: Not available
Cab Id: 0
Problem signature:
P1: wazuh-agent.exe
P2: 1.0.0.0
P3: 64f6dc81
P4: wazuh-agent.exe
P5: 1.0.0.0
P6: 64f6dc81
P7: c00000fd
P8: 000bcc4c
P9:
P10:
Attached files:
\\?\C:\Windows\Temp\WER5A85.tmp.appcompat.txt
\\?\C:\Windows\Temp\WER5CB8.tmp.WERInternalMetadata.xml
\\?\C:\Windows\Temp\WER5CD8.tmp.WERDataCollectionFailure.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_wazuh-agent.exe_e5e34538dc256c3f9fd9775ffb3ff58d20998b_11aab8ae_cab_39a25cd5
Analysis symbol:
Rechecking for solution: 0
Report Id: 72494ff7-f681-4fb1-b031-fd572f933ec2
Report Status: 4
Hashed bucket:
--------------------------------------------------------------------------------------------------------------------------------------------
Fault bucket 1840703613274146299, type 1
Event Name: APPCRASH
Response: Not available
Cab Id: 0
Problem signature:
P1: wazuh-agent.exe
P2: 1.0.0.0
P3: 64f6dc81
P4: wazuh-agent.exe
P5: 1.0.0.0
P6: 64f6dc81
P7: c00000fd
P8: 000bcc4c
P9:
P10:
Attached files:
\\?\C:\Windows\Temp\WER5A85.tmp.appcompat.txt
\\?\C:\Windows\Temp\WER5CB8.tmp.WERInternalMetadata.xml
\\?\C:\Windows\Temp\WER5CD8.tmp.WERDataCollectionFailure.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_wazuh-agent.exe_e5e34538dc256c3f9fd9775ffb3ff58d20998b_11aab8ae_306e6cb4
Analysis symbol:
Rechecking for solution: 0
Report Id: 72494ff7-f681-4fb1-b031-fd572f933ec2
Report Status: 0