Hi, can anyone help me?
My Wazuh is behaving strangely with Office 365 in a specific context of alerts.
My Wazuh alerts are sent to Teams, and as I noticed, suddenly some very old alerts (3 months ago) were reprocessed.
And I found them in archives.log and alerts.json.
{"timestamp":"2026-02-06T15:35:47.946+0000","rule":{"level":6,"description":"Account testebrenno@domain disabled","id":"100405","firedtimes":1,"mail":false,"groups":["office365","AzureActiveDirectory"],"hipaa":["164.312.b"],"pci_dss":["10.6.2"]},"agent":{"id":"000","name":"wazuh.manager"},"manager":{"name":"wazuh.manager"},"id":"x","full_log":"{\"integration\":\"office365\",\"office365\":{\"CreationTime\":\"2025-11-07T15:39:01\",\"Id\":\"x-x-x-x-x\",\"Operation\":\"Disable account.\",\"OrganizationId\":\"x-x-x-x-x\",\"RecordType\":8,\"ResultStatus\":\"Success\",\"UserKey\":\"Not Available\",\"UserType\":4,\"Version\":1,\"Workload\":\"AzureActiveDirectory\",\"ObjectId\":\"testebrenno@domain\",\"UserId\":\"x-x-x-x-140c8578b9f5\",\"AzureActiveDirectoryEventType\":1,\"ExtendedProperties\":[{\"N
But I can't find them in any index on the Wazuh dashboard.
What could be happening? Only the events related to Account Enable/Created/Disabled/Deleted are "reprocessing" from almost 3 months ago; all other events like SharePoint, Exchange, and Azure AD are normal. They can be found in archives.log and alerts.json, but not in any index or dashboard.