Hello
Rule 23504 means Wazuh detected an active medium/untriaged vulnerability, while rule 23502 means it considered the vulnerability solved.
This does not necessarily mean the agents lost their database. Wazuh does not generate vulnerability alerts during the initial inventory synchronization, so you should first check whether package updates occurred on those two servers.
Choose one CVE and compare the complete JSON for both alerts, especially:
-
data.vulnerability.package.name- data.vulnerability.package.version
- data.vulnerability.package.architecture
- data.vulnerability.package.condition
If rule 23504 refers to a new package version and rule 23502 to the old version, a package upgrade probably triggered the alerts. Check the package history around that time too.
zgrep -hE ' (upgrade|install|remove) ' /var/log/dpkg.log*
zgrep -hE 'Start-Date|Upgrade:|Install:|Remove:' /var/log/apt/history.log*
Also check Vulnerability Detection > Inventory. The Events section contains the active/solved history, while Inventory shows the current state. If the CVE is no longer in Inventory, it has been resolved. If it is still present against the new package version, the system is still considered vulnerable.
If both alerts contain exactly the same package, version, and architecture, and there was no package activity, then this looks more like inventory or scanner state changing unexpectedly. In that case, check the manager log around the alert time:
grep -Ei 'vulnerability-scanner|content-updater|syscollector|indexer-connector|error|warning' /var/ossec/logs/ossec.log
A similar upgrade-related active/solved behavior was reported in an older version, you can also check them out below.
https://github.com/wazuh/wazuh/issues/13354https://github.com/wazuh/wazuh/pull/17052If possible, please share one complete 23504/23502 alert pair with the package details. That should make it clearer.
I await feedback from you.