I checked that log and same, the sca created is not shown. The agent is over a windows 11. The yml created is over /var/ossec/etc/shared/default and also I created the yml over another group related to the windows agent.. that is to check witch one is loades over sca dashboard and only is the local one
Over ossec.log of server I can not see any input related to sca_programs.yml . Also, I edited the custom sca to know if is loaded from local agent (100001,100002) or server(100003,100004), I can see only the local as before.
Server Manager:
grep -iE "/sca/|sca:" /var/ossec/logs/ossec.log
2026/03/13 07:22:10 sca: INFO: Starting Security Configuration Assessment scan.
2026/03/13 07:22:10 sca: INFO: Starting evaluation of policy: '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 07:22:30 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 07:22:30 sca: INFO: Security Configuration Assessment scan finished. Duration: 20 seconds.
2026/03/13 14:35:05 sca: INFO: Module started.
2026/03/13 14:35:05 sca: INFO: Loaded policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 14:35:05 sca: INFO: Starting Security Configuration Assessment scan.
2026/03/13 14:35:06 sca: INFO: Starting evaluation of policy: '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 14:35:36 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 14:35:36 sca: INFO: Security Configuration Assessment scan finished. Duration: 31 seconds.
2026/03/13 15:05:14 sca: INFO: Module started.
2026/03/13 15:05:14 sca: INFO: Loaded policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:05:14 sca: INFO: Starting Security Configuration Assessment scan.
2026/03/13 15:05:15 sca: INFO: Starting evaluation of policy: '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:05:22 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:05:22 sca: INFO: Security Configuration Assessment scan finished. Duration: 8 seconds.
2026/03/13 15:29:04 sca: INFO: Module started.
2026/03/13 15:29:04 sca: INFO: Loaded policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:29:04 sca: INFO: Starting Security Configuration Assessment scan.
2026/03/13 15:29:04 sca: INFO: Starting evaluation of policy: '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:29:11 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:29:11 sca: INFO: Security Configuration Assessment scan finished. Duration: 7 seconds.
2026/03/13 15:30:36 sca: INFO: Module started.
2026/03/13 15:30:36 sca: INFO: Loaded policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:30:36 sca: INFO: Starting Security Configuration Assessment scan.
2026/03/13 15:30:36 sca: INFO: Starting evaluation of policy: '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:30:44 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/03/13 15:30:44 sca: INFO: Security Configuration Assessment scan finished. Duration: 8 seconds.
Over doc say: "All files remotely pushed from the Wazuh server are saved in the /<WAZUH_HOME_DIRECTORY>/etc/shared/ directory on the agent endpoints regardless of the group they belong to" I checked an yes, the policy over the server is over windows agent "C:\Program Files (x86)\ossec-agent\shared" . ... but is not show in web manager... It doesn't seem to apply and it's not visible on the SCA dashboard
Let me know what command can I run to check some flow error.
Regards
German