FIM Registry trouble App version: 4.14.1

12 views
Skip to first unread message

Dmitry Mikheev

unread,
Jan 15, 2026, 7:42:53 AM (3 days ago) Jan 15
to Wazuh | Mailing List
FIM Registry worked until the last update!

Agent Ossec.config
<syscheck>
<disabled>no</disabled>
<frequency>86400</frequency>
<windows_registry check_mtime="no" arch="both">HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Id\System\ClientServices\Email\CITest</windows_registry>

Dashboard
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Id\System\ClientServices\Email
Last modify
Jan 9, 2026 @ 13:11:30.000

But I changed this key yesterday and again today!

Jan 9, 2026 @ 13:11:30.000
This is the approximate time the agent was updated to the new version...

Tested on Windows Server 2019 & 2022. 
Where to look?

tomas....@wazuh.com

unread,
Jan 15, 2026, 9:40:54 AM (3 days ago) Jan 15
to Wazuh | Mailing List

Hello,

To help determine whether the registry changes are being detected correctly, please perform the following tests:

  1. Force a new syscheck scan

    • Restart the Wazuh agent service, or temporarily reduce the scan interval:

      <frequency>60</frequency>
    • After the scan runs, modify the registry key again and check if a new event is generated.

  2. Enable registry modification time checks

    • Update the configuration as follows:

      <windows_registry check_mtime="yes" arch="both">
    • Restart the agent and modify the registry key once more.

  3. Ensure the value actually changes

    • Writing the same value again will not trigger a FIM event.

    • Please modify the data to a different value for testing purposes.

  4. Review agent logs

    • Check ossec.log for syscheck-related entries after making the change.

These steps should help clarify whether the behavior is related to scan timing, configuration, or change detection. Please let us know the results so we can continue assisting.

Best regards,

Tomás Turina

Dmitry Mikheev

unread,
Jan 16, 2026, 2:31:55 AM (2 days ago) Jan 16
to Wazuh | Mailing List
After setting check_mtime="yes" everything worked. 

Thanks.

Reply all
Reply to author
Forward
0 new messages