Here's a sample JSON. This event with different CVE-2016-... triggered 218 times from the same host on
Feb 13, 2026 around 21:33
{
"_index": "wazuh-alerts-4.x-2026.02.13",
"_id": "8gTsWJwBaczMXdxzvIj-",
"_score": null,
"_source": {
"input": {
"type": "log"
},
"agent": {
"ip": "192.168.180.1",
"name": "Client-1",
"id": "185"
},
"manager": {
"name": "wazuh"
},
"data": {
"vulnerability": {
"severity": "Critical",
"package": {
"condition": "Package less than or equal to 15.016.20045",
"name": "Adobe Acrobat Reader DC MUI",
"source": " ",
"version": "15.007.20033",
"architecture": "i686"
},
"assigner": "adobe",
"cwe_reference": "CWE-119",
"published": "2016-07-13T02:00:56Z",
"classification": "CVSS",
"title": "CVE-2016-4250 affects Adobe Acrobat Reader DC MUI",
"type": "Packages",
"rationale": "Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.",
"reference": "
https://helpx.adobe.com/security/products/acrobat/apsb16-26.html,
http://www.securityfocus.com/bid/91716,
http://www.securitytracker.com/id/1036281",
"score": {
"version": "3.0",
"base": "9.800000"
},
"cve": "CVE-2016-4250",
"scanner": {
"reference": "
https://cti.wazuh.com/vulnerabilities/cves/CVE-2016-4250"
},
"enumeration": "CVE",
"cvss": {
"cvss3": {
"base_score": "9.800000",
"vector": {
"user_interaction": "NONE",
"integrity_impact": "HIGH",
"scope": "UNCHANGED",
"availability": "HIGH",
"confidentiality_impact": "HIGH",
"attack_vector": "NETWORK",
"privileges_required": "NONE"
}
}
},
"updated": "2025-04-12T10:46:40Z",
"status": "Active"
}
},
"rule": {
"firedtimes": 206,
"mail": true,
"level": 13,
"pci_dss": [
"11.2.1",
"11.2.3"
],
"tsc": [
"CC7.1",
"CC7.2"
],
"description": "CVE-2016-4250 affects Adobe Acrobat Reader DC MUI",
"groups": [
"vulnerability-detector"
],
"id": "23506",
"gdpr": [
"IV_35.7.d"
]
},
"location": "vulnerability-detector",
"decoder": {
"name": "json"
},
"id": "1771018433.5475363046",
"timestamp": "2026-02-13T22:33:53.863+0100"
},
"fields": {
"data.vulnerability.published": [
"2016-07-13T02:00:56.000Z"
],
"data.vulnerability.updated": [
"2025-04-12T10:46:40.000Z"
],
"timestamp": [
"2026-02-13T21:33:53.863Z"
]
},
"sort": [
1771018433863
]
}