Wazuh Vulnerability not show "Solved"

800 views
Skip to first unread message

Henrique Avelino

unread,
Jan 16, 2023, 11:43:21 AM1/16/23
to Wazuh mailing list
Hi everyone,

The vulnerability scan works good, It scans and presents the available vulnerabilities, I fixed all, The wazuh identifies that there is no more vulnerability available, but it does not show me the "status:solved",  just "status:Active"
f4d67577-65d8-4165-83ae-453fea7ed474.jpg

aa9cf737-3267-475f-aa3e-f9f9d65fe337.jpg

How Can I fixed it? I need it to be marked as solved.

Federico Damian Lo Iacono

unread,
Jan 16, 2023, 2:58:58 PM1/16/23
to Wazuh mailing list
Hi Henrique, thanks for using Wazuh!

If you go to your agents' `Security events` section and search for Rule ID `23502`, do any alerts relating to patching the vulnerabilities show up? It's possible that the alerts were not generated, even if the vulnerabilities were fixed.

Regards.

Henrique Avelino

unread,
Jan 17, 2023, 6:31:18 AM1/17/23
to Wazuh mailing list
Hi Federico,

Thanks for answering.

I didn't find any alerts with ID 23502, is that the problem? I have 200+ agents and I didn't see any alerts for that ID.

2023-01-17_8-24-04.jpg

How can I fix it? 

Federico Damian Lo Iacono

unread,
Jan 17, 2023, 10:05:48 AM1/17/23
to Wazuh mailing list
Hi Henrique,

That could be it. ID 23502 is fired when a vulnerability is solved. The other possibility that occurs to me is that a full scan of the agents has not been performed since patching the vulnerable packages. Did you perhaps follow this guide or this proof of concept when setting up vulnerability detection?

A sample of the manager's `/var/ossec/etc/ossec.conf` file (with sensitive data obscured) and `/var/ossec/etc/shared/default/agent.conf` could help with diagnosing what is going on. Could you please provide these?

Thanks!

Henrique Avelino

unread,
Jan 17, 2023, 10:43:20 AM1/17/23
to Wazuh mailing list
Hi Federico,

You solved my problem.

I start recording the logs from level 6 (<log_alert_level>6</log_alert_level>) and the ID 23502 is level 3. 
I made a custom rule override to level 7 and now it started  logging some "Solved" logs. I'll follow throughout the day and I'll update you.

Thanks a lot.

Federico Damian Lo Iacono

unread,
Jan 17, 2023, 10:47:35 AM1/17/23
to Wazuh mailing list
It's my pleasure Henrique.

Hugo Santos

unread,
Jul 10, 2023, 9:44:37 AM7/10/23
to Wazuh mailing list
I've the same issue.

So to order to overcome it ,  i need to lower the log alert level to id 23502 value (3).
Or on rule 23502 raise to meet my ossec.conf alert log level, right ?
Reply all
Reply to author
Forward
0 new messages