Remove (cluster.name: wazuh) default filter on wazuh dashboard

144 views
Skip to first unread message

Unknown

unread,
Oct 26, 2023, 7:53:28 AM10/26/23
to Wazuh | Mailing List
Hello Team,

It it possible to delete the default filter (cluster.name: wazuh) from wazuh-dashboard?

Thanks

Unknown

unread,
Oct 26, 2023, 7:55:43 AM10/26/23
to Wazuh | Mailing List
As I made it hidden in my wazuh-manager, so in my logs this key cluster doesn't exists due to which I am unable to see any logs on wazuh dashboard because of this default filter (cluster.name: wazuh)

Maximiliano Ibarra

unread,
Oct 26, 2023, 9:00:51 AM10/26/23
to Wazuh | Mailing List
Hello.
I understand, at this moment it's impossible to remove this default filter. The wazuh plugin uses it to filter the different modules events.
Logically, this should not affect the visibility of the events. But you can try to see the events uses the opensearch discover and check if it's a filter problem.

Screenshot 2023-10-26 at 09.55.24.png

Screenshot 2023-10-26 at 09.55.40.png

On the opensearch discover, the cluster.node is not applied. Check if you see events and apply the cluster node filter to check if it is the problem.

Unknown

unread,
Oct 26, 2023, 9:29:52 AM10/26/23
to Wazuh | Mailing List
Hello,
Thanks for the quick response.

Yeah, I can see the data in discover option as there is no default filter.
You can help me to remove this filter from wazuh-dashboard code base if it is not possible via UI/ Configuration Changes.

Regards

Unknown

unread,
Oct 31, 2023, 1:58:20 AM10/31/23
to Wazuh | Mailing List
Hello Team,

Waiting for the response.

Thanks.

Maximiliano Ibarra

unread,
Oct 31, 2023, 1:08:22 PM10/31/23
to Wazuh | Mailing List
Hi. Sorry, but the changes you want to make may bring many unexpected behaviors in Wazuh dashboard modules and features.
Can I ask you if you have modified the cluster configuration to a single node or changed the name of the manager/cluster?
Screenshot 2023-10-31 at 14.02.37.png
Because it can cause problems in the events filtering.
Reply all
Reply to author
Forward
0 new messages