Problems Status Wazuh

76 views
Skip to first unread message

Edeivy Palma

unread,
Oct 13, 2023, 1:43:14 PM10/13/23
to Wazuh | Mailing List
How to Fix Problem Status wazuh agent disconnected to Active

Marcos Javier Bonacci

unread,
Oct 13, 2023, 2:50:34 PM10/13/23
to Wazuh | Mailing List

Hi Edeivy

Thanks for using Wazuh

To fix the problem of the Wazuh agent being disconnected from Active, you can try the following steps:

  1. Check the network connectivity between the Wazuh agent and the Wazuh manager. Ensure that there are no firewall rules blocking the communication. You can use: telnet <Wazuh_administrator_IP> 1514

  2. Verify that the Wazuh agent is running with systemctl status wazuh-agent on Linux systems or the sc query wazuh-agent command on Windows systems.  Check the agent configuration file and make sure it has the correct IP address and port of the Wazuh manager. The agent configuration file is located in /var/ossec/etc/ossec.conf on Linux systems or in C:\Program Files (x86)\ossec-agent\ossec.conf on Windows systems.

  3. Restart the Wazuh agent service. Sometimes a simple restart can resolve the disconnection issue. Use the systemctl restart wazuh-agent command on Linux systems or the sc stop wazuh-agent command followed by the sc start wazuh-agent command on Windows systems to restart the agent service.

  4. Check the logs of both the Wazuh agent and the Wazuh manager for any error messages or warnings related to the disconnection. This can provide valuable information for troubleshooting. The agent logs are located in /var/ossec/logs/ossec.log on Linux systems or in C:\Program Files (x86)\ossec-agent-logs/ossec.log on Windows systems. Administrator logs are located in /var/ossec/logs/ossec.log on Linux systems

I remain attentive to your comments.
Regards,
Javier

Edeivy Palma

unread,
Oct 13, 2023, 5:10:18 PM10/13/23
to Wazuh | Mailing List
When I want to put the part of systemctl status wazuh-agent I get this result
servicio agente.png

Marcos Javier Bonacci

unread,
Oct 16, 2023, 8:14:25 AM10/16/23
to Wazuh | Mailing List
Hello Edeivy,
Correct me if I'm wrong, but have you run the systemctl status wazuh-agent command on the server? That command is to validate the agent status. For the wazuh-manager status, the command to use is: systemctl status wazuh-manager
I attach an image of the Wazuh components to graph the difference.
Regards,
Javier
Wazuh components and data flow

Edeivy Palma

unread,
Oct 16, 2023, 10:34:16 AM10/16/23
to Wazuh | Mailing List

That's right, this comes up when I check the systemctl status wazuh-agent
servicio agente.png

Marcos Javier Bonacci

unread,
Oct 23, 2023, 10:06:25 AM10/23/23
to Wazuh | Mailing List

Edeivy, have you solved the connection problems with the wazuh agent?
I look forward to your comments
Regards,
Javier
Reply all
Reply to author
Forward
0 new messages