agents log not shown in dashboard

541 views
Skip to first unread message

USHA GIRI

unread,
Mar 28, 2022, 1:18:58 AM3/28/22
to Wazuh mailing list
Hello Team, 
      Although the installation is completed and sucessfull, i am not able to see events, dashboard in security events or any other modules of the agents, The agents are also connected, active. The configuration files are also configured and edited in both manager and agent's side. 
#help
Thank You, mail.PNG

Juan Carlos

unread,
Mar 28, 2022, 4:50:23 AM3/28/22
to Wazuh mailing list
Hi Usha,

This can happen if alerts are not being indexed. Given that the Wazuh manager and Elasticsearch seem to be functioning properly then Filebeat may have a configuration issue or its service may not be running.

Verify the service status with the command: systemctl status filebeat and if it isn't running enable and start it

You may also verify the configuration and connectivity of Filebeat to Elasticsearch by executing: filebeat test output

Let us know what the output of these commands are if you're still facing the issue and we'll be glad to help you.

Best Regards,
Juan C. Tello

USHA GIRI

unread,
Mar 30, 2022, 10:00:14 AM3/30/22
to Wazuh mailing list
Hello, 
    The problem solved after serveral restart to wazuh-manager, elasticsearch, kibana and filebeat. But, i have a question, this kind of problem seems repetitive and it solves by itself after a day or two without any change in the configuration, what is the issue or cause of these problem?
Thankyou

Juan Carlos

unread,
Apr 4, 2022, 4:26:32 AM4/4/22
to Wazuh mailing list
Hi,
With the current information it is difficult to determine a specific cause, but this can occur if due to lack of resources one of the services fails to start at boot up.

I recommend finding out a specific period of time when this has failed and looking at the logs around that time for specific errors. The relevant files are: /var/log/filebeat/filebeat*, /var/log/elasticsearch/* and var/ossec/logs/wazuh/*/*/*.log*

Please, let us know if you have any more questions.
Best Regards,
Juan C. Tello

Reply all
Reply to author
Forward
0 new messages