Hello everyone.
I've been using Wazuh for same time and because the logs was growing I was left without space so I've use the "Index lifecycle management" from the manual to set the logs retention policy. But after some time I've discovered that dashboard is not showing any alerts on the dashboard, so I decided to remove the retention policy rule and in a hurry I've deleted maybe by mistake in Reporting, some reports rule.
Can someone help me please solve this issue, I want my dashboard to be populated again.
1. The agents are active and there are events (I receive them in slack)
2. All the services are running fine (
wazuh-manager wazuh-indexer wazuh-dashboard filebeat
)
3. sudo journalctl -u open --no-pager | grep -E 'ERROR|WARN - shows no errors
Output from different commands can be found in attached screenshots...
Thank you in advance.
*Using Wazuh OVA 4.14.1