Hello dear wazuh team,
I have a had a threat about this in the past because my Windows Wazuh agents did not return whodata auditing information to the manager.
After scrolling through the wazuh agent logs I now found the exact error message:
wazuh-agent: ERROR: (6621): Event Channel subscription could not be made. Whodata scan is disabled.
wazuh-agent: ERROR: (6710): Failed to start the Whodata engine. Directories/files will be monitored in Realtime mode
These two log lines always appear right after another so one should definitely cause the other.
The question now is why the event channel subscription could not be made AND why it is necessary for whodata.
Searching google and this forum I could not find an answer so I hope to get one here.
Thanks a lot in advance!
Cheers
Sebastian