indexer-connector: WARNING: Failed to sync agent

130 views
Skip to first unread message

Ahmed Awwad

unread,
Jul 2, 2026, 3:16:24 AMJul 2
to Wazuh | Mailing List
 Hi everyone

I had just built a new Wazuh Cluster (3 Server nodes, 3 indexer nodes) + HAProxy LB
all build verification was good, but when onboarded a windows machine 
No logs received, Agent Status Active, Keepalive keep sending,, 
I had enabled Archive. * index, no logs 

I checked Master Node logs i found this 
grep -iE "indexer|inventory" /var/ossec/logs/ossec.log
2026/07/01 09:57:53 wazuh-modulesd:inventory-harvester: INFO: Stopping inventory_harvester module.
2026/07/01 09:57:53 logger-helper: INFO: Inventory harvester module stopped.
2026/07/01 09:57:56 wazuh-modulesd:inventory-harvester: INFO: Loaded Inventory harvester module.
2026/07/01 09:58:05 wazuh-modulesd:inventory-harvester: INFO: Loaded Inventory harvester module.
2026/07/01 09:58:05 wazuh-modulesd:inventory-harvester: INFO: Starting inventory_harvester module.
2026/07/01 09:58:06 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-packages-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:06 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-vulnerabilities-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:07 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-system-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:08 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-processes-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:09 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-ports-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:10 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-hotfixes-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:11 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-hardware-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:12 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-protocols-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:13 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-interfaces-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:14 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-networks-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:15 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-users-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:16 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-groups-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:17 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-browser-extensions-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:18 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-inventory-services-wazuh_cluster', retrying until the connection is successful.
2026/07/01 09:58:18 logger-helper: INFO: InventoryHarvesterFacade module started.
2026/07/01 13:19:19 wazuh-modulesd:inventory-harvester: INFO: Stopping inventory_harvester module.
2026/07/01 13:19:19 logger-helper: INFO: Inventory harvester module stopped.
2026/07/01 13:19:21 wazuh-modulesd:inventory-harvester[870585] wm_harvester.c:151 at wm_inventory_harvester_read(): INFO:Loaded Inventory harvester module.
2026/07/01 13:19:31 wazuh-modulesd:inventory-harvester[870959] wm_harvester.c:151 at wm_inventory_harvester_read(): INFO:Loaded Inventory harvester module.
2026/07/01 13:19:31 wazuh-modulesd[870959] main.c:105 at main(): DEBUG: Created new thread for the 'inventory_harvester' module.
2026/07/01 13:19:31 wazuh-modulesd:inventory-harvester[870959] wm_harvester.c:56 at wm_inventory_harvester_main(): INFO: Starting inventory_harvester module.
2026/07/01 13:19:31 wazuh-modulesd:inventory-harvester[870959] wm_harvester.c:48 at wm_inventory_harvester_log_config(): DEBUG: {"indexer":{"enabled":"yes","hosts":["https://<indexer-IP-03>:9200","https://<indexer-IP-02>:9200","https://<indexer-IP-01>:9200"],"ssl":{"certificate_authorities":["/etc/filebeat/certs/root-ca.pem"],"certificate":"/etc/filebeat/certs/wazuh-master.pem","key":"/etc/filebeat/certs/wazuh-master-key.pem"}},"clusterEnabled":true,"clusterName":"wazuh_cluster","cluste                                    rNodeName":"wazuh-master"}
2026/07/01 13:19:31 wazuh-modulesd:vulnerability-scanner[870959] wm_vulnerability_scanner.c:45 at wm_vulnerability_scanner_log_config(): DEBUG: {"vulnerability-detection":{"enabled":"yes","index-status":"yes","feed-update-interval":"60m","cti-url":"https://cti.wazuh.com/api/v1/catalog/contexts/vd_1.0.0/consumers/vd_.8.0"},"wmMaxEps":100,"translationLRUSize":2048,"osdataLRUSize":1000,"remediationLRUSize":2048,"managerDisabledScan":1,"reportQueueSize":262144,"indexer":{"enabled":"yes","hosts":["https://<indexer-IP-03>:9200","https://<indexer-IP-02>:9200","https://<indexer-IP-01>:9200"],"ssl":{"certificate_authorities":["/etc/filebeat/certs/root-ca.pem"],"certificate":"/etc/filebeat/certs/wazuh-master.pem","key":"/etc/filebeat/certs/wazuh-master-key.pem"}},"clusterEnabled":true,"clusterName":"wazuh_cluster","clusterNodeName":"wazuh-master"}
2026/07/01 13:19:31 logger-helper[870959] inventoryHarvesterFacade.cpp:29 at initInventoryDeltasSubscription(): DEBUG: InventoryHarvesterFacade::initInventoryDeltasSubscription: Initializing inventory deltas subscription.
2026/07/01 13:19:31 logger-helper[870959] inventoryHarvesterFacade.cpp:68 at initRsyncSubscription(): DEBUG: InventoryHarvesterFacade::initInventoryRsyncSubscription: Initializing inventory rsync subscription.
2026/07/01 13:19:31 logger-helper[870959] inventoryHarvesterFacade.cpp:210 at initSystemEventDispatcher(): DEBUG: InventoryHarvesterFacade::initSystemEventDispatcher: Initializing system event dispatcher.
2026/07/01 13:19:31 logger-helper[870959] systemInventoryOrchestrator.hpp:80 at SystemInventoryOrchestrator(): DEBUG: SystemInventoryOrchestrator constructor
2026/07/01 13:19:31 monitoring[870959] monitoring.hpp:146 at operator()(): DEBUG: Health check failed for 'https://<indexer-IP-03>:9200' - Unauthorized - Check indexer credentials
2026/07/01 13:19:31 monitoring[870959] monitoring.hpp:146 at operator()(): DEBUG: Health check failed for 'https://<indexer-IP-03>:9200' - Unauthorized - Check indexer credentials
2026/07/01 13:19:31 monitoring[870959] monitoring.hpp:146 at operator()(): DEBUG: Health check failed for 'https://<indexer-IP-02>:9200' - Unauthorized - Check indexer credentials
2026/07/01 13:19:31 monitoring[870959] monitoring.hpp:146 at operator()(): DEBUG: Health check failed for 'https://<indexer-IP-02>:9200' - Unauthorized - Check indexer credentials
2026/07/01 13:19:32 monitoring[870959] monitoring.hpp:146 at operator()(): DEBUG: Health check failed for 'https://<indexer-IP-01>:9200' - Unauthorized - Check indexer credentials
2026/07/01 13:19:32 monitoring[870959] monitoring.hpp:146 at operator()(): DEBUG: Health check failed for 'https://<indexer-IP-01>:9200' - Unauthorized - Check indexer credentials

then This agent is managed by Server-01 (worker) 
cat /var/ossec/var/run/wazuh-remoted.state # State file for wazuh-remoted # THIS FILE WILL BE DEPRECATED IN FUTURE VERSIONS # Updated every 5 seconds. # Queue size queue_size='0' # Total queue size total_queue_size='131072' # TCP sessions tcp_sessions='1' # Events sent to Analysisd evt_count='36953' # Control messages received ctrl_msg_count='517' # Discarded messages discarded_count='0' # Total number of bytes sent sent_bytes='49699' # Total number of bytes received recv_bytes='19937012' and wazuh-server-01:~# tail -f /var/ossec/logs/ossec.log 2026/07/01 12:39:13 indexer-connector: WARNING: Failed to sync agent '001': No available server 2026/07/01 12:39:13 indexer-connector: WARNING: Failed to sync agent '001': No available server 2026/07/01 12:49:07 agent_control: ERROR: Wazuh is running in cluster mode: agent_control is not available in worker nodes. Please, try again in the master node: <master-IP>

I tried to fix any missing certificate from worker Servers until filebeat test output is okay
wazuh-server-01:~# filebeat test output elasticsearch: [https://<indexer01>:9200](https://<Indexer01-IP>:9200)... parse url... OK connection... parse host... OK dns lookup... OK addresses: [<indexer01>] dial up... OK TLS... security: server's certificate chain verification is enabled handshake... OK TLS version: TLSv1.2 dial up... OK talk to server... OK version: 7.10.2 elasticsearch: [https://](https:// <Indexer02-IP>  :9200)]... parse url... OK connection... parse host... OK dns lookup... OK addresses: [<indexer02>] dial up... OK TLS... security: server's certificate chain verification is enabled handshake... OK TLS version: TLSv1.2 dial up... OK talk to server... OK version: 7.10.2 elasticsearch: [https://](https:// <Indexer03-IP>  :9200)] parse url... OK connection... parse host... OK dns lookup... OK addresses: [<indexer03>] dial up... OK TLS... security: server's certificate chain verification is enabled handshake... OK TLS version: TLSv1.2 dial up... OK talk to server... OK version: 7.10.2

when i "tail -f /var/ossec/logs/ossec.log" at Server-01
2026/07/01 12:39:13 indexer-connector: WARNING: Failed to sync agent '001': No available server
2026/07/01 12:39:13 indexer-connector: WARNING: Failed to sync agent '001': No available server
2026/07/01 12:49:07 agent_control: ERROR: Wazuh is running in cluster mode: agent_control is not available in worker nodes. Please, try again in the master node: <master-IP> .
2026/07/01 12:54:14 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2026/07/01 12:54:36 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2026/07/01 13:32:57 agent_control: ERROR: Wazuh is running in cluster mode: agent_control is not available in worker nodes  . Please, try again in the master node: <master-IP> .
2026/07/01 13:54:37 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2026/07/01 13:54:59 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2026/07/01 14:55:01 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2026/07/01 14:55:22 wazuh-modulesd:syscollector: INFO: Evaluation finished.

 
  tail -f /var/ossec/logs/ossec.log | grep -i indexer
root@wazuh-server-01:/var/ossec/etc# tail -f /var/ossec/logs/ossec.log
2026/07/01 15:47:01 wazuh-modulesd: WARNING: Could not connect to socket 'queue/cluster/c-internal.sock': Connection refused (111).
2026/07/01 15:47:02 wazuh-modulesd: WARNING: Could not connect to socket 'queue/cluster/c-internal.sock': Connection refused (111).
2026/07/01 15:47:03 wazuh-modulesd: WARNING: Could not connect to socket 'queue/cluster/c-internal.sock': Connection refused (111).
2026/07/01 15:47:04 wazuh-modulesd: WARNING: Could not connect to socket 'queue/cluster/c-internal.sock': Connection refused (111).
2026/07/01 15:47:05 wazuh-modulesd: WARNING: Could not connect to socket 'queue/cluster/c-internal.sock': Connection refused (111).
2026/07/01 15:47:06 rootcheck: INFO: Ending rootcheck scan.
2026/07/01 15:47:06 wazuh-modulesd: WARNING: Could not connect to socket 'queue/cluster/c-internal.sock': Connection refused (111).
2026/07/01 15:47:07 wazuh-modulesd: WARNING: Cluster error detected
2026/07/01 15:47:07 wazuh-modulesd: ERROR: Could not send message through the cluster after '10' attempts.
2026/07/01 15:47:07 wazuh-modulesd:agent-upgrade: ERROR: (8123): There has been an error executing the request in the tasks manager.
here is the Agent ossec.conf

<!--
  Wazuh - Agent - Default configuration for Windows
  More info at: https://documentation.wazuh.com
  Mailing list: https://groups.google.com/forum/#!forum/wazuh
-->

 

<ossec_config>

   <client>

<server>
<address><LoadBalacer-IP></address>
<port>1514</port>
<protocol>tcp</protocol>
</server>
<config-profile>windows, windows10</config-profile>
<crypto_method>aes</crypto_method>
<notify_time>20</notify_time>
<time-reconnect>60</time-reconnect>
<auto_restart>yes</auto_restart>
<enrollment>
<enabled>yes</enabled>
<groups>Endpoints,Testing,Windows</groups>
</enrollment>
</client>

   <!-- Agent buffer options -->

<client_buffer>
<disabled>no</disabled>
<queue_size>5000</queue_size>
<events_per_second>500</events_per_second>
</client_buffer>

   <!-- Log analysis -->

<localfile>
<location>Application</location>
<log_format>eventchannel</log_format>
</localfile>

   <localfile>

<location>Security</location>
<log_format>eventchannel</log_format>
<query>Event/System[EventID != 5145 and EventID != 5156 and EventID != 5447 and
      EventID != 4656 and EventID != 4658 and EventID != 4663 and EventID != 4660 and
      EventID != 4670 and EventID != 4690 and EventID != 4703 and EventID != 4907 and
      EventID != 5152 and EventID != 5157]</query>
</localfile>

   <localfile>

<location>System</location>
<log_format>eventchannel</log_format>
</localfile>

   <localfile>

<location>active-response\active-responses.log</location>
<log_format>syslog</log_format>
</localfile>

   <!-- Policy monitoring -->

<rootcheck>
<disabled>no</disabled>
<windows_apps>./shared/win_applications_rcl.txt</windows_apps>
<windows_malware>./shared/win_malware_rcl.txt</windows_malware>
</rootcheck>

   <!-- Security Configuration Assessment -->

<sca>
<enabled>yes</enabled>
<scan_on_start>yes</scan_on_start>
<interval>12h</interval>
<skip_nfs>yes</skip_nfs>
</sca>

   <!-- File integrity monitoring -->

<syscheck>

     <disabled>no</disabled>

 <!-- Frequency that syscheck is executed default every 12 hours -->

<frequency>43200</frequency>

     <!-- Default files to be monitored. -->

<directories recursion_level="0" restrict="regedit.exe$|system.ini$|win.ini$">%WINDIR%</directories>

     <directories recursion_level="0" restrict="at.exe$|attrib.exe$|cacls.exe$|cmd.exe$|eventcreate.exe$|ftp.exe$|lsass.exe$|net.exe$|net1.exe$|netsh.exe$|reg.exe$|regedt32.exe|regsvr32.exe|runas.exe|sc.exe|schtasks.exe|sethc.exe|subst.exe$">%WINDIR%\SysNative</directories>

<directories recursion_level="0">%WINDIR%\SysNative\drivers\etc</directories>
<directories recursion_level="0" restrict="WMIC.exe$">%WINDIR%\SysNative\wbem</directories>
<directories recursion_level="0" restrict="powershell.exe$">%WINDIR%\SysNative\WindowsPowerShell\v1.0</directories>
<directories recursion_level="0" restrict="winrm.vbs$">%WINDIR%\SysNative</directories>

     <!-- 32-bit programs. -->

<directories recursion_level="0" restrict="at.exe$|attrib.exe$|cacls.exe$|cmd.exe$|eventcreate.exe$|ftp.exe$|lsass.exe$|net.exe$|net1.exe$|netsh.exe$|reg.exe$|regedit.exe$|regedt32.exe$|regsvr32.exe$|runas.exe$|sc.exe$|schtasks.exe$|sethc.exe$|subst.exe$">%WINDIR%\System32</directories>
<directories recursion_level="0">%WINDIR%\System32\drivers\etc</directories>
<directories recursion_level="0" restrict="WMIC.exe$">%WINDIR%\System32\wbem</directories>
<directories recursion_level="0" restrict="powershell.exe$">%WINDIR%\System32\WindowsPowerShell\v1.0</directories>
<directories recursion_level="0" restrict="winrm.vbs$">%WINDIR%\System32</directories>

     <directories realtime="yes">%PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\Startup</directories>

     <ignore>%PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini</ignore>

     <ignore type="sregex">.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$</ignore>

     <!-- Windows registry entries to monitor. -->

<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\batfile</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\cmdfile</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\comfile</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\exefile</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\piffile</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Directory</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Folder</windows_registry>
<windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Classes\Protocols</windows_registry>
<windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Policies</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Security</windows_registry>
<windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer</windows_registry>

 <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services</windows_registry>

<windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg</windows_registry>

     <windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</windows_registry>

<windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce</windows_registry>
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx</windows_registry>
<windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL</windows_registry>
<windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies</windows_registry>
<windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows</windows_registry>
<windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon</windows_registry>

     <windows_registry arch="both">HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components</windows_registry>

     <!-- Windows registry entries to ignore. -->

<registry_ignore>HKEY_LOCAL_MACHINE\Security\Policy\Secrets</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users</registry_ignore>
<registry_ignore type="sregex">\Enum$</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpsSvc\Parameters\AppCs</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpsSvc\Parameters\PortKeywords\DHCP</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpsSvc\Parameters\PortKeywords\IPTLSIn</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpsSvc\Parameters\PortKeywords\IPTLSOut</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpsSvc\Parameters\PortKeywords\RPC-EPMap</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpsSvc\Parameters\PortKeywords\Teredo</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PolicyAgent\Parameters\Cache</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx</registry_ignore>
<registry_ignore>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ADOVMPPackage\Final</registry_ignore>

     <!-- Frequency for ACL checking (seconds) -->

<windows_audit_interval>60</windows_audit_interval>

     <!-- Nice value for Syscheck module -->

<process_priority>10</process_priority>

     <!-- Maximum output throughput -->

<max_eps>50</max_eps>

     <!-- Database synchronization settings -->

<synchronization>
<enabled>yes</enabled>
<interval>5m</interval>
<max_eps>10</max_eps>
</synchronization>
</syscheck>

   <!-- System inventory -->

<wodle name="syscollector">
<disabled>no</disabled>
<interval>1h</interval>
<scan_on_start>yes</scan_on_start>
<hardware>yes</hardware>
<os>yes</os>
<network>yes</network>
<packages>yes</packages>
<ports all="yes">yes</ports>
<processes>yes</processes>
<users>yes</users>
<groups>yes</groups>
<services>yes</services>
<browser_extensions>yes</browser_extensions>

     <!-- Database synchronization settings -->

<synchronization>
<max_eps>10</max_eps>
</synchronization>
</wodle>

   <!-- CIS policies evaluation -->

<wodle name="cis-cat">
<disabled>yes</disabled>
<timeout>1800</timeout>
<interval>1d</interval>
<scan-on-start>yes</scan-on-start>

     <java_path>\\server\jre\bin\java.exe</java_path>

<ciscat_path>C:\cis-cat</ciscat_path>
</wodle>

   <!-- Osquery integration -->

<wodle name="osquery">
<disabled>yes</disabled>
<run_daemon>yes</run_daemon>
<bin_path>C:\Program Files\osquery\osqueryd</bin_path>
<log_path>C:\Program Files\osquery\log\osqueryd.results.log</log_path>
<config_path>C:\Program Files\osquery\osquery.conf</config_path>
<add_labels>yes</add_labels>
</wodle>

   <!-- Active response -->

<active-response>
<disabled>no</disabled>
<ca_store>wpk_root.pem</ca_store>
<ca_verification>yes</ca_verification>
</active-response>

   <!-- Choose between plain or json format (or both) for internal logs -->

<logging>
<log_format>plain</log_format>
</logging>

 </ossec_config>

 <!-- END of Default Configuration. -->

What i am missing here because, everything was good at the build as the documentation and test but now things mess up.

Md. Nazmur Sakib

unread,
Jul 2, 2026, 7:47:13 AMJul 2
to Wazuh | Mailing List
Hi Ahmed, 

Your Google Group issue went to Google's automated spam filter. We were not able to track it. I have marked it as not spam and am looking into it.

Please allow me some time.

Md. Nazmur Sakib

unread,
Jul 2, 2026, 8:34:44 AMJul 2
to Wazuh | Mailing List

You have the agent connected to your manager and sending keep-alive messages, but you do not have logs from the agent in the archive.
Just to confirm, go to the Wazuh dashboard. Go to Agents management > Summary and check if the agents show as active. Deploy new agent button One more thing to consider. Archives must be enabled on ALL 3 server nodes. The agent could be reporting to any of the 3 workers via HAProxy. If you enabled logall_json on only one node, events landing on the other two never get archived. On every server node:

<ossec_config> <global> <logall>yes</logall> <logall_json>yes</logall_json> </global> </ossec_config>

And restart the manager. I think the issue is related to the communication between the agent - LB- manager.

Can you check your agent’s ossec log to see if you can see any errors or warnings?


Linux/Unix /var/ossec/logs/ossec.log


macOS /Library/Ossec/logs/ossec.log


Windows C:\Program Files (x86)\ossec-agent\ossec.log


Also, for testing, can you point one of the agent’s IP directly to the manager node instead of the LB?

This is just to confirm the issue is related to the LB.

<client>

    <server>

        <address>10.0.0.10</address>

        <port>1514</port>

        <protocol>tcp</protocol>

    </server>

Update the IP, save the configuration and restart the agent.

Now try to generate some logs.

If you still do not get any logs in the archive, check the network connection following this doc:
Verifying communication with the Wazuh manager


If you get logs in after pointing directly to the manager, share the LB configuration so that I can review it from my end.

Hide any sensitive information like public IP.

I look forward to your update.

Ahmed Awwad

unread,
Jul 6, 2026, 12:27:52 AMJul 6
to Wazuh | Mailing List
Hey  Md. Nazmur Sakib

Thanks for your time first , 

secondly the agent status is active 

Screenshot 2026-07-05 101149.png

I enabled Archive at all 3 Server Nodes . (still no logs at all at archives.*)

I checked /var/ossec/logs/ossec.log
at 3 servers :
Master: 
 tail -f /var/ossec/logs/ossec.log
2026/07/05 06:57:17 indexer-connector: INFO: IndexerConnector initialized successfully for index: wazuh-states-inventory-services-wazuh_cluster.
2026/07/05 06:57:17 wazuh-logcollector: INFO: (9203): Monitoring journal entries.
2026/07/05 06:57:17 wazuh-syscheckd: INFO: (6009): File integrity monitoring scan ended.
2026/07/05 06:57:17 wazuh-syscheckd: INFO: FIM sync module started.
2026/07/05 06:57:17 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2026/07/05 06:57:24 wazuh-remoted: WARNING: Multigroup 'Endpoints,Testing,Windows' was modified from outside, so it was regenerated.
2026/07/05 06:57:24 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/07/05 06:57:24 sca: INFO: Security Configuration Assessment scan finished. Duration: 8 seconds.
2026/07/05 06:57:44 wazuh-syscheckd: INFO: netstat not available. Skipping port check.
2026/07/05 06:57:49 rootcheck: INFO: Ending rootcheck scan.

Server-01: 
tail -f /var/ossec/logs/ossec.log
2026/07/05 06:54:14 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_ubuntu24-04.yml'
2026/07/05 06:54:14 sca: INFO: Security Configuration Assessment scan finished. Duration: 9 seconds.
2026/07/05 06:54:35 wazuh-modulesd: WARNING: Cluster error detected
2026/07/05 06:54:36 wazuh-modulesd: WARNING: Cluster error detected
2026/07/05 06:54:37 wazuh-modulesd: WARNING: Cluster error detected
2026/07/05 06:54:38 wazuh-modulesd: WARNING: Cluster error detected
2026/07/05 06:54:38 wazuh-syscheckd: INFO: netstat not available. Skipping port check.
2026/07/05 06:54:39 wazuh-modulesd: WARNING: Cluster error detected
2026/07/05 06:54:40 wazuh-modulesd: WARNING: Cluster error detected

2026/07/05 06:54:44 rootcheck: INFO: Ending rootcheck scan.

I enabled Debug mode =1 at  /var/ossec/logs/internal_options.conf # Unix agentd
agent.debug=1

# Wazuh DB debug level
wazuh_db.debug=1

wazuh_modules.debug=1

# Wazuh Cluster debug level
wazuh_clusterd.debug=1

tail -f /var/ossec/logs/ossec.log
2026/07/05 07:09:49 wazuh-db[621432] main.c:427 at run_worker(): DEBUG: Client 26 disconnected.
2026/07/05 07:09:49 wazuh-db[621432] main.c:365 at run_dealer(): DEBUG: New client connected (26).
2026/07/05 07:09:49 wazuh-db[621432] main.c:427 at run_worker(): DEBUG: Client 26 disconnected.
2026/07/05 07:09:55 wazuh-db[621432] main.c:365 at run_dealer(): DEBUG: New client connected (26).
2026/07/05 07:09:55 wazuh-db[621432] main.c:427 at run_worker(): DEBUG: Client 26 disconnected.
2026/07/05 07:09:58 :router[621432] logging_helper.c:37 at taggedLogFunction(): DEBUG: GET: /v1/agents/sync request processed in 258 us
2026/07/05 07:09:59 wazuh-db[621432] main.c:365 at run_dealer(): DEBUG: New client connected (22).
2026/07/05 07:09:59 wazuh-db[621432] main.c:427 at run_worker(): DEBUG: Client 22 disconnected.
2026/07/05 07:09:59 wazuh-db[621432] main.c:365 at run_dealer(): DEBUG: New client connected (22).
2026/07/05 07:09:59 wazuh-db[621432] main.c:427 at run_worker(): DEBUG: Client 22 disconnected.
2026/07/05 07:10:05 wazuh-db[621432] main.c:365 at run_dealer(): DEBUG: New client connected (22).
2026/07/05 07:10:05 wazuh-db[621432] main.c:427 at run_worker(): DEBUG: Client 22 disconnected.
2026/07/05 07:10:08 :router[621432] logging_helper.c:37 at taggedLogFunction(): DEBUG: GET: /v1/agents/sync request processed in 262 us


I checked Connection Agent -> LB  at Ports 1514,1515,55000
true for 1514 and 1515
but failed for 55000 (wasn't mentioned in documentation to be allowed)

I tested connection from Agent -> Wazuh-server-01 (direct) at  Ports 1514,1515,55000
True for all

then I changed the client config to point directly to Wazuh-server-01

<client>

    <server>

        <address><Wazuh-server-01-IP></address>

        <port>1514</port>

        <protocol>tcp</protocol>

    </server>


Saved 
Restarted agent service 
Restarted Server-manager at Wazuh-server-01 

Still no logs appear at the Archive index GUI

but i checked the following:

I generated a custom log at the Test machine 

New-EventLog -LogName Application -Source "WazuhTestScript"

Write-EventLog -LogName Application -Source "WazuhTestScript-1" -EntryType Warning -EventId 999 -Message "Wazuh Test: Unintended login attempt detected on backend database."

at Wazuh-server-01: 
tail -f /var/ossec/logs/archives/archives.log
wazuh_ad pts/0        <My-IP>   Mon Jun 15 09:11 - 09:11  (00:00)
wazuh_ad pts/0        <My-IP>   Mon Jun 15 08:31 - 09:06  (00:34)
wazuh_ad pts/0        <My-IP>   Thu Jun  4 10:50 - 10:53  (00:02)
wazuh_ad pts/3        tmux(26601).%0   Thu May 14 12:09   still logged in
wazuh_ad pts/2        <PC-Test-IP>       Thu May 14 12:08 - 12:28  (00:20)
wazuh_ad pts/0        <PC-Test-IP>       Thu May 14 11:29 - 14:05  (02:36)
wazuh_ad pts/0        <Wazuh-server02-IP>   Wed May  6 13:18 - 13:19  (00:00)
wazuh_ad pts/0        <Wazuh-master-IP>   Wed May  6 13:11 - 13:11  (00:00)
reboot   system boot  6.8.0-111-generi Wed May  6 10:38   still running
wtmp begins Wed May  6 10:38:59 2026
2026 Jul 05 08:00:34 (PC-TestH) any->EventChannel {"win":{"system":{"providerName":"WazuhTestScript","eventID":"999","version":"0","level":"3","task":"1","opcode":"0","keywords":"0x80000000000000","systemTime":"2026-07-05T08:00:34.0959838Z","eventRecordID":"18805","processID":"31412","threadID":"0","channel":"Application","computer":"PC-TestH.rshq.local","severityValue":"WARNING","message":"\"Wazuh Test: Unintended login attempt detected on backend database.\""},"eventdata":{"data":"Wazuh Test: Unintended login attempt detected on backend database."}}}

When i change back the agent config to connect to LB
 <client>

    <server>

        <address><LB-IP></address>

        <port>1514</port>

        <protocol>tcp</protocol>

    </server> 

and regenerated the custom Event 

New-EventLog -LogName Application -Source "WazuhTestScript"

Write-EventLog -LogName Application -Source "WazuhTestScript-1" -EntryType Warning -EventId 999 -Message "Wazuh Test: Unintended login attempt detected on backend database."

at Wazuh-server-02:
 tail -f /var/ossec/logs/archives/archives.log
2026 Jul 05 08:15:20 wazuh-server-02->journald Jul 05 08:15:19 wazuh-server-02 systemd[1]: fwupd-refresh.service: Deactivated successfully.
2026 Jul 05 08:15:20 wazuh-server-02->journald Jul 05 08:15:19 wazuh-server-02 systemd[1]: Finished fwupd-refresh.service - Refresh fwupd metadata and update motd.
2026 Jul 05 08:15:36 (PC-TestH) any->EventChannel {"win":{"system":{"providerName":"LMS","eventID":"2128","version":"0","level":"4","task":"3","opcode":"0","keywords":"0x80000000000000","systemTime":"2026-07-05T08:15:36.3110109Z","eventRecordID":"18816","processID":"5536","threadID":"0","channel":"Application","computer":"PC-TestH.rshq.local","severityValue":"INFORMATION","message":"\"W/A for User Initiated Connection Succeeded\""}}}
2026 Jul 05 08:16:04 (PC-TestH) any->EventChannel {"win":{"system":{"providerName":"WazuhTestScript","eventID":"999","version":"0","level":"3","task":"1","opcode":"0","keywords":"0x80000000000000","systemTime":"2026-07-05T08:16:04.8697196Z","eventRecordID":"18817","processID":"31412","threadID":"0","channel":"Application","computer":"PC-TestH.rshq.local","severityValue":"WARNING","message":"\"Wazuh Test: Unintended login attempt detected on backend database.\""},"eventdata":{"data":"Wazuh Test: Unintended login attempt detected on backend database."}}}

and here is the agent status 

Screenshot 2026-07-05 111739.png


and No logs showed at the Archives at the GUI side yet
but the cluster give a green status so i don't have any clue

Md. Nazmur Sakib

unread,
Jul 6, 2026, 2:23:54 AMJul 6
to Wazuh | Mailing List
From this log, it seems the cluster is not configured correctly.

2026/07/01 15:47:01 wazuh-modulesd: WARNING: Could not connect to socket 'queue/cluster/c-internal.sock': Connection refused (111).


Can you also share your cluster status? Check if all the managers are connected.

/var/ossec/bin/cluster_control -l


The output should be something like this:

NAME                      TYPE       VERSION  ADDRESS
wazuh-master         master   4.14.2       10.0.0.9
wazuh-server-01    worker    4.14.2       10.0.0.10
wazuh-server-01    worker    4.14.2       10.0.0.11


If you see the nodes are not connected, review the cluster configuration.
Wazuh cluster nodes configuration


Also ensure that the cluster TCP port 1516 (reference) is open on all nodes. Check and ensure that there is no firewall restriction.

Let me know the update on this.

Ahmed Awwad

unread,
Jul 6, 2026, 7:37:45 AMJul 6
to Wazuh | Mailing List

here is the cat /var/ossec/etc/ossec.conf for each nodes servers 
root@wazuh-master~# cat varossecetc.txt
root@wazuh-server-02~# cat varossec.txt
root@wazuh-server-01~# cat varossec.txt

Ahmed Awwad

unread,
Jul 6, 2026, 7:37:46 AMJul 6
to Wazuh | Mailing List
root@wazuh-master:/etc/netplan# /var/ossec/bin/cluster_control -l
NAME             TYPE    VERSION  ADDRESS
wazuh-master     master  4.14.5   <Master-IP>
wazuh-server-02  worker  4.14.5   <Server-01-IP>
wazuh-server-01  worker  4.14.5    <Server-02-IP>

regarding firewall restriction , there is no firewall between node , they are same vlan and they are VMS so no firewall connection preventing it
but is there any internal firewall services should i check and allow ?

Md. Nazmur Sakib

unread,
Jul 10, 2026, 1:11:22 AM (13 days ago) Jul 10
to Wazuh | Mailing List

Sorry for the delay. I was discussing your issue with the internal team. I somehow overlooked some information you shared. There are archived logs on both of the worker nodes. The agent connected to the worker nodes and forwarded the logs from the agent to the worker nodes.

I believe if you check the alerts log on the worker nodes, you will also see the alerts log there.

The path of the alerts log is
/var/ossec/logs/alerts/alerts.json

So if you see the alert logs in this path on any of your Wazuh manager nodes, that confirms that your Wazuh manager is generating logs.
tail -f  /var/ossec/logs/alerts/alerts.json

But if they are still missing from your dashboard, Next we should check if Filebeat is forwarding the logs.

I can see from your Filebeat test output no error.

You are using the correct version of Filebeat, which is 7.10.2.

Check the Filebeat logs.

cat /var/log/filebeat/filebeat* | grep -iE "error|warn"


Also share the filebeat configurations.

cat /etc/filebeat/filebeat.yml

cat /usr/share/filebeat/module/wazuh/alerts/manifest.yml

Next, go to the dashboard UI.

Indexer Management > Dev Tools

And run this command. Check if you can see any alert indices(wazuh-alerts-4.x-).

GET _cat/indices


I will look forward to your update.

Reply all
Reply to author
Forward
0 new messages