Hi,if possible, could you please write your next message entirely in English? This will help ensure we fully understand your issue and provide the most accurate assistance.
Understanding your problem:
Additional information needed:
tail -f /var/ossec/logs/cluster.log
tail -f /var/ossec/logs/ossec.log
Initial recommendations:
Please provide this information so we can help you identify the root cause and improve your cluster performance.


Step 1: Verify agent connection status on the Master
Run these commands on your Master node (in /var/ossec/bin/):# Count currently connected agents
Compare these numbers with what you see in the Wazuh Dashboard. Do they match?
Step 2: Monitor a specific disconnected agent
Identify one agent that shows as "disconnected" in the dashboard:
Step 3: Request agent-side logs
If the agent shows as disconnected on the manager side, please provide:
From the disconnected agent machine:

Thank you for providing the agent count information. I can see the numbers match between the manager and dashboard (880 active, 502 disconnected), which confirms the agents are genuinely disconnecting from the managers - this is not a synchronization or display issue.
Before we can recommend solutions to keep your agents active, we need to understand why they are disconnecting. This is crucial because the solution will depend on the root cause.
Could you please help us identify the problem by providing the following information:
1. Nature of the disconnections:
2. Agent-side logs (critical):
Please select 2-3 agents that are currently showing as "Disconnected" and share their logs:
For Windows agents:
3. Manager-side logs for specific agents:
On the Master node, check logs for those same disconnected agents:
Please, replace AGENT_NAME with the actual agent hostname.
4. Network/Firewall considerations:
Once you provide this information, we can determine the specific root cause and give you targeted recommendations to keep your agents connected reliably.