Hello Team,
I have integrated Wazuh with YARA on Windows endpoints by following the official Wazuh documentation. However, I am not seeing any alerts being triggered from the YARA rules. The Wazuh agent and manager are running without errors, and YARA is installed properly, but the rules do not seem to generate alerts in Wazuh.
Could you please guide me on how to properly configure and validate the integration so that YARA rules will trigger alerts from Windows endpoints?
Thank you for your support.
I’ve tested this issue on my side, and it’s working fine here.
However, I used a different path since the Downloads folder contains unsupported names. After configuring it, the alerts didn’t appear on the dashboard. Then I changed the FIM configuration to a different path and updated the rules.
2025/09/14 10:19:23 wazuh-agent: WARNING: (6955): Ignoring file 'c:\users\hasit\downloads\agent connections - wazuh server cluster wazuh documentation.html' due to unsupported name (non-UTF8).