Hi,
I have a distributed Wazuh (4.12.0) and I'm ingesting logs from Zeek and Suricata among my other agents, and in the manager I get this error:
tail -f /var/ossec/logs/ossec.log
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
2026/06/02 17:32:14 wazuh-analysisd: ERROR: Too many fields for JSON decoder.
I have added to the end of this file /var/ossec/etc/internal_options.conf:
analysisd.json_max_fields=4096
And yet the error persists, How can I fix this?
Atte,
Henry