# curl https://raw.githubusercontent.com/wazuh/wazuh/3.6/extensions/elasticsearch/wazuh-elastic6-template-alerts.json -o template.json % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 19737 100 19737 0 0 48489 0 --:--:-- --:--:-- --:--:-- 48613
For example here is the end of the log from one of the Linux agents:
2018/08/31 12:50:06 ossec-agentd: INFO: Closing connection to server (wazuh2/192.168.1.241:1514/tcp). 2018/08/31 12:50:21 ossec-agentd: WARNING: Unable to reload hostname for 'wazuh2'. Using previous address. 2018/08/31 12:50:21 ossec-agentd: INFO: Trying to connect to server (wazuh2/192.168.1.241:1514/tcp). 2018/08/31 12:50:21 ossec-agentd: INFO: (4102): Connected to the server (wazuh2/192.168.1.241:1514/tcp). 2018/08/31 12:50:21 ossec-agentd: INFO: Server responded. Releasing lock. 2018/08/31 12:50:25 ossec-logcollector: INFO: Agent is now online. Process unlocked, continuing... 2018/08/31 13:31:16 wazuh-modulesd:syscollector: INFO: Starting evaluation. 2018/08/31 13:31:21 wazuh-modulesd:syscollector: INFO: Evaluation finished. 2018/08/31 14:31:16 wazuh-modulesd:syscollector: INFO: Starting evaluation. 2018/08/31 14:31:23 wazuh-modulesd:syscollector: INFO: Evaluation finished.
Hello Luke and Robert,
Apologies for the inconveniences. This is definitely not an intentional change but a bug. We’ve been able to reproduce it in our development environment, and we’ve created an issue in our GitHub repository to keep track on it.
We’ll fix it as soon as possible and include it on the next release.
In the meantime…
Discover button.agent.id field to filter them.Regards,
Juanjo
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/7ea9d1f9-c106-4e4d-a7dd-88677c2edc1e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Hello Luke and Robert,
Apologies for the inconveniences. This is definitely not an intentional change but a bug. We’ve been able to reproduce it in our development environment, and we’ve created an issue in our GitHub repository to keep track on it.We’ll fix it as soon as possible and include it on the next release.
In the meantime…
- On the Discover tab, you can still see a full list of alerts clicking on the
Discoverbutton.- On the Agents tab, you can see visualizations tailored for each specific agents, because we use the
agent.idfield to filter them.Regards,
Juanjo
El dom., 2 sept. 2018 a las 14:21, Luke escribió:
I've noticed this as well. I'm particularly curious if the change from agent.name to precoder.hostname is intentional or a bug? If it's a bug, I don't want to change all my visualizations to use precoder.hostname.--As Robert mentioned, the only hosts to show up under agent.name are my manager names - no agents.Thanks,
On Friday, August 31, 2018 at 7:59:41 PM UTC-4, Robert H wrote:Okay, I fixed my dashboard. I was using agent.name in the visualizations. I had to change that to predecoder.hostname.But my Top 5 Agent and most/all of the similar visuals on the Overview pages all seem off. Anything where agent names used to show up, now only shows my 2 managers or says no results, but there is alert data in the table views. Top agents for vulnerabilities, show no agent names in the box, but there is data in the graph, etc.I think something is mixed up in the app pages.Regards,Robert
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
Hello again Luke,
Yes, we’re planning to launch a point release on the next days (no specific ETA at the moment), including several bugfixes such as this one related to the agent.name field.
Thank you so much for your patience and feedback. This helps us a lot to continue improving Wazuh and we really appreciate that. Don’t hesitate to open a new thread on this mailing list, or open a new issue at our repositories everytime you have a problem or questions related to Wazuh.
Regards,
Juanjo
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/7ea9d1f9-c106-4e4d-a7dd-88677c2edc1e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6ab3bed6-b3dc-4887-b288-c497c2f987bf%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CABywkcYUDWOqvX485Rb6upU4Gsm%3Dutko7bSVDdvM%2ByL-qaw_LA%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/1d4cfdeb-e7dd-4797-96a5-f60003935731%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/7ea9d1f9-c106-4e4d-a7dd-88677c2edc1e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6ab3bed6-b3dc-4887-b288-c497c2f987bf%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CABywkcYUDWOqvX485Rb6upU4Gsm%3Dutko7bSVDdvM%2ByL-qaw_LA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
--
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6f71cf0c-0aee-4aab-be42-aa823969c0af%40googlegroups.com.
The system had been rebooted several times during the process
Saturday and Sunday - but yes, I agree - something did change
yesterday. And since Wazuh was running, just not reporting to the
dashboard - I just have to go through all the logs of alerts and
non-alerts to see if I can figure out what it was. Strangest
thing.
lsof /var/ossec/logs/alerts/alerts.json