Hello Juan,
Before starting to check the status of Wazuh, we recommend you to restart the services:
service wazuh-manager restart
After restarting let’s check the status of Wazuh’s daemons:
service wazuh-manager status
The last step of these first checks is to review the ossec.conf file to check for errors that may clarify what is happening:
tail -n30 /var/ossec/logs/ossec.log | grep -i -E "error|warn"
I look forward to hearing from you, if you have any questions please do not hesitate to ask.
There seems to be no errors and maild is running, we need to confirm that the problem persists, in which case, let’s check the logs for maild.
To do this let’s execute the following command:
cat /var/ossec/logs/ossec.log | grep -i "wazuh-maild"
In addition, if the error persists it might help to look at the maild configuration (suppressing email addresses) to see if we can replicate the error.
The configuration related to email alerts is in the global section of the ossec.conf file as indicated here: https://documentation.wazuh.com/current/user-manual/manager/manual-email-report/#generic-email-options
If the value of email_notification is yes and there are no errors in the ossec.log file then there should be no problem and everything will work as expected.
Another thing you can check is the value of email_alert_level in the alerts section, by default this value is 12, which means that you will only receive email alerts for levels equal or higher than 12. It is possible that no alerts are currently being generated for these levels.
Hi Juan,
I have been reviewing this error and have found a possible solution. Let’s try modifying the following line in the ossec.conf file:
<email_log_source>alerts.log</email_log_source>
to:
<email_log_source>alerts.json</email_log_source>
After this change has been made, we will restart:
service wazuh-manager restart
If the error persists after changing the alerts to .json format, try removing that line from the configuration.
This error should be fixed in the latest versions of Wazuh, I hope this solves the problem, otherwise I look forward to your response to further investigate the error knowing the version of Wazuh you use.
More information:

Hello Juan,
It is possible that the change is related to the email account used, this error:
Jun 14 09:52:03 elk-soc postfix/error[29329]: C56F360C48C7: to=<[x...@example.com](https://groups.google.com/)>, relay=none, delay=348776, delays=348775/1.8/0/0.01, dsn=4.7.8, status=deferred (delivery temporarily suspended: SASL authentication failed; server [smtp.gmail.com](http://smtp.gmail.com)[74.125.130.108] said: 535-5.7.8 Username and Password not accepted. Learn more at?535 5.7.8 [https://support.google.com/mail/?p=BadCredentials](https://support.google.com/mail/?p=BadCredentials) l20-20020a17090af8d400b001e02073474csm8205512pjd.36 - gsmtp)
This is because the Google account being used does not have the “less secure apps” option enabled. In order to authenticate through Postfix, the “less secure apps” option must be enabled for accounts that do not have two-factor authentication enabled: https://myaccount.google.com/lesssecureapps.
In case you do have two-factor authentication enabled you will need to create an application password, to do this you can follow these steps: https://support.google.com/accounts/answer/185833
Once you have done this and changed the settings (if you have created an application password), Postfix should be able to authenticate correctly.
Finally, I recommend you to update Wazuh to the latest stable version 4.3.4: https://documentation.wazuh.com/current/upgrade-guide/index.html