IT Hygiene

224 views
Skip to first unread message

pdnb

unread,
Oct 2, 2025, 10:00:34 AMOct 2
to Wazuh | Mailing List
Hi i just upgrade wazuh 4.13.0 and i use RBAC to control users. how to setup permission for IT Hygiene module ?

i try setup 
wazuh-states-inventory-*  for role on index side , but without success

Luis Enrique Chico Capistrano

unread,
Oct 2, 2025, 11:58:05 AMOct 2
to Wazuh | Mailing List
Hi pdnb,
Please allow me some time; I will try to reproduce the issue and get back to you with an update as soon as possible.

pdnb

unread,
Oct 3, 2025, 4:13:26 AMOct 3
to Wazuh | Mailing List
that perms :
Zrzut ekranu 2025-10-03 100248.png
give me access to Dashboard in IT Higiene - rest are inaccessible with :
Zrzut ekranu 2025-10-03 101245.png

Luis Enrique Chico Capistrano

unread,
Oct 3, 2025, 12:05:43 PMOct 3
to Wazuh | Mailing List
Hi, thanks for the feedback.
I've asked the team for some help here, as I was trying to reproduce and solve the issue. I'll get back to you as soon as I have news.

Luis Enrique Chico Capistrano

unread,
Oct 3, 2025, 7:39:37 PMOct 3
to Wazuh | Mailing List
Hi,

I followed the guide "Creating and setting a Wazuh read-only user" to configure the user, which allowed me to view the IT Hygiene module and the rest of the interface.

I'm not sure if you are looking for any kind of restriction, but if that is the case, could you provide more details?


Screenshot from 2025-10-03 20-32-28.png 



Screenshot from 2025-10-03 20-36-36.png
Screenshot from 2025-10-03 20-36-36.png

pdnb

unread,
Oct 7, 2025, 6:49:11 AMOct 7
to Wazuh | Mailing List
Thanks for the quick reply. Unfortunately, I can't do exactly the same thing because I have different indexes and different team members with different levels of access to the indexes, so * is out of the question. I have the configuration below and currently do not have access to IT Hygiene>System>Hardware and Software>Windows KBs.
Below my config :
{
  "wazuh_operator": {
    "reserved": false,
    "hidden": false,
    "cluster_permissions": [
      "cluster_composite_ops_ro"
    ],
    "index_permissions": [
      {
        "index_patterns": [
          "wazuh-states-*",
          "wazuh-alerts-*",
          "wazuh-statistics*",
          ".*"
        ],
        "dls": "",
        "fls": [],
        "masked_fields": [],
        "allowed_actions": [
          "read"
        ]
      }
    ],
    "tenant_permissions": [
      {
        "tenant_patterns": [
          "global_tenant"
        ],
        "allowed_actions": [
          "kibana_all_read"
        ]
      }
    ],
    "static": false

Luis Enrique Chico Capistrano

unread,
Oct 7, 2025, 9:37:28 PMOct 7
to Wazuh | Mailing List
Hi, 
I was able to reproduce the issue. I've notified the team for help and will share an update as soon as I have news.

Luis Enrique Chico Capistrano

unread,
Oct 8, 2025, 9:44:44 AMOct 8
to Wazuh | Mailing List
Hi pndb,

Finally, I was able to make it work! To do that, I added the following permission: indices:data/write/index
permissions_hygiene.png
Screenshot from 2025-10-08 10-42-44.png

Luis Enrique Chico Capistrano

unread,
Oct 8, 2025, 10:09:49 AMOct 8
to Wazuh | Mailing List
You could also add permissions to wazuh-monitoring*. For more information, please refer to the following document.

Paweł Wiśniewski

unread,
Oct 13, 2025, 8:34:39 AMOct 13
to Luis Enrique Chico Capistrano, Wazuh | Mailing List
Still nothing :
obraz.png
obraz.png
i dont get it - how it cannot show what index has an issue - i know that is OpenSearch issue ;) 

--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/q92630WP-pA/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/e2ae94fb-dd23-44bb-95a7-649e67d06166n%40googlegroups.com.


--
------
Pozdrawiam
Paweł

pdnb

unread,
Oct 13, 2025, 8:38:29 AMOct 13
to Wazuh | Mailing List
i add  wazuh-monitoring*  perms and still nothing changed

pdnb

unread,
Oct 14, 2025, 2:59:12 AMOct 14
to Wazuh | Mailing List
ok , some kind of progress , with that perms :
Zrzut ekranu 2025-10-14 085715.png
Zrzut ekranu 2025-10-14 085813.png
i see : 
Zrzut ekranu 2025-10-14 085615.png
but not : 
Zrzut ekranu 2025-10-14 085856.png

Luis Enrique Chico Capistrano

unread,
Oct 14, 2025, 10:15:09 AMOct 14
to Wazuh | Mailing List
Hi pdnb,
I was able to reproduce your issue and solved it by adding the wazuh-inventory-* pattern to Index permissions.


inventory.png




Screenshot from 2025-10-14 11-10-02.png
Screenshot from 2025-10-14 10-52-13.png

pdnb

unread,
Oct 15, 2025, 2:30:47 AMOct 15
to Wazuh | Mailing List
Thx Luis to be patience :) when i was adding wazuh-inventory-* now i have perm as below .  I even restarted indexer - without success , anything was changed  :
Zrzut ekranu 2025-10-15 082207.png

pdnb

unread,
Oct 15, 2025, 2:48:11 AMOct 15
to Wazuh | Mailing List
Luis , now issue was cookies - cleaning related to wazuh solve problem . 
Thank for your help !

pdnb

unread,
Nov 12, 2025, 6:48:40 AMNov 12
to Wazuh | Mailing List
issue come back with  wazuh-states-inventory-browser-extensions-* in 4.14.0 , as you can see below i add whole pattern for new index but without any luck :D ( i have previously added wazu-states-* that should be covering new index  ) 
Zrzut ekranu 2025-11-12 124535.png
PS. cookies cleaned , dash restarted ;) 
Reply all
Reply to author
Forward
0 new messages