Hi Wazuh Team,
I would like to seek clarification regarding the ClamAV integration and Malware Detection dashboard behavior.
1. ClamAV Alerts Visible in Threat Hunting but Not in Malware DetectionI have been testing the ClamAV integration using the EICAR test signature.
The detections are successfully generated and can be seen in Threat Hunting, as shown below. The events are matched against the rule "ClamAV: Virus detected" (Rule ID: 52502) and contain the expected fields such as:
However, these same events do not appear under the Malware Detection dashboard/module.
Based on the Malware Detection view, the dashboard appears to be filtering on:
rule.groups: rootcheck, virustotal, yaraSince the ClamAV events belong to the groups:
clamd, freshclam, virusthey do not seem to be included in the Malware Detection dashboard results.
My questions are:
I am also looking for clarification regarding the log source described in the ClamAV integration documentation:
The documentation indicates that ClamAV logs are written to:
/var/log/syslogHowever, during testing on RHEL 9 and RHEL 10 systems (both Wazuh component hosts and Wazuh agent endpoints), I observed the following:
Example events show:
Agent endpoint:
location: journald predecoder.program_name: clamd rule.description: ClamAV: Virus detectedComponent host:
location: /var/log/messages predecoder.program_name: clamd rule.description: ClamAV: Virus detectedMy questions are:
Any clarification would be greatly appreciated.
Thank you.



