Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 15599
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Trường An Tô Nguyễn
10:11 AM
Send syslog to Wazuh
Hi all, I've recently set up Wazuh using Docker containers. I also have another application,
unread,
Send syslog to Wazuh
Hi all, I've recently set up Wazuh using Docker containers. I also have another application,
10:11 AM
João Vitor Belmonte Rates
10:11 AM
Wazuh API and Active Response
Hello, We're exploring the possibility of executing a command directly on a Wazuh agent via the
unread,
Wazuh API and Active Response
Hello, We're exploring the possibility of executing a command directly on a Wazuh agent via the
10:11 AM
Paulo Ricardo Bruck
,
Bony V John
3
10:11 AM
35748 Ensure kernel module loading unloading and modification is collected
Hi Bony Thanks for reply. But , unfortunately, gmail cut the line showing rule. See below: line is
unread,
35748 Ensure kernel module loading unloading and modification is collected
Hi Bony Thanks for reply. But , unfortunately, gmail cut the line showing rule. See below: line is
10:11 AM
M G
10:09 AM
Active reponse - add agent to group
Hello, Is it possible for an active response to add an agent to a certain group for one hour? For
unread,
Active reponse - add agent to group
Hello, Is it possible for an active response to add an agent to a certain group for one hour? For
10:09 AM
Romain Hennebois
,
esteban...@wazuh.com
3
10:05 AM
Optimisation helps
Hello, I did this : { "date_index_name": { "if": "ctx?.rule?.description ==
unread,
Optimisation helps
Hello, I did this : { "date_index_name": { "if": "ctx?.rule?.description ==
10:05 AM
Gokul Suresh
,
Stuti Gupta
3
6:18 AM
Wazuh integration with azure load balancer
Thank you Stuti for your reply. I would like to know one more thing. Could you please specify which
unread,
Wazuh integration with azure load balancer
Thank you Stuti for your reply. I would like to know one more thing. Could you please specify which
6:18 AM
Rei Gjata
,
Stuti Gupta
4
5:59 AM
Filebeat not creating Indexes
HI There is an error " Document contains at least one immense term in field=\"
unread,
Filebeat not creating Indexes
HI There is an error " Document contains at least one immense term in field=\"
5:59 AM
Sumit Kumawat
, …
Julian Jorge
5
5:44 AM
Want to Create My Own cti.abc.com Platform Like Wazuh CTI
Not yet 😕. ___ Regards, SUMIT KUMAWAT On Mon, 8 Sept, 2025, 3:03 pm Julian Jorge, <julian.jorge.
unread,
Want to Create My Own cti.abc.com Platform Like Wazuh CTI
Not yet 😕. ___ Regards, SUMIT KUMAWAT On Mon, 8 Sept, 2025, 3:03 pm Julian Jorge, <julian.jorge.
5:44 AM
DIWAHAR RAHAWID
,
ismail....@wazuh.com
2
5:28 AM
Automate log rotation
Hi, You can refer to this document for creating a retention policy. Index lifecycle management helps
unread,
Automate log rotation
Hi, You can refer to this document for creating a retention policy. Index lifecycle management helps
5:28 AM
George Paun
,
hasitha.u...@wazuh.com
5
4:57 AM
user admin
Hi George In this case, I recommend using a Wazuh CDB list to include all admin usernames. You can
unread,
user admin
Hi George In this case, I recommend using a Wazuh CDB list to include all admin usernames. You can
4:57 AM
Basim Ibrahim
,
hasitha.u...@wazuh.com
3
2:43 AM
Wazuh not getting installed
Hi, NET STOP Wazuh --> service is not installed. msiexec.exe /x wazuh-agent-4.12.0-1.msi /qn ->
unread,
Wazuh not getting installed
Hi, NET STOP Wazuh --> service is not installed. msiexec.exe /x wazuh-agent-4.12.0-1.msi /qn ->
2:43 AM
Anand Kumar
,
hasitha.u...@wazuh.com
2
1:10 AM
Custom Decoders Configuration
Hi Anand, It seems you're testing a log that has already been processed, most likely taken from
unread,
Custom Decoders Configuration
Hi Anand, It seems you're testing a log that has already been processed, most likely taken from
1:10 AM
Paulo Ricardo Bruck
,
hasitha.u...@wazuh.com
4
Sep 7
35775 Ensure audit tools mode is configured.
Hi Paulo I am glad that your issue has been resolved after removing 755 from the condition. On Sunday
unread,
35775 Ensure audit tools mode is configured.
Hi Paulo I am glad that your issue has been resolved after removing 755 from the condition. On Sunday
Sep 7
Bayu Sangkaya (bayusky.labs)
,
Henadence Anyam
2
Sep 7
Vcenter decoders
Hi Bayu Sangkaya, Your children decoders should use the same name. For example, I have changed the
unread,
Vcenter decoders
Hi Bayu Sangkaya, Your children decoders should use the same name. For example, I have changed the
Sep 7
Dex Perry
,
Bony V John
3
Sep 6
Fortigate Syslog Not Showing in Wazuh Dashboard (Packets Seen via Tcpdump)
Hi Bony, Thanks for your earlier guidance — it helped a lot. I've confirmed that FortiGate logs
unread,
Fortigate Syslog Not Showing in Wazuh Dashboard (Packets Seen via Tcpdump)
Hi Bony, Thanks for your earlier guidance — it helped a lot. I've confirmed that FortiGate logs
Sep 6
Amin
,
Javier Medeot
2
Sep 5
Recommended Kubernetes Architecture
Hi Amin. Your proposed architecture sounds right for your environment. Running Wazuh on Kubernetes
unread,
Recommended Kubernetes Architecture
Hi Amin. Your proposed architecture sounds right for your environment. Running Wazuh on Kubernetes
Sep 5
felixm
,
Nicolas Zapata
3
Sep 4
Clean up after removing indexes from dash board
Additionally, if the indexes are being deleted manually from the dashboard, it would be advisable to
unread,
Clean up after removing indexes from dash board
Additionally, if the indexes are being deleted manually from the dashboard, it would be advisable to
Sep 4
bilal
,
Olamilekan Abdullateef Ajani
2
Sep 4
Monitor renamed fils on windows
Hello Bilal, This is possible with the use of wazuh FIM with the aid of syscheck. When you have a
unread,
Monitor renamed fils on windows
Hello Bilal, This is possible with the use of wazuh FIM with the aid of syscheck. When you have a
Sep 4
Facu Basgall
,
Juan Felipe González Ortiz
9
Sep 4
Slow performance with LDAP user.
Hi, most likely the poor performance is due to the users and groups issue. I'm going to set up an
unread,
Slow performance with LDAP user.
Hi, most likely the poor performance is due to the users and groups issue. I'm going to set up an
Sep 4
Felix Andorfer
,
Olamilekan Abdullateef Ajani
6
Sep 3
Agent reconnect issue when switching networks
Hello Felix, Based on my test, you should not get so many warnings and so much information from the
unread,
Agent reconnect issue when switching networks
Hello Felix, Based on my test, you should not get so many warnings and so much information from the
Sep 3
Facu Basgall
,
Olamilekan Abdullateef Ajani
2
Sep 3
Modify rules by agent
Hello, One way to do this is if you have a specific field in the alert that is commong to all or some
unread,
Modify rules by agent
Hello, One way to do this is if you have a specific field in the alert that is commong to all or some
Sep 3
Henry Valero
,
Md. Nazmur Sakib
4
Sep 3
Error in the dashboard, the data is not displayed
Hello Nazmur, I made the suggested changes and ran the indicated commands, these are the results of
unread,
Error in the dashboard, the data is not displayed
Hello Nazmur, I made the suggested changes and ran the indicated commands, these are the results of
Sep 3
Gokul Suresh
Sep 3
Azure Load balancer integration with wazuh
Hi team, I have to integrate azure load balancer logs into wazuh for monitoring. I have to monitor
unread,
Azure Load balancer integration with wazuh
Hi team, I have to integrate azure load balancer logs into wazuh for monitoring. I have to monitor
Sep 3
Yossif Helmy
,
Benjamin Nworah
9
Sep 3
Fields not being refreshed
Thank you, Benjamin. I would like to close the ticket. On Wednesday, September 3, 2025 at 4:00:40 PM
unread,
Fields not being refreshed
Thank you, Benjamin. I would like to close the ticket. On Wednesday, September 3, 2025 at 4:00:40 PM
Sep 3
Singh Satish
,
Md. Nazmur Sakib
3
Sep 3
child decoder of windows_eventchannel
Based on my findings at this moment, it is not possible to write sibling decoders for the Windows
unread,
child decoder of windows_eventchannel
Based on my findings at this moment, it is not possible to write sibling decoders for the Windows
Sep 3
하프사
,
ismail....@wazuh.com
2
Sep 3
Custom Log Storage & Alerting on Disk Usage in Lab
Hi, Wazuh generates several internal log files, including alerts.log, archives.log, alerts.json, and
unread,
Custom Log Storage & Alerting on Disk Usage in Lab
Hi, Wazuh generates several internal log files, including alerts.log, archives.log, alerts.json, and
Sep 3
Julio Cesar
,
diego....@wazuh.com
5
Sep 3
Combining pfSense Agent and Syslog Log Collection
Hi, That configuration is performed in Suricata. Wazuh is now configured to receive the logs you
unread,
Combining pfSense Agent and Syslog Log Collection
Hi, That configuration is performed in Suricata. Wazuh is now configured to receive the logs you
Sep 3
Aayush Shrivastava
,
Adedamola Okelola
6
Sep 3
Agent Communication
still the same issue I deployed the new wazuh instance but the issue remanis same Connected 50+
unread,
Agent Communication
still the same issue I deployed the new wazuh instance but the issue remanis same Connected 50+
Sep 3
stefanny chavez anto
,
Javier Rosas
6
Sep 2
ERROR: CANNOT INITIALIZE WAZUH INDEXER CLUSTER
Mira que en la documentación que me mandas del quick start indica que se necesitan al menos 8 GB de
unread,
ERROR: CANNOT INITIALIZE WAZUH INDEXER CLUSTER
Mira que en la documentación que me mandas del quick start indica que se necesitan al menos 8 GB de
Sep 2
Facu Basgall
,
Héctor Gómez
5
Sep 2
Problem installing the agent.
Did you have any luck with this? Were you able to install the agent? On Thursday, August 28, 2025 at
unread,
Problem installing the agent.
Did you have any luck with this? Were you able to install the agent? On Thursday, August 28, 2025 at
Sep 2