Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Group path
Wazuh | Mailing List
Contact owners and managers
1–30 of 16859
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Magnus Höglund
, …
Nguyen Xuan Dong
15
9:20 AM
Wazuh 4.8 Nextcloud mapper_parsing_exception
Opened it with the logtest output and your 4.14.8 case: https://github.com/wazuh/wazuh/issues/39767
unread,
Wazuh 4.8 Nextcloud mapper_parsing_exception
Opened it with the logtest output and your 4.14.8 case: https://github.com/wazuh/wazuh/issues/39767
9:20 AM
Dharmil Jariwala
,
Md. Nazmur Sakib
5
7:20 AM
Manager Logs in Wazuh 5.0 Beta
Because as in previous version, you can not install wazuh agent on wazuh manager. And Wazuh manager
unread,
Manager Logs in Wazuh 5.0 Beta
Because as in previous version, you can not install wazuh agent on wazuh manager. And Wazuh manager
7:20 AM
Hextra Srl
,
diego...@wazuh.com
5
Sep 29
auditd EXECVE/PROCTITLE arguments stay hex-encoded
Hextra Srl Thanks for sharing the processor. We tested it as is against real auditd events from our
unread,
auditd EXECVE/PROCTITLE arguments stay hex-encoded
Hextra Srl Thanks for sharing the processor. We tested it as is against real auditd events from our
Sep 29
Varun Nagar
,
Olamilekan Abdullateef Ajani
9
Sep 28
MSSQL Integration error
Hello, The decoder is the inbuilt JSON decoder so you do not need to do anything. As mentioned, after
unread,
MSSQL Integration error
Hello, The decoder is the inbuilt JSON decoder so you do not need to do anything. As mentioned, after
Sep 28
Peter Santiago
,
Md. Nazmur Sakib
2
Sep 28
rootcheck question for Wazuh 5 beta 5
Hi Peter! This is a well-known false positive caused by Btrfs, not a rootkit. Rootcheck's "
unread,
rootcheck question for Wazuh 5 beta 5
Hi Peter! This is a well-known false positive caused by Btrfs, not a rootkit. Rootcheck's "
Sep 28
Bob Barrett
,
Md. Nazmur Sakib
2
Sep 28
PoC Windows netsh alienvault
Hello Bob! I was able to reproduce the same error in my Lab. It seems that in the recent version, the
unread,
PoC Windows netsh alienvault
Hello Bob! I was able to reproduce the same error in my Lab. It seems that in the recent version, the
Sep 28
WENWEN H
, …
Jose Luis Carreras Marin
16
Sep 28
AWS WAF action:BLOCK events silently dropped by aws-s3 wodle (~40-50% loss), action:ALLOW unaffected (0% loss)
You are right, and it holds for 4.4.5 too. I checked ruleset/rules/0350-amazon_rules.xml at v4.4.5,
unread,
AWS WAF action:BLOCK events silently dropped by aws-s3 wodle (~40-50% loss), action:ALLOW unaffected (0% loss)
You are right, and it holds for 4.4.5 too. I checked ruleset/rules/0350-amazon_rules.xml at v4.4.5,
Sep 28
Nguyen Xuan Dong
2
Sep 28
4 ways a Wazuh custom rule passes wazuh-logtest and never fires in production
A follow-up on case 3, because the part I left open now has a measurement behind it. Francisco Sousa
unread,
4 ways a Wazuh custom rule passes wazuh-logtest and never fires in production
A follow-up on case 3, because the part I left open now has a measurement behind it. Francisco Sousa
Sep 28
Fernando Montanher
, …
Francisco Sousa
22
Sep 25
Title: Canonical vulnerabilities no longer appearing in Wazuh CTI
Hextra, the loop is not closed yet, it moved. The two lines you quoted come from two different
unread,
Title: Canonical vulnerabilities no longer appearing in Wazuh CTI
Hextra, the loop is not closed yet, it moved. The two lines you quoted come from two different
Sep 25
mt b
,
Olamilekan Abdullateef Ajani
4
Sep 25
CVE flood
Hello, Yes, that is most likely what happened. Ubuntu kernel packages usually includes the kernel
unread,
CVE flood
Hello, Yes, that is most likely what happened. Ubuntu kernel packages usually includes the kernel
Sep 25
Jörg Schin.
,
Md. Nazmur Sakib
7
Sep 25
Wazuh 5.0.0 beta5 – FIM events are not routed to Custom Space
Hi, After completely deleting the integration and using your decoders, I initially ignored the
unread,
Wazuh 5.0.0 beta5 – FIM events are not routed to Custom Space
Hi, After completely deleting the integration and using your decoders, I initially ignored the
Sep 25
periyasamy
,
Md. Nazmur Sakib
2
Sep 25
how can i edit or modify threat hunting dashboard
Hello! What kind of edit or modification are you trying to make to the threat hunting dashboard? If
unread,
how can i edit or modify threat hunting dashboard
Hello! What kind of edit or modification are you trying to make to the threat hunting dashboard? If
Sep 25
Isaac S.
,
carlos...@wazuh.com
3
Sep 25
Cluster nodes vulnerability report.
Hello Carlos This is the Vulnerability Detection and indexer configuration from one of workers nodes
unread,
Cluster nodes vulnerability report.
Hello Carlos This is the Vulnerability Detection and indexer configuration from one of workers nodes
Sep 25
Arun Hundaragi
,
Olamilekan Abdullateef Ajani
2
Sep 24
Wazuh Worker Node Capacity Guidance — Sustained EPS Sizing
Hello Arun, For Wazuh, there is no fixed CPU/RAM to EPS ratio, because the cost of processing an
unread,
Wazuh Worker Node Capacity Guidance — Sustained EPS Sizing
Hello Arun, For Wazuh, there is no fixed CPU/RAM to EPS ratio, because the cost of processing an
Sep 24
ARUN S
,
Md. Nazmur Sakib
2
Sep 24
Wazuh 4.14.7 CDB lookup occasionally fails for existing vendor entries in custom software policy rule
Hi Arun, There's no confirmed 4.14.x bug I know of where not_match_key fails on one occasion and
unread,
Wazuh 4.14.7 CDB lookup occasionally fails for existing vendor entries in custom software policy rule
Hi Arun, There's no confirmed 4.14.x bug I know of where not_match_key fails on one occasion and
Sep 24
No Data
,
Olamilekan Abdullateef Ajani
11
Sep 22
Vulnerbility Scanner SHows alert on Fixed Package
Hello, I am glad it has been fixed. The correction has reached your scanner, and the update has been
unread,
Vulnerbility Scanner SHows alert on Fixed Package
Hello, I am glad it has been fixed. The correction has reached your scanner, and the update has been
Sep 22
Marc Michot
,
Olamilekan Abdullateef Ajani
5
Sep 22
Libunbound false positive
curl -s https://cti.wazuh.com/api/v1/catalog/contexts/vd_1.0.0/consumers/vd_4.8.0 | jq '.data | {
unread,
Libunbound false positive
curl -s https://cti.wazuh.com/api/v1/catalog/contexts/vd_1.0.0/consumers/vd_4.8.0 | jq '.data | {
Sep 22
Uni AT
,
Olamilekan Abdullateef Ajani
2
Sep 21
Alerting/reports/vizualisations with RBAC (single-tenant) + permissions issue with alerts/monitors for users
Hello, Thank you for the detailed description and screenshots, helps isolate the issue. - For
unread,
Alerting/reports/vizualisations with RBAC (single-tenant) + permissions issue with alerts/monitors for users
Hello, Thank you for the detailed description and screenshots, helps isolate the issue. - For
Sep 21
Nguyen Xuan Dong
, …
Francisco Sousa
11
Sep 21
Stock Wazuh loads no audit rules, so auditd-sourced detections have nothing to match
Francisco, I'm taking the three-state split as a correction, and it changes what I publish rather
unread,
Stock Wazuh loads no audit rules, so auditd-sourced detections have nothing to match
Francisco, I'm taking the three-state split as a correction, and it changes what I publish rather
Sep 21
No Data
,
Alejandro Ruiz Becerra
4
Sep 21
False Positiv on CVE-2026-44170
Hi again! Can you check if the reported package is installed in your system? The path should be
unread,
False Positiv on CVE-2026-44170
Hi again! Can you check if the reported package is installed in your system? The path should be
Sep 21
No Data
,
antonio...@wazuh.com
2
Sep 21
false positiv on CVE-2026-14380 RedHat 9
Hi, Thank you for bringing this to our attention. The false positive has already been reported.
unread,
false positiv on CVE-2026-14380 RedHat 9
Hi, Thank you for bringing this to our attention. The false positive has already been reported.
Sep 21
No Data
,
Olamilekan Abdullateef Ajani
3
Sep 21
false positiv on cve-2026-9698
Looks like it's been fixed. Olamilekan Abdullateef Ajani schrieb am Mittwoch, 16. September 2026
unread,
false positiv on cve-2026-9698
Looks like it's been fixed. Olamilekan Abdullateef Ajani schrieb am Mittwoch, 16. September 2026
Sep 21
Ahmed Awwad
,
Md. Nazmur Sakib
2
Sep 21
Store Archive Logs at Indexers and Auto Remove compressed archives.json files
You cannot configure this in the Wazuh configuration. You can delete the archive files using a cron
unread,
Store Archive Logs at Indexers and Auto Remove compressed archives.json files
You cannot configure this in the Wazuh configuration. You can delete the archive files using a cron
Sep 21
Harishwar Boya
,
Dennis Ariel Gamboa Veliz
2
Sep 18
Subject: Correlating Cloudflare Client IPs with GKE Container/Django Logs in Wazuh
Hi Harishwar, First, to be sure I am solving the right problem: do you want your existing Django
unread,
Subject: Correlating Cloudflare Client IPs with GKE Container/Django Logs in Wazuh
Hi Harishwar, First, to be sure I am solving the right problem: do you want your existing Django
Sep 18
Jack Martin
,
Olamilekan Abdullateef Ajani
4
Sep 18
Wazuh 4.14.1 – Alerts Not Appearing in Dashboard Despite Successful Agent Connectivity
Hello Jack, There is no fixed Wazuh limit of 1000 indices. The number 1000 refers to the open shard
unread,
Wazuh 4.14.1 – Alerts Not Appearing in Dashboard Despite Successful Agent Connectivity
Hello Jack, There is no fixed Wazuh limit of 1000 indices. The number 1000 refers to the open shard
Sep 18
wazuh user
,
Olamilekan Abdullateef Ajani
4
Sep 17
TLS SYSLOG VIA PORT 6514
Hello Changing the port from 514 to 6514 is not enough, as that would only create a plain TCP
unread,
TLS SYSLOG VIA PORT 6514
Hello Changing the port from 514 to 6514 is not enough, as that would only create a plain TCP
Sep 17
Harishwar Boya
,
Md. Nazmur Sakib
2
Sep 16
Snapshot restore fails with security_exception "no permissions for []" on non-system index (4.14.7 / OpenSearch 2.19.5)
Hi Harishwar, I believe this is not a Wazuh 4.14.7 bug. The empty [] in the error means the plugin
unread,
Snapshot restore fails with security_exception "no permissions for []" on non-system index (4.14.7 / OpenSearch 2.19.5)
Hi Harishwar, I believe this is not a Wazuh 4.14.7 bug. The empty [] in the error means the plugin
Sep 16
Pratik Dabhi
, …
Nguyen Xuan Dong
7
Sep 16
Is the classic ruleset/decoders/ruleset/rules PR process still active, or has it moved to the Engine?
Awwal - the technique list and the replay harness are public: https://github.com/xuxu298/siem-replay-
unread,
Is the classic ruleset/decoders/ruleset/rules PR process still active, or has it moved to the Engine?
Awwal - the technique list and the replay harness are public: https://github.com/xuxu298/siem-replay-
Sep 16
Monesh
,
Olamilekan Abdullateef Ajani
2
Sep 15
req api monitoring from server
Hello, Could you clarify what you mean by monitoring the APIs? Are you looking to: Collect and
unread,
req api monitoring from server
Hello, Could you clarify what you mean by monitoring the APIs? Are you looking to: Collect and
Sep 15
Marc Michot
, …
Awwal Ishiaku
5
Sep 15
CVE-2026-13595 util-linux on Trixie/Debian
Hi, It seems the CTI is now up2date and the system runs as expected :) thank you all. Le lundi 14
unread,
CVE-2026-13595 util-linux on Trixie/Debian
Hi, It seems the CTI is now up2date and the system runs as expected :) thank you all. Le lundi 14
Sep 15