Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16345
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
exe
2:23 AM
rsyslog and Wazuh
Greetings, we want to use rsyslog to capture for example Sonicwall logs, but I'm a bit stuck
unread,
rsyslog and Wazuh
Greetings, we want to use rsyslog to capture for example Sonicwall logs, but I'm a bit stuck
2:23 AM
hvn4k.
,
Md. Nazmur Sakib
5
2:23 AM
Wazuh rules fine tuning.
i created a rule that is detecting duplicate and for testing i set its level to 4 to check and it was
unread,
Wazuh rules fine tuning.
i created a rule that is detecting duplicate and for testing i set its level to 4 to check and it was
2:23 AM
Dmitry Mikheev
,
Stuti Gupta
9
Feb 23
Duplicate agent name:
It seems that no events are being discarded, and the issue is caused by older agent entries still
unread,
Duplicate agent name:
It seems that no events are being discarded, and the issue is caused by older agent entries still
Feb 23
Jacob Molland
,
Bony V John
2
Feb 23
Wazuh using Keycloak as an IdP (OIDC)
Hi, Please allow me some time, I'm working on this and will get back to you with an update as
unread,
Wazuh using Keycloak as an IdP (OIDC)
Hi, Please allow me some time, I'm working on this and will get back to you with an update as
Feb 23
Xavier Mertens
,
Bony V John
4
Feb 23
Server upgraded but still listed as running the old OS
Hi, If the issue still persists, please check the <wodle name="syscollector">
unread,
Server upgraded but still listed as running the old OS
Hi, If the issue still persists, please check the <wodle name="syscollector">
Feb 23
Henry Valero
,
hasitha.u...@wazuh.com
4
Feb 23
Remote command execution is not working on Wazuh 4.14.3
Hi, Thanks Hasitha: I've tried modifying the ossec.conf file directly in the agent and it works,
unread,
Remote command execution is not working on Wazuh 4.14.3
Hi, Thanks Hasitha: I've tried modifying the ossec.conf file directly in the agent and it works,
Feb 23
Julien Bard
,
Nahuel Figueroa
5
Feb 23
Got the log but no alert
Please share the logtest output with debug level -dd On Mon, Feb 23, 2026 at 1:03 PM Julien Bard <
unread,
Got the log but no alert
Please share the logtest output with debug level -dd On Mon, Feb 23, 2026 at 1:03 PM Julien Bard <
Feb 23
Denis Grilli
,
Federico Gustavo Caffieri
3
Feb 23
Error changing the selected API - wazuh-dashboard
Thanks for your reply. My setup is using wazuh 4.14.3 and is formed by two indexer node in a cluster
unread,
Error changing the selected API - wazuh-dashboard
Thanks for your reply. My setup is using wazuh 4.14.3 and is formed by two indexer node in a cluster
Feb 23
Third Nht
,
Anthony Faruna
2
Feb 23
Is this log entry a threat? Looking for a Custom Rule to detect Web Shell activity in static paths.
Hello, Thank you for sharing the log samples and your observations. Based on what you've provided
unread,
Is this log entry a threat? Looking for a Custom Rule to detect Web Shell activity in static paths.
Hello, Thank you for sharing the log samples and your observations. Based on what you've provided
Feb 23
Yazid
, …
MaP
17
Feb 23
Wazuh / Symentec Integration
Hi Yazid, I suspect your data isn't being decoded correctly. Which file is displayed in the
unread,
Wazuh / Symentec Integration
Hi Yazid, I suspect your data isn't being decoded correctly. Which file is displayed in the
Feb 23
MSS
,
Gabriel Diaz Lopez de la Llave
6
Feb 23
Distributed Wazuh 4.13 Sizing
Hello! The final destination is the indexer, so that will be the requirement for the indexer cluster,
unread,
Distributed Wazuh 4.13 Sizing
Hello! The final destination is the indexer, so that will be the requirement for the indexer cluster,
Feb 23
dwight c
,
Nikhil Gurjar
4
Feb 22
Entra mfa/sso configuration
Hi dwight c, Glad to hear that it is working as expected. Please don't hesitate to contact us if
unread,
Entra mfa/sso configuration
Hi dwight c, Glad to hear that it is working as expected. Please don't hesitate to contact us if
Feb 22
Andrehens Chicfici
,
hasitha.u...@wazuh.com
12
Feb 22
Nessus triggers the same Shellshock-Attack Mails/Alerts hundred times daily
Hi Andrehens, That's okay, let me know if you need any further help with this, and we can look
unread,
Nessus triggers the same Shellshock-Attack Mails/Alerts hundred times daily
Hi Andrehens, That's okay, let me know if you need any further help with this, and we can look
Feb 22
Muhammad Ali Khan
,
hasitha.u...@wazuh.com
8
Feb 22
Suppress Default Wazuh Rules Using CDB-Based Custom Rule
Hi Muhammad You can exclude all Windows logs. If the agent is a Windows machine, you can comment out
unread,
Suppress Default Wazuh Rules Using CDB-Based Custom Rule
Hi Muhammad You can exclude all Windows logs. If the agent is a Windows machine, you can comment out
Feb 22
Ivan Martinez
,
Isaiah Daboh
13
Feb 21
MS SQLServer Monitoring and active response
Hi Isaiah... I did some more testing... Please, take a look at the following link: https://medium.com
unread,
MS SQLServer Monitoring and active response
Hi Isaiah... I did some more testing... Please, take a look at the following link: https://medium.com
Feb 21
Veera
,
Pablo Ariel Gonzalez
19
Feb 21
fim.db management
Thanks .. That worked and I am able to receive results and adjust the timings accordingly.. On Friday
unread,
fim.db management
Thanks .. That worked and I am able to receive results and adjust the timings accordingly.. On Friday
Feb 21
Yogi Valentino
,
Julián Morales
3
Feb 21
Wazuh 0 Logs
Hi Julián I've solved the problem, I'm resetup Certificate for all of the wazuh components.
unread,
Wazuh 0 Logs
Hi Julián I've solved the problem, I'm resetup Certificate for all of the wazuh components.
Feb 21
Emar Flix
,
Olamilekan Abdullateef Ajani
5
Feb 20
Wazuh Csross-Cluster Replication (Failover).
Hello again, So from looking at that documentation, it says, "Once you run _stop on a follower
unread,
Wazuh Csross-Cluster Replication (Failover).
Hello again, So from looking at that documentation, it says, "Once you run _stop on a follower
Feb 20
Andrehens Chicfici
,
gonzalo....@wazuh.com
2
Feb 20
Multigroup modified
Hi Andrehens! If you're actively making changes, seeing that warning from time to time is normal.
unread,
Multigroup modified
Hi Andrehens! If you're actively making changes, seeing that warning from time to time is normal.
Feb 20
Xavier Mertens
,
Olamilekan Abdullateef Ajani
6
Feb 20
Flooded with alerts 99901
This is really weird: On my agent, 1085 files have the same sha256!? sqlite> select count(*) from
unread,
Flooded with alerts 99901
This is really weird: On my agent, 1085 files have the same sha256!? sqlite> select count(*) from
Feb 20
perps grace
,
Olamilekan Abdullateef Ajani
2
Feb 20
Trend Vision one Decoders
Hello Perps, I have created a sample decoder and matching rule for you below. Feel free to modify
unread,
Trend Vision one Decoders
Hello Perps, I have created a sample decoder and matching rule for you below. Feel free to modify
Feb 20
perps grace
,
Md. Nazmur Sakib
2
Feb 20
Sophos Rules and decoders
Hello, I was able to trigger alerts with your log, decoder, and rule. So there can be two possible
unread,
Sophos Rules and decoders
Hello, I was able to trigger alerts with your log, decoder, and rule. So there can be two possible
Feb 20
Max Kirshin
,
Ian Yenien Serrano
3
Feb 20
Centralized configuration
Can you verify that wazuh-modulesd is working? You can test it by running: systemctl status wazuh-
unread,
Centralized configuration
Can you verify that wazuh-modulesd is working? You can test it by running: systemctl status wazuh-
Feb 20
Gokul Suresh
,
Marc Christian Pernesita Gregorio
5
Feb 20
Issue loading Endpoints "Stats" page
Hi Gokul, Thank you for confirming the number of agents affected. Since this is happening to only one
unread,
Issue loading Endpoints "Stats" page
Hi Gokul, Thank you for confirming the number of agents affected. Since this is happening to only one
Feb 20
Micah Still
,
Md. Nazmur Sakib
9
Feb 20
Wazuh Dashboard Stopped Visualizing Alerts
You can follow this document to make a retention policy with the help of ISM. https://documentation.
unread,
Wazuh Dashboard Stopped Visualizing Alerts
You can follow this document to make a retention policy with the help of ISM. https://documentation.
Feb 20
Jacob Molland
,
Jorge Eduardo Silva Jackson
4
Feb 19
Wazuh trusting Keycloak Certs
Hey Jorge, I finally have an update - I was able to get to the Wazuh SSO page, however now when i log
unread,
Wazuh trusting Keycloak Certs
Hey Jorge, I finally have an update - I was able to get to the Wazuh SSO page, however now when i log
Feb 19
Andrehens Chicfici
,
J. Rome
9
Feb 19
Custom Auddiocodes SBC Decoder
You are very close. The remaining issue is not the brackets or quotes in the message body. Your ERROR
unread,
Custom Auddiocodes SBC Decoder
You are very close. The remaining issue is not the brackets or quotes in the message body. Your ERROR
Feb 19
doc dodo
,
Jorge Eduardo Molas
2
Feb 19
not installed software
Hi, Wazuh's Syscollector module only stores installed packages, so to find devices without a
unread,
not installed software
Hi, Wazuh's Syscollector module only stores installed packages, so to find devices without a
Feb 19
Andrehens Chicfici
,
Cedrick Foko
12
Feb 19
Vulnerability Scanner triggering hundreds of false positives at the same tim
Hello Andrehens, You are still getting the alerts because the custom rule is silencing once the CVEs
unread,
Vulnerability Scanner triggering hundreds of false positives at the same tim
Hello Andrehens, You are still getting the alerts because the custom rule is silencing once the CVEs
Feb 19
Andrehens Chicfici
,
Olamilekan Abdullateef Ajani
3
Feb 19
Lists not loading
Thanks! Quick & easy fix. I was wondering why those are not listed in there as default... cheers
unread,
Lists not loading
Thanks! Quick & easy fix. I was wondering why those are not listed in there as default... cheers
Feb 19