Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16590
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Rahul Manoj
,
Bony V John
4
2:16 AM
Domain whitelisting for aws integration
Hi Team, I would also like to know if there is any recommended whitelist of domains/endpoints
unread,
Domain whitelisting for aws integration
Hi Team, I would also like to know if there is any recommended whitelist of domains/endpoints
2:16 AM
whoami
,
hasitha.u...@wazuh.com
2
May 16
Request for Guidance: Wazuh Detection Lab for Lateral Movement, LotL, DNS Tunneling, AMSI Bypass, and Supply-Chain Defense
Hi whoami Thank you for sharing these detailed detection-engineering use cases. The overall approach
unread,
Request for Guidance: Wazuh Detection Lab for Lateral Movement, LotL, DNS Tunneling, AMSI Bypass, and Supply-Chain Defense
Hi whoami Thank you for sharing these detailed detection-engineering use cases. The overall approach
May 16
Megan
,
Olamilekan Abdullateef Ajani
2
May 15
FIM changes tracking via Anomaly detection module
Hello Megan, I am currently looking into reproducing this, I will revert with my findings. Regards On
unread,
FIM changes tracking via Anomaly detection module
Hello Megan, I am currently looking into reproducing this, I will revert with my findings. Regards On
May 15
Brenno Garcia
,
Olamilekan Abdullateef Ajani
8
May 15
Wazuh Wodle
Did a process walkthrough here too, if you don't mind. https://github.com/lakecide/wazuh-browser-
unread,
Wazuh Wodle
Did a process walkthrough here too, if you don't mind. https://github.com/lakecide/wazuh-browser-
May 15
никита какдела
,
Carlos Anguita López
4
May 15
Wazuh Correlation for EventID 4104 (Powershell ScriptBlock)
Hello, We don't have a official roadmap, nor a date of release. You can check the GitHub Project
unread,
Wazuh Correlation for EventID 4104 (Powershell ScriptBlock)
Hello, We don't have a official roadmap, nor a date of release. You can check the GitHub Project
May 15
Miran Ul Haq
,
juan.c...@wazuh.com
5
May 15
Read-Only rights for Vulnerability Dashboard Only
Hi Juan, Really appreciate your help. This worked and gave the desired output. Best Regards, Miran On
unread,
Read-Only rights for Vulnerability Dashboard Only
Hi Juan, Really appreciate your help. This worked and gave the desired output. Best Regards, Miran On
May 15
minshad
,
Bony V John
6
May 15
Detecting Unauthorized or Shadow AI Tools in our Environments
Hi, The issue is with the custom rule configuration. That is why the alert is not being triggered.
unread,
Detecting Unauthorized or Shadow AI Tools in our Environments
Hi, The issue is with the custom rule configuration. That is why the alert is not being triggered.
May 15
Monesh
,
Md. Nazmur Sakib
2
May 15
reg password change
Hello Monesh, To change the admin password that you use for login to the web interface. Run this
unread,
reg password change
Hello Monesh, To change the admin password that you use for login to the web interface. Run this
May 15
Veera
, …
Stuti Gupta
15
May 15
vulnerabilities not reporting in wazuh agents
There is a connection issue. From the timestamps in the logs, the agent was previously connected, but
unread,
vulnerabilities not reporting in wazuh agents
There is a connection issue. From the timestamps in the logs, the agent was previously connected, but
May 15
John Doecisco
,
fabio.c...@wazuh.com
4
May 14
LDAP Integration Not Getting backend-roles
Hi John, Thanks for the detail. The backend_roles: [ ] from /api/account confirms the indexer is not
unread,
LDAP Integration Not Getting backend-roles
Hi John, Thanks for the detail. The backend_roles: [ ] from /api/account confirms the indexer is not
May 14
Isaac S.
,
Olamilekan Abdullateef Ajani
2
May 14
Audit log parse and convert EPOCH timestamp to readeable format
Hello Isaac, This is possible, you just need 2 things, modify the decoder to reflect the new field
unread,
Audit log parse and convert EPOCH timestamp to readeable format
Hello Isaac, This is possible, you just need 2 things, modify the decoder to reflect the new field
May 14
Monesh
,
Olamilekan Abdullateef Ajani
2
May 14
reg dashboard issue
Hello, From what you shared, the Wazuh indexer stopped working before the Dashboard failed too. Can
unread,
reg dashboard issue
Hello, From what you shared, the Wazuh indexer stopped working before the Dashboard failed too. Can
May 14
Veera
,
Nikhil Gurjar
2
May 14
Downloading the wazuh package for el5
Hi Veera, Please find the download link for Wazuh agent version 4.14.4-1 for EL5 / SLES11 (RPM-
unread,
Downloading the wazuh package for el5
Hi Veera, Please find the download link for Wazuh agent version 4.14.4-1 for EL5 / SLES11 (RPM-
May 14
Jack Martin
,
Jorest Brice Tankoua Njassep
2
May 13
Guidance Required for Secure SSL Configuration in On-Premises Wazuh Deployment
Hi Jack, Follow the steps below Download the Wazuh cert tool: https://packages.wazuh.com/4.14/wazuh-
unread,
Guidance Required for Secure SSL Configuration in On-Premises Wazuh Deployment
Hi Jack, Follow the steps below Download the Wazuh cert tool: https://packages.wazuh.com/4.14/wazuh-
May 13
Chandra pal singh Chauhan
,
Othniel Ebolum
2
May 13
Guidance on Reducing SNS Email Noise for Vulnerability Detector Alerts
Hello Chandra, No, you cannot natively aggregate these vulnerability-related events with the current
unread,
Guidance on Reducing SNS Email Noise for Vulnerability Detector Alerts
Hello Chandra, No, you cannot natively aggregate these vulnerability-related events with the current
May 13
Brenno Garcia
,
Eli Josue Rodriguez
2
May 13
Supress rule wazuh
Hi, what you are seeing is expected behavior in Wazuh's rule engine. The rule 100034 is not
unread,
Supress rule wazuh
Hi, what you are seeing is expected behavior in Wazuh's rule engine. The rule 100034 is not
May 13
Brenno Garcia
,
Olamilekan Abdullateef Ajani
5
May 13
Wazuh + pfsense
Hello Brenno, Apologies for the delayed response. Yes, that is correct. The ignore applies only to
unread,
Wazuh + pfsense
Hello Brenno, Apologies for the delayed response. Yes, that is correct. The ignore applies only to
May 13
ACH MUQODDAM
,
Md. Nazmur Sakib
3
May 13
Best practice for handling "maximum limit of files monitored" warning in FIM
Thankyou for information On Tuesday, May 12, 2026 at 8:42:45 PM UTC+7 Md. Nazmur Sakib wrote: Hello,
unread,
Best practice for handling "maximum limit of files monitored" warning in FIM
Thankyou for information On Tuesday, May 12, 2026 at 8:42:45 PM UTC+7 Md. Nazmur Sakib wrote: Hello,
May 13
Alara Joel
,
Stuti Gupta
13
May 12
No log files AWS
Hi Alara, For the archives check, instead of grepping a generic keyword like aws, try grepping for
unread,
No log files AWS
Hi Alara, For the archives check, instead of grepping a generic keyword like aws, try grepping for
May 12
app...@proton.me
,
Isaiah Daboh
3
May 12
CTI not up to date for CVE-2026-33210
Hello, There is a known issue with this CVE that has to do with libraries for Ruby. This CVE will be
unread,
CTI not up to date for CVE-2026-33210
Hello, There is a known issue with this CVE that has to do with libraries for Ruby. This CVE will be
May 12
Vuk Kadija
,
Bony V John
3
May 12
Using API for Vulnerability detection
Hello Bony, Tnx for the help and explanation. Works like a charm. Best regards, Vuk On Monday, May 11
unread,
Using API for Vulnerability detection
Hello Bony, Tnx for the help and explanation. Works like a charm. Best regards, Vuk On Monday, May 11
May 12
doc dodo
,
Olamilekan Abdullateef Ajani
6
May 12
Index permissions for custom role
Yes, this solved the problem. Thank you very much. понедельник, 11 мая 2026 г. в 17:03:48 UTC+3,
unread,
Index permissions for custom role
Yes, this solved the problem. Thank you very much. понедельник, 11 мая 2026 г. в 17:03:48 UTC+3,
May 12
Narasimha Naidu B
,
Bony V John
11
May 11
Email Notifications and Critical Alerts
Hi, Apologies for the late response. For email alerts, you can check the following points: Ensure
unread,
Email Notifications and Critical Alerts
Hi, Apologies for the late response. For email alerts, you can check the following points: Ensure
May 11
Facu Basgall
, …
Fabio Martins
4
May 11
What does enabling remote commands involve?
On Mon, 11 May 2026 at 17:02 Facu Basgall <facub...@gmail.com> wrote: I understand that, but
unread,
What does enabling remote commands involve?
On Mon, 11 May 2026 at 17:02 Facu Basgall <facub...@gmail.com> wrote: I understand that, but
May 11
Luka Wynants
,
Md. Nazmur Sakib
2
May 11
Infoblox syslog no being decoded as expected
Hello If your decoder matches a program name in the pre-decoder, you need to add the reference to it
unread,
Infoblox syslog no being decoded as expected
Hello If your decoder matches a program name in the pre-decoder, you need to add the reference to it
May 11
Carolina Landa
May 11
[Save the Date] Wazuh Meetups in June: Bangkok, Milan & Augsburg
Hi everyone, In June, we are bringing the Wazuh community together across Europe and Asia! Join us to
unread,
[Save the Date] Wazuh Meetups in June: Bangkok, Milan & Augsburg
Hi everyone, In June, we are bringing the Wazuh community together across Europe and Asia! Join us to
May 11
Max
,
Md. Nazmur Sakib
2
May 11
Wazuh Log encryption
Hello, Wazuh secures log data primarily by encrypting communication using Blowfish or AES encryption
unread,
Wazuh Log encryption
Hello, Wazuh secures log data primarily by encrypting communication using Blowfish or AES encryption
May 11
perps grace
,
Henadence Anyam
2
May 11
NAC Decoders and Rules
Hi Perps, The events you shared can be decoded by the Wazuh built-in JSON decoder as you can see in
unread,
NAC Decoders and Rules
Hi Perps, The events you shared can be decoded by the Wazuh built-in JSON decoder as you can see in
May 11
Anand Kumar
,
hasitha.u...@wazuh.com
5
May 11
Wazuh Active Response not working when its deployed in docker container, As shown in attached image below.
Hi Anand, I am glad to hear that the issue has been fixed. On Monday, May 11, 2026 at 4:28:13 PM UTC+
unread,
Wazuh Active Response not working when its deployed in docker container, As shown in attached image below.
Hi Anand, I am glad to hear that the issue has been fixed. On Monday, May 11, 2026 at 4:28:13 PM UTC+
May 11
Vitaly Bovshover
,
hasitha.u...@wazuh.com
3
May 11
[Wazuh Cluster] Agents disconnecting (queue is full / Requesting key), /var/ossec/queue/db/ > 150GB on Worker nodes
Hi Vitaly wazuh-agent: WARNING: Target 'agent' message queue is full (1024). Log lines may be
unread,
[Wazuh Cluster] Agents disconnecting (queue is full / Requesting key), /var/ossec/queue/db/ > 150GB on Worker nodes
Hi Vitaly wazuh-agent: WARNING: Target 'agent' message queue is full (1024). Log lines may be
May 11