Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 15587
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
felixm
,
Nicolas Zapata
3
Sep 4
Clean up after removing indexes from dash board
Additionally, if the indexes are being deleted manually from the dashboard, it would be advisable to
unread,
Clean up after removing indexes from dash board
Additionally, if the indexes are being deleted manually from the dashboard, it would be advisable to
Sep 4
bilal
,
Olamilekan Abdullateef Ajani
2
Sep 4
Monitor renamed fils on windows
Hello Bilal, This is possible with the use of wazuh FIM with the aid of syscheck. When you have a
unread,
Monitor renamed fils on windows
Hello Bilal, This is possible with the use of wazuh FIM with the aid of syscheck. When you have a
Sep 4
Rei Gjata
,
Stuti Gupta
3
Sep 4
Filebeat not creating Indexes
Hi Stuti Its an all in one environment , version 4.11.2 Output of the cluster health ----------------
unread,
Filebeat not creating Indexes
Hi Stuti Its an all in one environment , version 4.11.2 Output of the cluster health ----------------
Sep 4
Facu Basgall
,
Juan Felipe González Ortiz
9
Sep 4
Slow performance with LDAP user.
Hi, most likely the poor performance is due to the users and groups issue. I'm going to set up an
unread,
Slow performance with LDAP user.
Hi, most likely the poor performance is due to the users and groups issue. I'm going to set up an
Sep 4
Felix Andorfer
,
Olamilekan Abdullateef Ajani
6
Sep 3
Agent reconnect issue when switching networks
Hello Felix, Based on my test, you should not get so many warnings and so much information from the
unread,
Agent reconnect issue when switching networks
Hello Felix, Based on my test, you should not get so many warnings and so much information from the
Sep 3
Facu Basgall
,
Olamilekan Abdullateef Ajani
2
Sep 3
Modify rules by agent
Hello, One way to do this is if you have a specific field in the alert that is commong to all or some
unread,
Modify rules by agent
Hello, One way to do this is if you have a specific field in the alert that is commong to all or some
Sep 3
Henry Valero
,
Md. Nazmur Sakib
4
Sep 3
Error in the dashboard, the data is not displayed
Hello Nazmur, I made the suggested changes and ran the indicated commands, these are the results of
unread,
Error in the dashboard, the data is not displayed
Hello Nazmur, I made the suggested changes and ran the indicated commands, these are the results of
Sep 3
Gokul Suresh
Sep 3
Azure Load balancer integration with wazuh
Hi team, I have to integrate azure load balancer logs into wazuh for monitoring. I have to monitor
unread,
Azure Load balancer integration with wazuh
Hi team, I have to integrate azure load balancer logs into wazuh for monitoring. I have to monitor
Sep 3
Yossif Helmy
,
Benjamin Nworah
9
Sep 3
Fields not being refreshed
Thank you, Benjamin. I would like to close the ticket. On Wednesday, September 3, 2025 at 4:00:40 PM
unread,
Fields not being refreshed
Thank you, Benjamin. I would like to close the ticket. On Wednesday, September 3, 2025 at 4:00:40 PM
Sep 3
Singh Satish
,
Md. Nazmur Sakib
3
Sep 3
child decoder of windows_eventchannel
Based on my findings at this moment, it is not possible to write sibling decoders for the Windows
unread,
child decoder of windows_eventchannel
Based on my findings at this moment, it is not possible to write sibling decoders for the Windows
Sep 3
하프사
,
ismail....@wazuh.com
2
Sep 3
Custom Log Storage & Alerting on Disk Usage in Lab
Hi, Wazuh generates several internal log files, including alerts.log, archives.log, alerts.json, and
unread,
Custom Log Storage & Alerting on Disk Usage in Lab
Hi, Wazuh generates several internal log files, including alerts.log, archives.log, alerts.json, and
Sep 3
Julio Cesar
,
diego....@wazuh.com
5
Sep 3
Combining pfSense Agent and Syslog Log Collection
Hi, That configuration is performed in Suricata. Wazuh is now configured to receive the logs you
unread,
Combining pfSense Agent and Syslog Log Collection
Hi, That configuration is performed in Suricata. Wazuh is now configured to receive the logs you
Sep 3
Aayush Shrivastava
,
Adedamola Okelola
6
Sep 3
Agent Communication
still the same issue I deployed the new wazuh instance but the issue remanis same Connected 50+
unread,
Agent Communication
still the same issue I deployed the new wazuh instance but the issue remanis same Connected 50+
Sep 3
stefanny chavez anto
,
Javier Rosas
6
Sep 2
ERROR: CANNOT INITIALIZE WAZUH INDEXER CLUSTER
Mira que en la documentación que me mandas del quick start indica que se necesitan al menos 8 GB de
unread,
ERROR: CANNOT INITIALIZE WAZUH INDEXER CLUSTER
Mira que en la documentación que me mandas del quick start indica que se necesitan al menos 8 GB de
Sep 2
Facu Basgall
,
Héctor Gómez
5
Sep 2
Problem installing the agent.
Did you have any luck with this? Were you able to install the agent? On Thursday, August 28, 2025 at
unread,
Problem installing the agent.
Did you have any luck with this? Were you able to install the agent? On Thursday, August 28, 2025 at
Sep 2
Leonardo Ventura
,
Rolly Davany Mougoue Kakanou
2
Sep 2
MISP Integration help
Hello Leonardo, Could you please share the complete alert, ensuring that any sensitive information is
unread,
MISP Integration help
Hello Leonardo, Could you please share the complete alert, ensuring that any sensitive information is
Sep 2
Lucas
,
Leonardo López
4
Sep 2
CloudTrail Log Collection to Central S3 (Log Archive Account) Is Failing
Hello Lucas, I don't think that the issue is the bucket name, but try it if you can. Can you
unread,
CloudTrail Log Collection to Central S3 (Log Archive Account) Is Failing
Hello Lucas, I don't think that the issue is the bucket name, but try it if you can. Can you
Sep 2
avkby445h 24
,
Olamilekan Abdullateef Ajani
2
Sep 2
Cisco-ASA default decoder and rules not working
Hello, If I understand you clearly, you mean the logs are not decoded properly. I feel the way you
unread,
Cisco-ASA default decoder and rules not working
Hello, If I understand you clearly, you mean the logs are not decoded properly. I feel the way you
Sep 2
ShtrudelMan
,
Md. Nazmur Sakib
14
Sep 2
Restoring old logs in the Wazuh Dashboard
Good afternoon! The problem is solved. I did not specify the parameters correctly when running the
unread,
Restoring old logs in the Wazuh Dashboard
Good afternoon! The problem is solved. I did not specify the parameters correctly when running the
Sep 2
Jorge Moya Albarran
,
Isaac Yusuf
2
Sep 2
Close Indexes
Hello, There is no option to configure a "Close" in the Index Lifecycle Management. But
unread,
Close Indexes
Hello, There is no option to configure a "Close" in the Index Lifecycle Management. But
Sep 2
German DiCasas
,
Alberto Marcelino Zárate
3
Sep 2
LDAP user access issue
How can I avoid that the user login? I mean, How is the configuration to check only if the user is
unread,
LDAP user access issue
How can I avoid that the user login? I mean, How is the configuration to check only if the user is
Sep 2
chachab
, …
Singh Satish
7
Sep 2
Help Decoder for MS SQL eventchannel - Application
Hi, Can you please share what exact you did to resolve above issue. On Thursday, June 5, 2025 at 3:41
unread,
Help Decoder for MS SQL eventchannel - Application
Hi, Can you please share what exact you did to resolve above issue. On Thursday, June 5, 2025 at 3:41
Sep 2
sanjay J
,
Jorest Brice Tankoua Njassep
4
Sep 2
Wazuh API connection showing Offline in Dashboard
I need a copy of your Docker Compose file to verify that the network communication between the pods
unread,
Wazuh API connection showing Offline in Dashboard
I need a copy of your Docker Compose file to verify that the network communication between the pods
Sep 2
WENWEN H
,
Stuti Gupta
4
Sep 2
File Integrity Monitoring - Time difference
Hi If you want to stop those noisy ResourceDiscovered / ResourceDeleted events (rule IDs 80454 &
unread,
File Integrity Monitoring - Time difference
Hi If you want to stop those noisy ResourceDiscovered / ResourceDeleted events (rule IDs 80454 &
Sep 2
Victor
,
Jorge Eduardo Silva Jackson
3
Sep 2
Record of compromise attempt using Wazuh Agent
Hi Victor, Thanks for reporting this case — it can be very useful for the community to understand how
unread,
Record of compromise attempt using Wazuh Agent
Hi Victor, Thanks for reporting this case — it can be very useful for the community to understand how
Sep 2
Jorge Moya Albarran
,
Anthony Faruna
2
Sep 1
User creation and deletion
Hello Jorge, Please try the rule below and let me know if it meets your requirements. <rule id=
unread,
User creation and deletion
Hello Jorge, Please try the rule below and let me know if it meets your requirements. <rule id=
Sep 1
Miguel Angel Torrez Maldonado
,
Pablo Ariel Gonzalez
2
Sep 1
Integration - UNIX Socket Communication
Miguel: I understand that, based on what you explained, the current approach might not fully fit your
unread,
Integration - UNIX Socket Communication
Miguel: I understand that, based on what you explained, the current approach might not fully fit your
Sep 1
Nico Alonso
,
Olamilekan Abdullateef Ajani
2
Sep 1
Ignore all alerts generated by an OpenVAS
Hello Nico, If you are aiming to ignore/silent event from the source IP of openVAS, you can simple
unread,
Ignore all alerts generated by an OpenVAS
Hello Nico, If you are aiming to ignore/silent event from the source IP of openVAS, you can simple
Sep 1
Francesc G
,
Isaac Yusuf
3
Sep 1
Cluster health turns yellow monthly
I had to change the plugins.security.system_indices.enabled parameter to false in /etc/wazuh-indexer/
unread,
Cluster health turns yellow monthly
I had to change the plugins.security.system_indices.enabled parameter to false in /etc/wazuh-indexer/
Sep 1
George Paun
,
hasitha.u...@wazuh.com
4
Sep 1
user admin
To be more explicit i need for all users with role Administrators Pe luni, 1 septembrie 2025, la 12:
unread,
user admin
To be more explicit i need for all users with role Administrators Pe luni, 1 septembrie 2025, la 12:
Sep 1