Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16116
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Yogi Valentino
,
hasitha.u...@wazuh.com
3
4:35 AM
Wazuh Sysmon App Opened
Hi Yogi, You want your Wazuh and Sysmon setup to generate alerts only for applications that you
unread,
Wazuh Sysmon App Opened
Hi Yogi, You want your Wazuh and Sysmon setup to generate alerts only for applications that you
4:35 AM
CIA
, …
hasitha.u...@wazuh.com
3
4:32 AM
wazuh&& pfsense
Hi CIA, I have found a third-party resource that helps you to forward the logs to Wazuh. To listen to
unread,
wazuh&& pfsense
Hi CIA, I have found a third-party resource that helps you to forward the logs to Wazuh. To listen to
4:32 AM
Yap Toni
,
hasitha.u...@wazuh.com
4
1:04 AM
Parse DNS Server - Analytical log to Wazuh
Hi Yap, It would be helpful if you could share sample JSON logs from the DNS Server logs. By default,
unread,
Parse DNS Server - Analytical log to Wazuh
Hi Yap, It would be helpful if you could share sample JSON logs from the DNS Server logs. By default,
1:04 AM
Baran
,
antonio...@wazuh.com
2
Dec 26
Advice needed: Upgrade strategy for multiple Wazuh environments (v4.3.6, v4.9.2, v4.11.2)
Hi Baran, Since version 4.3, many changes have been introduced. I recommend that you take a look at
unread,
Advice needed: Upgrade strategy for multiple Wazuh environments (v4.3.6, v4.9.2, v4.11.2)
Hi Baran, Since version 4.3, many changes have been introduced. I recommend that you take a look at
Dec 26
Facu Basgall
,
Carlos Ezequiel Bordon
8
Dec 26
Error - Wazuh integration Azure Log Analytics
Currently, the following tables are supported: https://learn.microsoft.com/en-us/azure/azure-monitor/
unread,
Error - Wazuh integration Azure Log Analytics
Currently, the following tables are supported: https://learn.microsoft.com/en-us/azure/azure-monitor/
Dec 26
Giuseppe Ruberto
,
Stuti Gupta
4
Dec 26
OPNsense filterlog decoder
Hi The default decoder is decoding most of the fields, you can see in the image. Can you please let
unread,
OPNsense filterlog decoder
Hi The default decoder is decoding most of the fields, you can see in the image. Can you please let
Dec 26
Prince
,
Cedrick Foko
2
Dec 26
Custom Active Response Not Executing on Wazuh Agent
Hello Prince, In order to execute the script on the agents, you need to add your custom active
unread,
Custom Active Response Not Executing on Wazuh Agent
Hello Prince, In order to execute the script on the agents, you need to add your custom active
Dec 26
john
,
Stuti Gupta
11
Dec 26
Wazuh Dashboard – ResponseError / OpenSearch 503 issue
Hi John, Sorry for the late reply. I'm glad to hear that the indexer issue has been resolved.
unread,
Wazuh Dashboard – ResponseError / OpenSearch 503 issue
Hi John, Sorry for the late reply. I'm glad to hear that the indexer issue has been resolved.
Dec 26
john
,
Md. Nazmur Sakib
2
Dec 26
RequestError: Error fetching items
Hi John, Are you getting this error with the admin user or some other custom user you have created?
unread,
RequestError: Error fetching items
Hi John, Are you getting this error with the admin user or some other custom user you have created?
Dec 26
Tengku Arya Saputra
,
Md. Nazmur Sakib
2
Dec 26
Ignore 404 status code
Hello Tengku, Can you explain your query in detail? Are you trying to filter out logs from triggering
unread,
Ignore 404 status code
Hello Tengku, Can you explain your query in detail? Are you trying to filter out logs from triggering
Dec 26
A Bobrov
,
Md. Nazmur Sakib
2
Dec 26
range ports
Hello You cannot use multiple ports in the </port> section of the <remote> block. <
unread,
range ports
Hello You cannot use multiple ports in the </port> section of the <remote> block. <
Dec 26
Tengku Arya Saputra
,
Md. Nazmur Sakib
2
Dec 26
FIX Email alerting
Hello Tengku, It seems to me the issue is with SMTP server name <smtp_server>smtp.office365.com
unread,
FIX Email alerting
Hello Tengku, It seems to me the issue is with SMTP server name <smtp_server>smtp.office365.com
Dec 26
M V
,
Karlo Balmores Veranga
4
Dec 26
Custom integration issue
Hi, You already have <alert_format>json</alert_format>, so we need to check if alerts are
unread,
Custom integration issue
Hi, You already have <alert_format>json</alert_format>, so we need to check if alerts are
Dec 26
Veera
,
Karlo Balmores Veranga
3
Dec 26
Wazuh agent auto upgrade
Hi, Do you still need assitance? Thanks, On Friday, December 19, 2025 at 1:51:27 PM UTC+8 Karlo
unread,
Wazuh agent auto upgrade
Hi, Do you still need assitance? Thanks, On Friday, December 19, 2025 at 1:51:27 PM UTC+8 Karlo
Dec 26
Yogi Valentino
, …
Jack Martin
7
Dec 25
Rules to Detect Disconnect PNP Wazuh
Hello, I need assistance with a task where a message should be displayed when a USB device is
unread,
Rules to Detect Disconnect PNP Wazuh
Hello, I need assistance with a task where a message should be displayed when a USB device is
Dec 25
Narasimha Naidu B
,
hasitha.u...@wazuh.com
3
Dec 24
Request Assistance: AD Integration with Wazuh Dashboard Login
Hi Hasitha, I followed the document and updated the required details; however, I'm still unable
unread,
Request Assistance: AD Integration with Wazuh Dashboard Login
Hi Hasitha, I followed the document and updated the required details; however, I'm still unable
Dec 24
Riccardo Olivetto
,
Olamilekan Abdullateef Ajani
8
Dec 24
Wazuh create alert for syslog logs
Hello Riccardo, I am glad to hear that it all works now. For the new use case you have shared, you
unread,
Wazuh create alert for syslog logs
Hello Riccardo, I am glad to hear that it all works now. For the new use case you have shared, you
Dec 24
EugenX
,
carlos...@wazuh.com
2
Dec 24
Rule: 92058 fired (level 12) -> "Application Compatibility Database launched"
Hello EugenX, It looks like this alert is being triggered due to the sdbinst.exe utility, which is
unread,
Rule: 92058 fired (level 12) -> "Application Compatibility Database launched"
Hello EugenX, It looks like this alert is being triggered due to the sdbinst.exe utility, which is
Dec 24
RusFM
,
Javier Rosas
3
Dec 23
Timestamp is Ingest Time
Hello again. Not sure I follow this. The @timestamp field differs from the date of the log? This
unread,
Timestamp is Ingest Time
Hello again. Not sure I follow this. The @timestamp field differs from the date of the log? This
Dec 23
Narasimha Naidu B
,
Olamilekan Abdullateef Ajani
3
Dec 23
Feasibility of Monitoring Browser History via Wazuh
Hello Narasimha, To follow up on this, I found the blog below, which you can also use as a reference
unread,
Feasibility of Monitoring Browser History via Wazuh
Hello Narasimha, To follow up on this, I found the blog below, which you can also use as a reference
Dec 23
German DiCasas
, …
Jose Camargo
7
Dec 23
Vulnerability scanner - no official fix
I have a CVE that is CVE-2025-9086 over a Ubuntu 22.04.5 LTS (Jammy Jellyfish). Wazuh 4.14.1 show
unread,
Vulnerability scanner - no official fix
I have a CVE that is CVE-2025-9086 over a Ubuntu 22.04.5 LTS (Jammy Jellyfish). Wazuh 4.14.1 show
Dec 23
gustavo rodriguez
,
lucas....@wazuh.com
2
Dec 23
Issue using CDB lists in Wazuh 4.14.1 (Docker) – lists not loading
Hi! Those warnings usually mean the manager cant find or read the list files from inside the
unread,
Issue using CDB lists in Wazuh 4.14.1 (Docker) – lists not loading
Hi! Those warnings usually mean the manager cant find or read the list files from inside the
Dec 23
Facu Basgall
,
Luis Enrique Chico Capistrano
5
Dec 23
Help with a rule
Hi, the ruler is not working as expected. It is still capturing the event of the rule 60204 even if
unread,
Help with a rule
Hi, the ruler is not working as expected. It is still capturing the event of the rule 60204 even if
Dec 23
Rahul Manoj
,
Olamilekan Abdullateef Ajani
2
Dec 23
ERR_BAD_REQUEST while saving rule files – API reports daemons restarting, but backend shows all running
Hello, When you try to save a rule from the Wazuh GUI, Wazuh triggers a restart of the manager demons
unread,
ERR_BAD_REQUEST while saving rule files – API reports daemons restarting, but backend shows all running
Hello, When you try to save a rule from the Wazuh GUI, Wazuh triggers a restart of the manager demons
Dec 23
Stefan Penchev
,
Olamilekan Abdullateef Ajani
2
Dec 23
Wazuh centralized configuration - sysmonconfig.xml
Hello, The issue I see here is the XML file drilldown you did with the syscheck directory block. The
unread,
Wazuh centralized configuration - sysmonconfig.xml
Hello, The issue I see here is the XML file drilldown you did with the syscheck directory block. The
Dec 23
Mefisto Evil
,
Maximiliano Ibarra
3
Dec 23
wazuh triggering allert to whatsup that is not even installed on windows server
hello i dont have vulnerabilities.log file on wazuh manager somehow cat: /var/ossec/logs/
unread,
wazuh triggering allert to whatsup that is not even installed on windows server
hello i dont have vulnerabilities.log file on wazuh manager somehow cat: /var/ossec/logs/
Dec 23
Adrien Di Cristofaro
,
Stuti Gupta
12
Dec 23
Wazuh agents stop reporting after OS update & reboot (v4.14.0.1)
It seems that everything is back in order. CVE's from december security update has been detected
unread,
Wazuh agents stop reporting after OS update & reboot (v4.14.0.1)
It seems that everything is back in order. CVE's from december security update has been detected
Dec 23
Deepak Kumar
,
Bony V John
3
Dec 23
Vulnerability Events not showing in Wazuh
Hi, First, I will explain how vulnerability alerts are generated in Wazuh. The Vulnerability
unread,
Vulnerability Events not showing in Wazuh
Hi, First, I will explain how vulnerability alerts are generated in Wazuh. The Vulnerability
Dec 23
Robby Hunters
,
hasitha.u...@wazuh.com
4
Dec 22
Docker events only generate network bridge connect/disconnect alerts – missing container action alerts (eg. pause/unpause/start)
Hi Robby, I've attached the GitHub link here so you can review the latest updates from the
unread,
Docker events only generate network bridge connect/disconnect alerts – missing container action alerts (eg. pause/unpause/start)
Hi Robby, I've attached the GitHub link here so you can review the latest updates from the
Dec 22
G Mail
,
hasitha.u...@wazuh.com
3
Dec 22
Wazuh not logging me in anywhere.
Hi G Mail, Please let me know the update on this, so we can check further. On Sunday, December 21,
unread,
Wazuh not logging me in anywhere.
Hi G Mail, Please let me know the update on this, so we can check further. On Sunday, December 21,
Dec 22