Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Wazuh | Mailing List
Contact owners and managers
1–30 of 16294
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
DIWAHAR RAHAWID
,
Stuti Gupta
4
1:55 AM
FIM Monitoring
As expected, the issue is because the agent is processing a very large number of files when an entire
unread,
FIM Monitoring
As expected, the issue is because the agent is processing a very large number of files when an entire
1:55 AM
Yogi Valentino
1:50 AM
Wazuh Agent ID Back to 001
I was using Wazuh and Adding agent tester, then i removed it. When I put new agent it's continued
unread,
Wazuh Agent ID Back to 001
I was using Wazuh and Adding agent tester, then i removed it. When I put new agent it's continued
1:50 AM
Emr
1:50 AM
Efficient methods for searching archived Wazuh logs with unknown attribute locations?
Hi everyone, I need to search through 5 months of archived Wazuh alerts (gzipped JSON files), but I
unread,
Efficient methods for searching archived Wazuh logs with unknown attribute locations?
Hi everyone, I need to search through 5 months of archived Wazuh alerts (gzipped JSON files), but I
1:50 AM
Mohammad Firman Riyadi
,
[email protected]
4
1:44 AM
Wazuh Alerting: Telegram notifications stopped after deduplication attempt
I created a custom rule to deduplicate web server 400 errors (Rule 31151). My goal is to receive only
unread,
Wazuh Alerting: Telegram notifications stopped after deduplication attempt
I created a custom rule to deduplicate web server 400 errors (Rule 31151). My goal is to receive only
1:44 AM
никита какдела
,
Md. Nazmur Sakib
11
1:43 AM
PowerShell 4103
After checking this behavior, I found out that the lines below are intended to extract the userID
unread,
PowerShell 4103
After checking this behavior, I found out that the lines below are intended to extract the userID
1:43 AM
никита какдела
,
[email protected]
11
Feb 8
Per_bucket monitor performance
Hi никита, Right now, you only count how many IPs a user used (cardinality agg), but you don't
unread,
Per_bucket monitor performance
Hi никита, Right now, you only count how many IPs a user used (cardinality agg), but you don't
Feb 8
Omar Hassan
,
[email protected]
2
Feb 8
Custom Alerts passing ruleset test but failing to reach the Wazuh alerts file
Hi, Thank you for sharing the details, as per the sample rule and the sample full log provided, the
unread,
Custom Alerts passing ruleset test but failing to reach the Wazuh alerts file
Hi, Thank you for sharing the details, as per the sample rule and the sample full log provided, the
Feb 8
Satiswaran Selva Sakeram
, …
Dhoni
7
Feb 8
Email configuration
Thanks Dhoni On Tue, 27 Jan 2026 at 8:12 PM, Dhoni <
[email protected]
> wrote: check
unread,
Email configuration
Thanks Dhoni On Tue, 27 Jan 2026 at 8:12 PM, Dhoni <
[email protected]
> wrote: check
Feb 8
Satiswaran Selva Sakeram
,
[email protected]
2
Feb 8
Sophos Central Integration
Hi Satiswaran, If that's the case, you'll need to create a custom script to authenticate with
unread,
Sophos Central Integration
Hi Satiswaran, If that's the case, you'll need to create a custom script to authenticate with
Feb 8
CRIZ
,
[email protected]
3
Feb 8
Clarification on CDB Value Limits
Hi CRIZ, Wazuh doesn't have a fixed maximum limit on how many values (or entries) you can put in
unread,
Clarification on CDB Value Limits
Hi CRIZ, Wazuh doesn't have a fixed maximum limit on how many values (or entries) you can put in
Feb 8
Yazid
,
Richmond Aribibia Fimie
14
Feb 8
Wazuh / Symentec Integration
Hello @richmond, are you still available for help please ? am still struggling with the issue and
unread,
Wazuh / Symentec Integration
Hello @richmond, are you still available for help please ? am still struggling with the issue and
Feb 8
Brenno Garcia
,
[email protected]
2
Feb 8
Wazuh + Office365 Problem
Hi Brenno, By default, the module's only_future_events setting is set to yes, which means it
unread,
Wazuh + Office365 Problem
Hi Brenno, By default, the module's only_future_events setting is set to yes, which means it
Feb 8
ACH. MUQODDAM
,
[email protected]
3
Feb 7
mail kernel: device vethc4ea9f2 entered promiscuous mode
Hi ACH. MUQODDAM, Based on the shared log and the custom rule, I noticed a couple of issues. First,
unread,
mail kernel: device vethc4ea9f2 entered promiscuous mode
Hi ACH. MUQODDAM, Based on the shared log and the custom rule, I noticed a couple of issues. First,
Feb 7
Mohammad Firman Riyadi
2
Feb 7
Wazuh Telegram alerts stopped after deduplication via Dashboard Alerting and local rules
After I applied deduplication settings in the Wazuh Dashboard Alerting menu and modified my local
unread,
Wazuh Telegram alerts stopped after deduplication via Dashboard Alerting and local rules
After I applied deduplication settings in the Wazuh Dashboard Alerting menu and modified my local
Feb 7
Roksi
,
Matías Exequiel García
2
Feb 7
Few Wazuh agents wont upgrade
Hi Roksi. From what we see, the manager is able to send the WPK, but the agent fails when it tries to
unread,
Few Wazuh agents wont upgrade
Hi Roksi. From what we see, the manager is able to send the WPK, but the agent fails when it tries to
Feb 7
Jacob Molland
Feb 6
Wazuh trusting Keycloak Certs
Hey all, I have been trying to configure Wazuh to use Keycloak as an IdP via OIDC (OpenID Connect). I
unread,
Wazuh trusting Keycloak Certs
Hey all, I have been trying to configure Wazuh to use Keycloak as an IdP via OIDC (OpenID Connect). I
Feb 6
Shihab Hossain Shifat
,
[email protected]
5
Feb 6
Wazuh_Terraform_Setup
Hi, Thanks for you reply I can't find any directory like /var/lib/wazuh/wazuh-indexer-data/
unread,
Wazuh_Terraform_Setup
Hi, Thanks for you reply I can't find any directory like /var/lib/wazuh/wazuh-indexer-data/
Feb 6
Facu Basgall
,
Luis Enrique Chico Capistrano
23
Feb 6
Help with a rule
Hi Facu, Based on the archives.log files that you shared, I couldn't trigger any events for rule
unread,
Help with a rule
Hi Facu, Based on the archives.log files that you shared, I couldn't trigger any events for rule
Feb 6
Gokul Suresh
,
Himanshu Sharma
7
Feb 6
Virustotal integration errors in ossec.log
Thank you Himanshu for your reply. Currently there are no errors regarding this issue. Anyway I will
unread,
Virustotal integration errors in ossec.log
Thank you Himanshu for your reply. Currently there are no errors regarding this issue. Anyway I will
Feb 6
igor
,
Md. Nazmur Sakib
4
Feb 6
Indexer not indexing
I suggest you change the number of shards to 1 for each index. The default number is 3 shards for the
unread,
Indexer not indexing
I suggest you change the number of shards to 1 for each index. The default number is 3 shards for the
Feb 6
Aamir Sohail
, …
Francis Timilehin Jeremiah
6
Feb 6
vulnerability events
Hello, I just followed the instructions above and I was able to generate alerts on the Events tab of
unread,
vulnerability events
Hello, I just followed the instructions above and I was able to generate alerts on the Events tab of
Feb 6
[email protected]
,
Dennis Ariel Gamboa Veliz
5
Feb 5
Stuck with Hygeine Indexes
Got it! I suspect the issue is that the password has special characters and I did not surround it
unread,
Stuck with Hygeine Indexes
Got it! I suspect the issue is that the password has special characters and I did not surround it
Feb 5
Paul Charran
,
Jorge Ardila
10
Feb 5
using read_only_root_filesystem
Hi Paul. The folder /var/ossec/etc and any subfolder included there should not be mounted as RW,
unread,
using read_only_root_filesystem
Hi Paul. The folder /var/ossec/etc and any subfolder included there should not be mounted as RW,
Feb 5
Kenyanetwork team
,
Carlos Ezequiel Bordon
2
Feb 5
Wazuh Not Matching Custom Decoder/Rules for Hikvision NVR Logs
From what I can understand, your logs are being decoded with the JSON decoder. Please share some
unread,
Wazuh Not Matching Custom Decoder/Rules for Hikvision NVR Logs
From what I can understand, your logs are being decoded with the JSON decoder. Please share some
Feb 5
Andrehens Chicfici
,
J. Rome
5
Feb 5
Custom Auddiocodes SBC Decoder
So I went back to this project and the weird thing is: This log message gets decoded: 2026-01-23T03:
unread,
Custom Auddiocodes SBC Decoder
So I went back to this project and the weird thing is: This log message gets decoded: 2026-01-23T03:
Feb 5
EugenX
,
[email protected]
3
Feb 5
Rule: 92058 fired (level 12) -> "Application Compatibility Database launched"
Thank you Carlos, for you support, but unfortunately the rule you provided doesn't seem to work.
unread,
Rule: 92058 fired (level 12) -> "Application Compatibility Database launched"
Thank you Carlos, for you support, but unfortunately the rule you provided doesn't seem to work.
Feb 5
João Castanheira
,
Carlos Anguita López
2
Feb 5
Wazuh Kubernetes Deployment with Multi-Tenancy and RBAC
From a deployment perspective, running Wazuh on Kubernetes is feasible and allows you to benefit from
unread,
Wazuh Kubernetes Deployment with Multi-Tenancy and RBAC
From a deployment perspective, running Wazuh on Kubernetes is feasible and allows you to benefit from
Feb 5
Chandra pal singh Chauhan
,
Javier Sanchez Gil
12
Feb 5
Implementing PostgreSQL Login Monitoring Use Cases in Wazuh (DAM Compliance)
Hi Chandra, I re-tested the entire flow end-to-end, making a few adjustments to the decoder, and
unread,
Implementing PostgreSQL Login Monitoring Use Cases in Wazuh (DAM Compliance)
Hi Chandra, I re-tested the entire flow end-to-end, making a few adjustments to the decoder, and
Feb 5
Tengku Arya Saputra
,
Bony V John
3
Feb 5
False Positive detect webshell
Hi, If your goal is to trigger alerts when a PHP-like file is created or modified under: /<path
unread,
False Positive detect webshell
Hi, If your goal is to trigger alerts when a PHP-like file is created or modified under: /<path
Feb 5
Ham Somalyvann
,
Cristina Vico González
9
Feb 5
Watchguard Firebox Decoder and Rule
Hello, The official Wazuh documentation provides information on the syntax of decoders and rules, as
unread,
Watchguard Firebox Decoder and Rule
Hello, The official Wazuh documentation provides information on the syntax of decoders and rules, as
Feb 5