Groups
Groups
Conversations
All groups and messages
Send feedback to Google
Help
Training
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Wazuh | Mailing List
Contact owners and managers
1–30 of 16530
Welcome to Wazuh mailing list. Our team will be happy to answer and help with all your questions.
We look forward to your feedback and contributions.
Mark all as read
Report group
0 selected
Brenno Garcia
,
Hernán Osvaldo Santiago Valenzuela
4
8:22 AM
Office GeoIP
Hello, still not working This decoder doesnt work and all office logs alerted by rule 1002 unknown
unread,
Office GeoIP
Hello, still not working This decoder doesnt work and all office logs alerted by rule 1002 unknown
8:22 AM
Narasimha Naidu B
,
Bony V John
5
8:14 AM
Email Notifications and Critical Alerts
Hi Bony, Thanks for your support. I have made the changes in OSSEC as per the document, and I am now
unread,
Email Notifications and Critical Alerts
Hi Bony, Thanks for your support. I have made the changes in OSSEC as per the document, and I am now
8:14 AM
Md. Nazmur Sakib
2
7:15 AM
Changing wazuh dashboard password
Hello, the test is working. good so far On Monday, April 27, 2026 at 5:10:02 PM UTC+6 Md. Nazmur
unread,
Changing wazuh dashboard password
Hello, the test is working. good so far On Monday, April 27, 2026 at 5:10:02 PM UTC+6 Md. Nazmur
7:15 AM
Md. Nazmur Sakib
3
7:08 AM
Email Notifications and Critical Alerts
cool cool cool On Monday, April 27, 2026 at 5:06:21 PM UTC+6 Md. Nazmur Sakib wrote: Hi, You can
unread,
Email Notifications and Critical Alerts
cool cool cool On Monday, April 27, 2026 at 5:06:21 PM UTC+6 Md. Nazmur Sakib wrote: Hi, You can
7:08 AM
Emar Flix
,
Bony V John
3
5:53 AM
Wazuh master node queue/db directory growing indefinitely due to syscheck FIM entries
Hi, I understand your issue. The /var/ossec/queue/db/ directory is used by FIM, Syscollector, and SCA
unread,
Wazuh master node queue/db directory growing indefinitely due to syscheck FIM entries
Hi, I understand your issue. The /var/ossec/queue/db/ directory is used by FIM, Syscollector, and SCA
5:53 AM
M G
,
Henadence Anyam
6
4:21 AM
FIM - realtime, files
Hi MG, Realtime monitoring applies to both directories and files. For directories, it monitors all
unread,
FIM - realtime, files
Hi MG, Realtime monitoring applies to both directories and files. For directories, it monitors all
4:21 AM
Veera
,
Musbau Adekunle Soladoye
11
Apr 26
vulnerabilities not reported for selected agents
Hi @ Musbau Adekunle Soladoye Help me with the information on my previous query .. On Tuesday, April
unread,
vulnerabilities not reported for selected agents
Hi @ Musbau Adekunle Soladoye Help me with the information on my previous query .. On Tuesday, April
Apr 26
bastian Caro
,
Victor Carlos Erenu
2
Apr 24
Parsing decoder fallido
Hi bastian Caro Regarding your environment, can you tell me which version of Wazuh you're using?
unread,
Parsing decoder fallido
Hi bastian Caro Regarding your environment, can you tell me which version of Wazuh you're using?
Apr 24
Sparta Spartan
,
Olamilekan Abdullateef Ajani
2
Apr 24
Agent not sending logs
Hello Spartan, Best way to do this is to filter from the Discover dashboard using the agent ID and
unread,
Agent not sending logs
Hello Spartan, Best way to do this is to filter from the Discover dashboard using the agent ID and
Apr 24
Mihir
Apr 24
what is the proper way of changing wazuh dashboard password for multi node deployment?
unread,
what is the proper way of changing wazuh dashboard password for multi node deployment?
Apr 24
Wazuh Server
,
Md. Nazmur Sakib
2
Apr 24
Wazuh Dashboard Agent not Visible
Hello! Please review while mapping the user with the Wazuh API, you have given the correct permission
unread,
Wazuh Dashboard Agent not Visible
Hello! Please review while mapping the user with the Wazuh API, you have given the correct permission
Apr 24
exe
,
Awwal Ishiaku
10
Apr 23
Deleted duplicate index pattern, visualization now broken
Update: Your destination alerts index will look like "dest": { "index": "
unread,
Deleted duplicate index pattern, visualization now broken
Update: Your destination alerts index will look like "dest": { "index": "
Apr 23
Daniel
, …
Gustavo Choquevilca
17
Apr 23
Vulnerability Inventory not working on Windows hosts
Hello Daniel, Good news, we checked the wazuh-indexer index directly and the vulnerability data for
unread,
Vulnerability Inventory not working on Windows hosts
Hello Daniel, Good news, we checked the wazuh-indexer index directly and the vulnerability data for
Apr 23
Nhân Nguyễn
,
Md. Nazmur Sakib
6
Apr 23
I need help because Wazuh Decoder and Ruleset are running well, but there are no alerts on the dashboard.
Dear Md. Nazmur Sakib, I tried the decoder and ruleset you sent me, and when I applied them, an alert
unread,
I need help because Wazuh Decoder and Ruleset are running well, but there are no alerts on the dashboard.
Dear Md. Nazmur Sakib, I tried the decoder and ruleset you sent me, and when I applied them, an alert
Apr 23
Aamir Sohail
, …
Md. Nazmur Sakib
8
Apr 23
vulnerability events
Hi Aamir, There are no vulnerability alert triggers for the initial or baseline vulnerability scan.
unread,
vulnerability events
Hi Aamir, There are no vulnerability alert triggers for the initial or baseline vulnerability scan.
Apr 23
Brenno Garcia
,
Javier Adán Méndez Méndez
3
Apr 22
Gravityzone Decoders
Hi Brenno Try adding both use_own_name and a specific prematch to that child decoder: <decoder
unread,
Gravityzone Decoders
Hi Brenno Try adding both use_own_name and a specific prematch to that child decoder: <decoder
Apr 22
Wazuh Server
,
Luciano Valinotti
2
Apr 22
Need to get the logs export in local system
In Wazuh, “logs” can refer to different data sources (agent logs, alerts, or events stored in the
unread,
Need to get the logs export in local system
In Wazuh, “logs” can refer to different data sources (agent logs, alerts, or events stored in the
Apr 22
Emar Flix
,
Victor Carlos Erenu
7
Apr 22
/var/ossec/queue/db overload
Hi, Carlos I think is will help me: <syscheck> <disabled>no</disabled> <
unread,
/var/ossec/queue/db overload
Hi, Carlos I think is will help me: <syscheck> <disabled>no</disabled> <
Apr 22
Miran Ul Haq
,
Diego Guerrero
4
Apr 22
Group based agent configuration
Hi Diego, I was able to fix the issue. Again, it was simple permissions issue. Another problem I
unread,
Group based agent configuration
Hi Diego, I was able to fix the issue. Again, it was simple permissions issue. Another problem I
Apr 22
Todor Dimitrov
, …
Peter Santiago
6
Apr 22
Trojaned version of file detected.
Hi team, On Debian Trixie. /usr/bin/chsh /bin/passwd /usr/bin/passwd /usr/bin/chsh Is there a more
unread,
Trojaned version of file detected.
Hi team, On Debian Trixie. /usr/bin/chsh /bin/passwd /usr/bin/passwd /usr/bin/chsh Is there a more
Apr 22
hvn4k.
,
Md. Nazmur Sakib
2
Apr 22
Default Decoder not extracting srcip/usrname, Need to write custom decoder(s).
Hello! To achieve this, you need to modify the existing default decoders with the custom decoders. To
unread,
Default Decoder not extracting srcip/usrname, Need to write custom decoder(s).
Hello! To achieve this, you need to modify the existing default decoders with the custom decoders. To
Apr 22
Neil Roña
,
[email protected]
7
Apr 22
Can you please help me debug this one
Hi , This is okay already, we created new wazuh instance and then migrated all data to it On
unread,
Can you please help me debug this one
Hi , This is okay already, we created new wazuh instance and then migrated all data to it On
Apr 22
Ali Bajaj
,
Md. Nazmur Sakib
15
Apr 22
Wazuh Server do not collect logs
When it is possible to increase the shard limit, it is not advisable to increase the number too high
unread,
Wazuh Server do not collect logs
When it is possible to increase the shard limit, it is not advisable to increase the number too high
Apr 22
exe
,
Bony V John
8
Apr 22
CVE should be fixed but not showing in wazuh
Hi, Apologies for the late response. From the shared manager log, it seems you have two issues. One
unread,
CVE should be fixed but not showing in wazuh
Hi, Apologies for the late response. From the shared manager log, it seems you have two issues. One
Apr 22
Jack Martin
,
Farouk Musa
10
Apr 21
Help Needed: Creating a Custom Dashboard with Click-Through Alert Details and Custom Rules in Wazuh
For that dashboard, it wont be possible to drill down. On Tuesday, April 21, 2026 at 5:23:28 PM UTC+1
unread,
Help Needed: Creating a Custom Dashboard with Click-Through Alert Details and Custom Rules in Wazuh
For that dashboard, it wont be possible to drill down. On Tuesday, April 21, 2026 at 5:23:28 PM UTC+1
Apr 21
Harsh Godiwala
,
[email protected]
2
Apr 21
conflict in field name type
The images you attached shows the conflict in data.EventCount is happening because different indices
unread,
conflict in field name type
The images you attached shows the conflict in data.EventCount is happening because different indices
Apr 21
Domenica Wairimu
,
Olamilekan Abdullateef Ajani
4
Apr 21
EasyNAC Decoders and Rules
Hello Domenica, Can you please share something similar to the log line below from archives.json file
unread,
EasyNAC Decoders and Rules
Hello Domenica, Can you please share something similar to the log line below from archives.json file
Apr 21
M Jones
,
[email protected]
2
Apr 21
M365 Alerting
Hi M Jones, Yes, this is possible. GeoIP data should be inserted before rule matching, so you can do
unread,
M365 Alerting
Hi M Jones, Yes, this is possible. GeoIP data should be inserted before rule matching, so you can do
Apr 21
Suvadip Ghosh
,
Nicolas Zapata
7
Apr 21
Wazuh Integration with AWS RDS PGSQL
Hello team, Kindly help here. On Thursday, April 16, 2026 at 6:15:01 PM UTC+5:30 Suvadip Ghosh wrote:
unread,
Wazuh Integration with AWS RDS PGSQL
Hello team, Kindly help here. On Thursday, April 16, 2026 at 6:15:01 PM UTC+5:30 Suvadip Ghosh wrote:
Apr 21
Isaac S.
,
[email protected]
5
Apr 20
Cluster RED status and unassigned shards
Hi Isaac, I am glad that your issue has been resolved! On Monday, April 20, 2026 at 11:33:16 PM UTC+5
unread,
Cluster RED status and unassigned shards
Hi Isaac, I am glad that your issue has been resolved! On Monday, April 20, 2026 at 11:33:16 PM UTC+5
Apr 20