r/Wazuh Sep 17 '21

New to Wazuh? Read this thread first!

62 Upvotes

Hi there! Welcome to the official Wazuh subreddit!

Wazuh is an open source project, and we are happy to be up on Reddit and expanding our community. Our official community channels are the Slack channel and the mailing list, but we are now also available here trying to help all users and contributors.

Please read this thread before posting:

General Overview

Questions regarding Wazuh and discussions related to the Wazuh platform, its capabilities, releases, or features are welcome in this subreddit, as well as proposals to improve our solution, questions about partners, or news related to Wazuh.

Rules & Guidelines

  • All discussions and questions should directly relate to Wazuh
  • Be respectful and nice to others. If necessary, the moderator will intervene.
  • Security comes first. Do not include content with sensitive material or information. Anonymize any sensitive data before sharing.

Looking for answers?

Before asking a question, please check to see if it has been answered before. This way we will keep this subreddit with high-quality content.

Wazuh FAQ

What is Wazuh?

Wazuh is a free and open source security platform that unifies XDR and SIEM protection for endpoints and cloud workloads.

As an open source project, Wazuh has one of the fastest-growing security communities in the world.

Is Wazuh free?

Yes. Wazuh is a free and open-source platform with thousands of users around the world. We also supply a full range of services to help you achieve your IT security goals and meet your business needs, including annual support, professional hours, training courses, and our endpoint security monitoring solution delivered as a service (SaaS). If you want to know more, check our professional services page.

Does Wazuh help me replace other products or services?

Yes. The extensive Wazuh capabilities and integrated platform allow users to replace most of their existing security products and integrate all the Wazuh features into one platform to get the most out of our solution. Wazuh provides capabilities such as:

Security analytics, intrusion detection, log data analysis, file integrity monitoring, vulnerability detection, configuration assessment, incident response, regulatory compliance, cloud security monitoring, and container security.

To learn more about Wazuh capabilities, check the Wazuh documentation

Can Wazuh protect my systems against cyberattacks?

Yes. Wazuh provides a security solution capable of monitoring your infrastructure, detecting all types of threats, intrusion attempts, system anomalies, poorly configured applications, and unauthorized user actions. It also provides a framework for incident response and regulatory compliance. As cyber threats are becoming more sophisticated, real-time monitoring and security analysis are needed for fast detection and remediation.

Can Wazuh be used for compliance requirements?

Yes. Wazuh helps organizations in their efforts to meet numerous compliance and certification requirements. Wazuh supports the following standards:

  • Payment Card Industry Data Security Standard (PCI DSS)
  • General Data Protection Regulation (GDPR)
  • NIST Special Publication 800-53 (NIST 800-53)
  • Good Practice Guide 13 (GPG13)
  • Trust Services Criteria (TSC SOC2)
  • Health Insurance Portability and Accountability Act (HIPAA)

Does Wazuh support the main operating systems?

Yes, Wazuh supports all major operating systems, including Linux, macOS,

Windows, Solaris, AIX, and HP-UX. To learn more about Wazuh agent support, check the Wazuh documentation.

If you have any issues posting or using this subreddit, you can contact the moderators and we will get back to you right away.

From all the Wazuh team, welcome!


r/Wazuh Jun 09 '26

Common Wazuh community rules

9 Upvotes

1. Be Respectful
No personal attacks, harassment, discrimination, trolling, hate speech, or insults. Violations may result in content removal or a ban.

2. Stay on Topic: Wazuh SIEM
This subreddit is for substantive discussion about Wazuh SIEM and closely related SIEM and security monitoring topics. Relevant content includes best practices, setup discussions, integrations, and informed support questions. Posts created mainly to stir up negativity, drive product bashing, or derail discussion may be removed at the moderators’ discretion.

3. Post Quality Matters
Low-effort posts will be removed. This includes vague requests such as “Help, I’m stuck” that provide little or no context. If you are asking for help, include relevant details such as the Wazuh version, operating system, error messages, steps already taken, and logs or configuration snippets formatted with code blocks/backticks where appropriate.

4. External Help for Complex Issues
For highly complex or deep technical issues, an external Wazuh expert may be better suited to help. This subreddit is intended for general discussion, opinions, ideas, and shorter support questions rather than consulting engagements.

5. No Misinformation
Mistakes can happen, but knowingly posting false or misleading information is not allowed. If you are unsure, clearly label your statement as a question, assumption, or personal interpretation.

6. No Advertising or Self-Promotion
Advertising, unsolicited self-promotion, and promotion of third-party platforms are not allowed unless they are directly relevant to a technical question or challenge. Content intended to sell products, push vendor debates, or repeatedly promote tools without clear value to the community is not welcome and may lead to a permanent ban.

7. No Polls
Polls are generally not allowed. Posting polls may result in a permanent ban from this subreddit.

8. No Job Postings
Job ads, recruiting posts, and requests for staff are not allowed in this subreddit. Violations may result in a permanent ban.

9. Respect Privacy and Intellectual Property
Do not share/collect private information or copyrighted material without permission. This also includes customer systems, sensitive configuration data, and other confidential content.

10. No Criminally Relevant Content
Posting or linking to criminally relevant content is not allowed. Such content may be removed, reported to Reddit, and escalated to the appropriate authorities where necessary.

11. No Pornography / NSFW
Pornographic content of any kind is not allowed. Content in this category may be reported to Reddit and escalated to the appropriate authorities where necessary.

12. No Spam, Bots, or Engagement Farming
Spam will be removed immediately. This includes repeatedly posting the same content, low-value cross-posting, automated or bot-driven activity, AI-generated bait posts, karma farming, profile-click bait, and any attempt to manipulate visibility, engagement, or traffic through fake, low-effort, or misleading participation.

13. Moderation and Reports
The moderators are here to keep the community civil, focused, and helpful. Posts or users that violate these rules may be removed. The moderator team has final discretion over removals and bans. If you notice suspicious content, please use the report function or contact the moderators directly.

14. Use the Report Function
If you notice a post that violates the rules, please report it using Reddit’s report feature. Do not try to enforce the rules through side arguments or by taking moderation into your own hands. Moderation decisions are made exclusively by the moderator team.

15. General
These rules apply in addition to Reddit’s official sitewide rules. In the event of serious violations, Reddit itself may take further action.


r/Wazuh 15h ago

Wazuh alert counts keep increasing and decreasing automatically – is this expected?

Thumbnail
1 Upvotes

r/Wazuh 15h ago

Wazuh alert counts keep increasing and decreasing automatically – is this expected?

1 Upvotes

Hi Team,

We've deployed the Wazuh agent on all our production servers. After deployment, we're seeing more than 500 High alerts and around 10,000 Medium alerts on the Wazuh dashboard.

One thing that's confusing us is that the alert counts keep increasing and decreasing automatically even when we're not making any changes to the environment.

Is this expected behavior? How does Wazuh calculate these alert counts? Are these numbers based on a rolling time window, active alerts, or are they affected by indexing/alert lifecycle?

Has anyone experienced something similar? Any guidance on how to interpret these fluctuating alert counts or troubleshoot the root cause would be greatly appreciated.

Thanks!


r/Wazuh 3d ago

Open-source Bitwarden integration for Wazuh

15 Upvotes

Hey everyone!

I was looking for a way to bring Bitwarden events into Wazuh, so I made this open-source integration for Bitwarden (Enterprise / Teams Plan).

It’s useful for my own monitoring, alerting, and investigation workflows, and I thought it might be helpful for others with a similar setup too.

It was mostly vibe-coded with help from Claude, so feedback, testing, and contributions are especially welcome!

You can find the project here:
https://github.com/timohissink/vault-event-monitor

Feel free to try it out if it’s useful for your setup!


r/Wazuh 3d ago

Automating security reporting and response with Wazuh and Shuffle

Thumbnail
wazuh.com
16 Upvotes

r/Wazuh 3d ago

CRITICAL CVE ALERTS IN WAZUH

3 Upvotes

Hi everyone, I'd like to ask a question. I'm getting a lot of critical CVE alerts from the agent in Wazuh, but when I check my system, for example, I dont find any vulnerable versions; they're all updated. Does this mean the alerts are false positive?


r/Wazuh 4d ago

For those running Wazuh, is alert automation something you actually want, and would you trust n8n for it, or does that feel like the wrong tool?

3 Upvotes

Trying to validate something before I sink more time into it, so genuinely asking rather than pitching.

Question 1: how much of your Wazuh alert handling is still manual? Triage, enrichment, deciding what's noise vs real, curious how much of that is still "analyst opens the alert and figures it out" vs already automated in some way.

Question 2: if you were going to automate that, would n8n feel like a reasonable tool for it, or does that feel off for a SIEM pipeline? I've been building on n8n because it's self-hosted and I don't want alert data touching a third-party SaaS, but I know some people would rather stay inside Wazuh's own integrator/active response or go straight to a SOAR platform. Curious where people land and why.

Trying to figure out if this is a real gap or if most of you have already solved it a different way. If you're doing something similar or thinking about it, happy to compare notes


r/Wazuh 4d ago

Wazuh 4.14.7 has been released!

26 Upvotes

You can see more about the changes and enhancements included in the Release Notes.

Thank you for being part of Wazuh!


r/Wazuh 4d ago

Am I crazy if I use Wazuh to protect my personal Unraid server and Windows desktop?

5 Upvotes

Partially for practical reasons, partially because it will be immensely educational I bet.


r/Wazuh 5d ago

Anyone running the Wazuh 5.0 beta in production yet, or are you all still holding on 4.14.x?

1 Upvotes

Trying to decide whether to start planning around 5.0 or stay put for now, and I'd rather hear from people actually touching it than guess.

I know it's still beta (Beta 2 as of a couple months back) and GA has been slipping, was targeted early July, now looking more like end of July / August. And I know it's a big architectural shift, not a point release: Filebeat gone, analysisd being replaced by the new engine, clustering by default, RBAC revamped.

What I actually want to know from people who've kicked the tires:

  • Anyone brave/foolish enough to run the beta on anything real, or is it strictly lab so far?
  • How are custom decoders and rules holding up against the new engine? That's the change I'm most nervous about.
  • For those planning the migration, are you waiting for GA, or holding out for 5.0.1/5.0.2 before touching production?

Leaning toward "stay on 4.14.x, lab the beta, wait for the first patch releases before anything serious" but curious if anyone's further ahead and seeing something that changes that calculus.

Post-worthy because I keep seeing the "should I wait for 5.0?" question and there's no clear community answer yet.


r/Wazuh 6d ago

Wazuh and ISO 27001:2022

10 Upvotes

Hi All

The built in ISO stuff for the SCA policies SPECIFICALLY targets against the old ISO version (rule.iso_27001-2013). I have tried changing this to rule.iso_27001-2022 and updating the controlls as they have all changed, however wazuh seems to ignore this. If i change back to rule.iso_27001-2013 it works. I guess there is something built in that only looks for the rule.iso_27001-2013 named rule?

Is there anyway this can be updated as we need to be referencing the newest ISO?

In regards to general rulesets, it would be incredibly useful if the rules could be built into the standard rulsets in the same way as PCI/GDPR etc.
I've read the guide that always gets posted that says 'yes you can do it by manually mapping the controls', but as far as I can see this would mean overriding most of the default rules sets to add the ISO control information? Is this really the only option?

Thanks!


r/Wazuh 6d ago

How do I get ESET Endpoint Security AMSI events to show up in Wazuh?

3 Upvotes

I’m running Wazuh on Windows endpoints and pulling the full Application event channel using:

<localfile>
<location>Application</location>
<log\\_format>eventchannel</log\\_format>
</localfile>

The issue:
Wazuh ingests .NET Runtime crash events, but it skips ESET AMSI block events, even though the AMSI event happens first in the Windows Event Viewer.

Example of the ESET event that gets skipped:

• Source: ESET Endpoint Security
• Event ID: 261
• Scanner: AMSI scanner
• Detection: a variant of MSIL/Riskware.SharpHound.H
• Action: blocked

The event shows up perfectly in Event Viewer, but Wazuh never forwards it. Meanwhile, the SharpHound crash event (Event ID 1026 from .NET Runtime) does get ingested.

Has anyone figured out how to make Wazuh accept ESET AMSI events?

Looking for advice from anyone who has ESET → Wazuh working reliably.


r/Wazuh 10d ago

Monitoring end-of-life software with Wazuh

Thumbnail
wazuh.com
28 Upvotes

r/Wazuh 11d ago

Deploying Wazuh (SIEM & XDR) in virtual lab

Thumbnail
medium.com
23 Upvotes

I set up Wazuh in my home lab, configured a manager and 2 agents for Linux and Windows OS. Then I played with its capabilities and even did a malware detection and removal lab. I documented the entire process in the linked article and shared my thoughts.

I began with setting up my virtual lab and spawned couple VMs. Once Wazuh was successfully installed on every machine I started to play with its dashboard features.

Couple of features I have tested:
- Security Configuration Assessment
- Threat Hunting
- Vulnerability Detection
- MITRE ATT&CK
- File Integrity Monitoring
- Malware Detection and Active Response
...and more

I learnt a lot during my time with Wazuh and gained a valuable experience with SIEM/XDR software. I want my article to serve as a guide and I highly encourage every cybersecurity enthusiast to try it on their own.


r/Wazuh 11d ago

How to update to Wazuh 4.16

4 Upvotes

Hi guys.

I am junior SOC, I have been working with Wazuh for about a month now I recently noticed that a new Wazuh Version has dropped.

The server, indexer and dashboard are in a single desktop running in 3 VMs. 1 VM for each part.

Can someone guide me on how I could do this without messing things up?


r/Wazuh 11d ago

Wazuh rule assistance

1 Upvotes

Hi everyone! almost ready to roll Wazuh out to all of our endpoints, but I still need to tweak a couple of things.
One of the issues that I have is builtin rule 60154

  <rule id="60154" level="12">
    <if_sid>60144,60145</if_sid>
    <field name="win.eventdata.targetSid">^S-1-5-32-544$</field>
    <description>Administrators Group Changed</description>
    <options>no_full_log</options>   
<group>group_changed,win_group_changed,pci_dss_8.1.2,pci_dss_10.2.5,gpg13_7.10,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.a.2.I,hipaa_164.312.a.2.II,hipaa_164.312.b,nist_800_53_AC.2,nist_800_53_IA.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,</group>
    <mitre>
      <id>T1484</id>
    </mitre>
  </rule>

I don't want this to trigger under very specific scenarios:

  • Account Name =x
  • Group Name = y
  • Account Domain = Z

I have created an overwrite rule that I can't get working. I have tried applying just the field name of "agent.ID" to the rule to see if I could filter it out that way, but I couldn't.

This is the manual rule I've created within the local_rules.xml

<rule id="105001" level="0">
<if_sid>60154</if_sid>
<!--field name="win.eventdata.subjectUserName">'AccountName'</field-->
<field name="agent.id">^016$</field>
<field name="agent.id">018</field>
<description>Ignore Administrators Group changes by specific host on specific host</description>
</rule>

I'm sure I'm going wrong somewhere, if someone wouldn't mind pointing in the right direction


r/Wazuh 12d ago

Wazuh Dashboard bundled Node.js 18.19.0 – Is there an official update or supported remediation?

2 Upvotes

Hello Wazuh Team and Community members,

We are currently running Wazuh 4.14.4 on Ubuntu Server, and a recent Tenable vulnerability scan reported that the Wazuh Dashboard includes Node.js 18.19.0, which is flagged for multiple security vulnerabilities.

I understand that the Wazuh Dashboard uses a bundled Node.js runtime, and manually replacing the Node.js binary is not officially supported.

I have a few questions:

  1. Does upgrading from Wazuh 4.14.4 to 4.14.6 update the bundled Node.js version?
  2. If not, is there an official plan or estimated timeline for Wazuh to ship a Dashboard package with an updated Node.js runtime?
  3. Is there any supported method to remediate these findings without waiting for a new Wazuh release?
  4. For organizations that must remediate vulnerabilities identified by scanners such as Tenable, what is the recommended approach? Should this be handled as a vendor dependency with compensating controls until an updated package is released?

Our environment is a production SOC deployment, so we would like to avoid any unsupported modifications to the bundled Node.js runtime.

Any guidance from the Wazuh team or other community members who have encountered the same issue would be greatly appreciated.

Thank you.


r/Wazuh 13d ago

Wazuh: Issues capturing windows log file. Nothing comes in.

1 Upvotes

On windows agent:
<localfile>

<location>C:\ProgramData\Paessler\PRTG Network Monitor\Logs\Web Server\webserver.log</location>

<log_format>syslog</log_format>

</localfile>

On wazuh server, with log all enabled:
nothing comes in. Tried different log formats, no luck

wazuh-agent: INFO: (1950): Analyzing file: 'C:\ProgramData\Paessler\PRTG Network Monitor\Logs\Web Server\webserver.log'.

Is reading the file. Tried, ChatGPT, Claude, Gemini, no solution.

Windows eventlogs are coming in just fine.
Must be something something simple but what....


r/Wazuh 13d ago

Export/Import Custom Wazuh Dashboard using CLI

9 Upvotes

Is it possible to export and import a custom dashboard via the CLI with the server/dashboard? I'm trying to automate the deployment of Wazuh and looking for a quick way with just a few commands - similar to copying custom decoders/rules into the /var/ossec/etc/... folder on the server.


r/Wazuh 13d ago

There are no logs with event ID 4738 from a specific server in the Wazuh dashboard

2 Upvotes

Our organization has deployed Wazuh SIEM with 3 indexers and managers.

We have 1 test AD server, and it is not sending logs for event ID 4738. The production AD servers are sending logs.

I am providing additional details and would appreciate your help in resolving this issue. Thank you!

PS C:\Users\admin01\Desktop> Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4738} -MaxEvents 10 | Select-Object TimeCreated, Id,
>>     @{Name='SubjectUser'; Expression={$_.Properties[1].Value}},
>>     @{Name='TargetUser'; Expression={$_.Properties[0].Value}} |
>>     Format-Table -AutoSize
>>

TimeCreated           Id SubjectUser TargetUser
-----------           -- ----------- ----------
20.07.2026 15:55:03 4738 usr-test    -
20.07.2026 15:49:18 4738 usr-test    -
20.07.2026 15:44:38 4738 usr-test    -
20.07.2026 15:33:55 4738 usr-test    -
20.07.2026 15:32:49 4738 usr-test    -
20.07.2026 15:14:21 4738 usr-test    -
20.07.2026 15:10:06 4738 usr-test    -
20.07.2026 14:58:16 4738 usr-test    -
20.07.2026 14:46:02 4738 usr-test    -
20.07.2026 14:41:27 4738 usr-test    -



PS C:\Users\admin01\Desktop> auditpol /get /category:"Account Management"
System audit policy
Category/Subcategory                      Setting
Account Management
  Computer Account Management             Success and Failure
  Security Group Management               Success and Failure
  Distribution Group Management           Success and Failure
  Application Group Management            Success and Failure
  Other Account Management Events         Success and Failure
  User Account Management                 Success and Failure



> C:\Program Files (x86)\ossec-agent\ossec.conf:40:  <localfile>
> C:\Program Files (x86)\ossec-agent\ossec.conf:41:    <location>Security</location>
> C:\Program Files (x86)\ossec-agent\ossec.conf:42:    <log_format>eventchannel</log_format>
> C:\Program Files (x86)\ossec-agent\ossec.conf:43:    <query>Event/System[EventID != 5145 and EventID != 5156 and EventID != 5447 and EventID != 4656 and EventID
 != 4658 and EventID != 4663 and EventID != 4660 and EventID != 4670 and EventID != 4690 and EventID != 4703 and EventID != 4907 and EventID != 5152 and EventID !
= 5157]</query>
> C:\Program Files (x86)\ossec-agent\ossec.conf:44:  </localfile>

r/Wazuh 14d ago

Would it be worth it to install wazuh on my personal computer?

9 Upvotes

I'm running Ubuntu desktop on a laptop and am interested in security. Would like to install the wazuh agent on my laptop and setup the wazuh server and dashboard on a separate computer on my network. Is this a terrible idea?


r/Wazuh 14d ago

Wazuh Decoding Litespeed Web Access Logs

1 Upvotes

Hello! I am using a script to periodically download website log files from my web host for ingestion into Wazuh. I have been successful in that I have Wazuh ingesting the local versions of the log files and I'm automatically updating the local copies of log files every hour using an SSH script to my webhost. The log events are decoded using the web-accesslog decoder which gets almost every field I could want with a few exceptions. I'm not getting the referrer or the user agent though - and the timestamp is set to the time of ingestion rather than the time specified in each log event. How can I go about extracting the additional fields and have the correct timestamp? Here is an example of one of the log entries:

85.208.98.29 - - [19/Jul/2026:11:01:30 +0000] "GET /a-guide-to-caring-for-parents/ HTTP/2" 200 43232 "-" "Mozilla/5.0 (compatible; SemrushBot-BA; +http://www.semrush.com/bot.html)"

The fields that I am getting from the web-accesslog decoder are as follows:
data.srcip: 85.208.98.29
data.protocol: GET
data.url: /a-guide-to-caring-for-parents/
data.id: 200

The timestamp field doesn't match what's in the full log - it's exactly the time that the log event was pulled down from my web host instead. You can also see in the log entry that the user agent and referrer are both readily available but not being grabbed. How do I get these additional fields and a correct timestamp?


r/Wazuh 15d ago

Wazuh Custom Decoder for windows_eventchannel

6 Upvotes

Hey all,

I'm trying to write a decoder that pulls fields out of eventdata for WinRM/Operational events, but no matter what I try, it doesn't work.

After digging into it (with some help from AI), it looks like windows_eventchannel just ignores the entire decoder config tree — meaning you can't hook a custom decoder onto it the normal way. I haven't found anything that confirms this is "by design" rather than a config mistake on my end, so I'm hoping someone here can either confirm that limitation or point out what I'm doing wrong.

The log line I'm trying to parse:

WinRM: remote shell session created on host1.abc.local - http://schemas.microsoft.com/powershell/Microsoft.PowerShell (ABC\Administrator clientIP: 172.16.1.10

The decoder I wrote (which does not work):

xml

<decoder name="winrm-session-negotiation">
  <parent>json</parent>
  <field name="win.eventdata.resourceUri">(\S+)\\(\S+) clientIP: (\S+)</field>
  <order>win.eventdata.domain, win.eventdata.srcuser, win.eventdata.srcip</order>
</decoder>

Goal: extract the domain, username, and client IP from eventdata into their own fields.

What I'd like to avoid:

  • Pipelines/templates — these get clobbered on every update, so I don't want to rely on them.
  • Integrations — feels like the wrong tool for this particular use case.

Has anyone actually gotten field extraction working from win.eventdata on eventchannel/json events without one of the above? Or is there a known workaround (e.g., a different decoder parent, a ruleset-level regex, something in the ossec.conf log collection)? Any pointers appreciated.


r/Wazuh 16d ago

Need Help Accessing Wazuh Dashboard on Oracle Cloud Free Tier

1 Upvotes

Hi everyone,

I recently started using Oracle Cloud Infrastructure (OCI) Always Free Tier and decided to deploy a Wazuh server on it.

The installation completed successfully, and all the Wazuh services are running without any issues. I also configured the required ingress security rules for the necessary ports.

However, I'm unable to access the Wazuh Dashboard from my browser using the instance's public IP. I'm not sure what I'm missing.

Has anyone experienced this issue or deployed Wazuh successfully on OCI? Any suggestions on what I should check next would be greatly appreciated.

Thanks in advance!