Closed sushihash closed 2 months ago
Hi @sushihash ! How are you?
IndexerConnector initialized successfully for index:
Do you see this log? in the ossec.log?
Hi, Yes i have it,
2024/07/31 10:36:41 indexer-connector: INFO: IndexerConnector initialized successfully for index: wazuh-states-vulnerabilities-wazuh.
Hi @sushihash! Great to hear that we're indexing the vulnerabilities.
Is the new CVE
found either during the first scan (when an agent connects with the manager and starts the scan) or when you install a vulnerable package after that?
During the first scan, no events are generated. Events are only generated after the initial scan when you install a vulnerable package or when a vulnerability is resolved by installing the package or applying a fix.
I look forward to your response. Have a nice day!
Hi @GabrielEValenzuela,
they were detecting when i added the agent to the manager or when i started the agent
No event has been recorded in this case ?
It is possible to create a feature for that ? every scan creates event ?
Hi @sushihash! I hope you're doing well!
When you add an agent for the first time, it’s treated as the initial scan, so no alert will show up in the event tab. I’ll look into your feature request and get back to you with updates as soon as I can. Thanks for your time! Nice day! 😊
Hi @sushihash! How are you?
I wanted to let you know that this feature request will be implemented in the upcoming version 5.0.0
.
Nice day!
Inquire answered, inactive thread. Please re open-it if necessary
|Wazuh version|Component|Install type|Install method|Platform| |4.8.1|Wazuh Dashboard / Manager|package | linux|
Hi everyone,
I'm here to talk about vulnerability detection.
I have one agent, and initially, the vulnerability detection works. However, when a new CVE is detected, no event appears in the event category.
some pictures and files :