You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Wazuh version: 4.4.1 - 4.7.0
Custom SCA template: registry, file and command checks on Windows agents
Schedule: daily
The problem arises as more than hundred agents consistently report failed checks, specifically in the command checks, while other types of checks, such as file or registry checks, consistently succeed. And random agents report failure.
For instance, commands within the custom SCA template may run successfully on a agent on one day, report a failed status the next day, and then return to success the following day. The failures are sporadic, occurring at a rate of 1-2 failed command checks per week per agent.
In an attempt to troubleshoot, we scheduled the exact same command to run every 5 minutes on one system. However, this execution consistently produces the expected output without any failures. This raises suspicions that the issue might reside on the Wazuh server side rather than with the command or agent itself.
Wazuh version: 4.4.1 - 4.7.0
Custom SCA template: registry, file and command checks on Windows agents
Schedule: daily
The problem arises as more than hundred agents consistently report failed checks, specifically in the command checks, while other types of checks, such as file or registry checks, consistently succeed. And random agents report failure.
For instance, commands within the custom SCA template may run successfully on a agent on one day, report a failed status the next day, and then return to success the following day. The failures are sporadic, occurring at a rate of 1-2 failed command checks per week per agent.
In an attempt to troubleshoot, we scheduled the exact same command to run every 5 minutes on one system. However, this execution consistently produces the expected output without any failures. This raises suspicions that the issue might reside on the Wazuh server side rather than with the command or agent itself.
ossec.conf:
internal_options.conf:
local_internal_options.conf:
shared/agent.conf:
Agent debug log (SCA check c:sc query service -> r:RUNNING):
SCA check result: PASSED
SCA check result: FAILED
The text was updated successfully, but these errors were encountered: