Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does not show events in the 'Docker Listener', 'VirusTotal' and 'System Auditing' Modules when they are enabled #5749

Closed
damarisg opened this issue Aug 1, 2023 · 1 comment
Labels
level/task Task issue qa/known Issues that are already known by the QA team type/bug Bug issue

Comments

@damarisg
Copy link
Member

damarisg commented Aug 1, 2023

Wazuh Elastic Rev Security
4.5.0 7.x 4xxx Basic, ODFE, Xpack
Browser
Firefox 115.0.2 (64-bit)

Description

We detected that when we activate some modules they don't show alerts.

In this case we are working in the 4.5.0 Demo environment that has 2 APIs (env-1 and env-2).

Note: You need to have a Demo with 2 environments.

Steps to reproduce

  1. On Env 2, go to Wazuh > Settings > Modules
  2. Go to the Threat Detection and Response section > Activate each option (VirusTotal, Docker listener, Osquery).
  3. Go to the Auditing and Policy Monitoring section > Check that System auditing is activated.

Expected Result

  1. It shows alerts for each module

Actual Result

  1. The modules show events except Docker Listener, VirusTotal, and System Auditing when they are activated.

Screenshots

Details of modules activated

modulenv2

Details of modules without alerts

env2Docker

env2System

env2Virustotal

@davidjiglesias
Copy link
Member

This is expected based on comment from @teddytpc1 here wazuh/wazuh#18065 (comment)

@davidjiglesias davidjiglesias closed this as not planned Won't fix, can't repro, duplicate, stale Aug 2, 2023
@davidjiglesias davidjiglesias added the qa/known Issues that are already known by the QA team label Aug 30, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
level/task Task issue qa/known Issues that are already known by the QA team type/bug Bug issue
Projects
None yet
Development

No branches or pull requests

2 participants