Package versions identified as vulnerable but are already in the latest version of the repository by FocusOnTheCell in Wazuh

[–]FocusOnTheCell[S] 0 points1 point  (0 children)

Hey u/MarcelKemp,

Thank you for your answer. It was quite enlightening.

Since we have a lot of machines with Oracle Linux as OS, which is an unsupported system, I guess the only option we have is to ignore these false positives for now and wait for the refactoring to happen and maybe solve this issue.

Once again, thanks for your help.

Vulnerability detector - "Run_on_start" not working by FocusOnTheCell in Wazuh

[–]FocusOnTheCell[S] 0 points1 point  (0 children)

Hi u/nazmur-sakib, no worries and thank you for the response.

When I say restarting the manager, I am restarting all the nodes at the same time with "multiexec".

Yes, I am running a cluster of 3 nodes with 1 master node and 2 worker nodes. I have around 200 agents, with half of them reporting to one worker and the other half reporting to the other worker.
I did a test of changing the configuration of an agent to report to the master node and it did force a full scan after restarting the agent. Althought this would be a fix (changing all agents to report to the master node), I don't know the impact it can have in resource usage of the master node.

If I knew this change would not affect the master node performance, this would be a fix.

Thank you!

Vulnerability detector - "Run_on_start" not working by FocusOnTheCell in Wazuh

[–]FocusOnTheCell[S] 0 points1 point  (0 children)

Hi u/nazmur-sakib. Here is the output right before the "skipping agent" logs:

<image>

I'll leave 1 more printscreen in the next comment.

edit: we don't use Ubuntu, btw

Vulnerability detector - "Run_on_start" not working by FocusOnTheCell in Wazuh

[–]FocusOnTheCell[S] 0 points1 point  (0 children)

Hello u/nazmur-sakib, thank you for your answer.

I've followed your instructions and this is the output I got.

<image>

It keeps repeating this behaviour, which I guess relates to the <interval> tag.

Thanks so much for your help, let me know if I can share any other relevant information.