viewing the alert that triggered by the wazuh 6 months ago #17311
Replies: 10 comments 10 replies
-
Hi @mostwanted5, Yes, you can use the old alert files to re-inject alerts into your Wazuh dashboard for further analysis. Here's a link to an old blog post that includes detailed instructions on how to do so: Recover your data using Wazuh alerts backups. This blog post includes a script named Configure Filebeat to read the recovery file by editing
Restart Filebeat so changes can take effect, and run the script to start writing the recovery file and re-indexing your alerts. Let us know if you have any further questions. |
Beta Was this translation helpful? Give feedback.
-
Hii, |
Beta Was this translation helpful? Give feedback.
-
Hello, |
Beta Was this translation helpful? Give feedback.
-
or do i need to create a seperate wazuh for viewing this? |
Beta Was this translation helpful? Give feedback.
-
Hi @mostwanted5, No, there's no need to create a separate Wazuh instance to re-index the old alerts. Let's troubleshoot the issue:
The Make sure you have the same folder structure as well as the expected file names. If the recovery script can't find the old alert file, you'll see a message similar to this one in the
|
Beta Was this translation helpful? Give feedback.
-
manifest.yml module_version: 0.1 var:
input: config/alerts.yml ingest_pipeline: ingest/pipeline.json |
Beta Was this translation helpful? Give feedback.
-
recovery.log file 2023-06-01 15:08:55 wazuh-reinjection: Reading file: /var/ossec/logs/alerts/2023/Apr/ossec-alerts-10.json.gz |
Beta Was this translation helpful? Give feedback.
-
Try running the recovery script and
You should get a similar output:
Also, verify if all services are up and running:
|
Beta Was this translation helpful? Give feedback.
-
Hi @mostwanted5, The Wazuh app includes a default filter that filters the alerts by manager name or cluster name. If the alerts were generated in another manager, if the name of the manager or the Wazuh cluster settings have recently changed, this filter may be preventing you from seeing the alerts. To overcome this limitation, search for your alerts in the Discovery section. Go to the upper-left menu ☰ and select Discovery. You can also verify if the index wazuh-alerts-4.x-2023.04.10 is created under ☰ > Dev Tools.
Let us know if this solves your issue. |
Beta Was this translation helpful? Give feedback.
-
You're welcome! I'm very glad that everything is now working as expected. Feel free to ask more questions anytime. |
Beta Was this translation helpful? Give feedback.
-
is it possible to view and analyse the alerts in wazuh dashboard when i re upload a log file like alert.json or archive.json that is deleted long ago from wazuh.
Beta Was this translation helpful? Give feedback.
All reactions