Wazuh-dbd does not support custom types in rules #14081
Labels
level/task
module/dbd
wazuh-dbd
reporter/community
team/core
type/bug/regression
Breaks functionality known to work in previous releases
DATABASE=<mysql/pgsql>
Description
Since Wazuh v4.1, it is possible to specify different types of regex (
PCRE2
,OSRegex
orOSMatch
) in rules and decoders (#6480).On the other hand, there is the possibility of building wazuh with support for inserting alerts into a sql-like database.
This is done through the daemon
wazuh-dbd
(ossec-dbd
). At the moment, this daemon does not start if the rules or decoders have specified a regex type that is not the default one. The latest versions of wazuh use this functionality in the default rules, which causes the daemon to not start.Use case
The Wazuh manager is built and configured to send alerts to a database.
Steps to reproduce (using MySQL)
ossec.conf
fileActual result
Expected result
Starts normally and inserts alerts into the database
The text was updated successfully, but these errors were encountered: