-
Notifications
You must be signed in to change notification settings - Fork 2
Roadmap
Chris Bassey edited this page Aug 29, 2026
·
3 revisions
Version 2 replaces the legacy single heavy index with plugin-owned numeric
generations behind read/write aliases. Rollover covers operational alerts,
activity, cases, and evidence relationships. Retirement and purge remain
separate, reviewed actions; native wazuh-alerts-* stays read-only.
The release also includes resumable legacy migration, bounded evidence snapshots, case and evidence rollover, archived-case reopen, hold-aware archive purge, exact aggregation-based reports, durable automation queues, Boolean entity triggers, and explicit graph truncation at the safety ceiling.
- Add asynchronous, saved report jobs and immutable signed exports for compliance users who need a frozen record rather than the live/unarchived operational view.
- Add graph expansion and server-side neighborhood queries for investigations larger than the bounded interactive graph.
- Add lifecycle scheduling windows, dry-run diffs, notification hooks, and backup attestations before purge.
- Add configurable SLA policies with versioned policy history. Version 2 uses the documented fixed policy and exact write-time reporting fields.
- Add case templates, evidence export packages, richer collaboration, and external ticketing/webhook actions with encrypted secret storage.
- Continue validating every release against the actual Wazuh 4.12, 4.13, and 4.14 dashboard source trees and browser smoke suites.
Wazuh Alert Manager — unofficial plugin for Wazuh 4.12–4.14. Not affiliated with or endorsed by Wazuh Inc.