Management / Configuration
Configuration List the current Wazuh manager configuration
Global
JSON output {{mcc.managerConfiguration.global.jsonout_output}}
Log alert level {{mcc.managerConfiguration.alerts.log_alert_level}}
Cluster
Name {{mcc.managerConfiguration.cluster.name}}
Node type {{mcc.managerConfiguration.cluster.node_type}}
Syscheck
Frequency {{mcc.managerConfiguration.syscheck.frequency}}
Alert new files {{mcc.managerConfiguration.syscheck.alert_new_files}}
Rootcheck
Frequency {{mcc.managerConfiguration.rootcheck.frequency}}
Skip NFS {{mcc.managerConfiguration.rootcheck.skip_nfs}}
Syscollector
Disabled {{mcc.managerConfiguration.syscollector.disabled}}
Scan on start {{mcc.managerConfiguration.syscollector.scan_on_start}}
Logcollector
Logcollector settings
E-mail alerts
Email to {{mcc.managerConfiguration.email_alerts.email_to}}
Alert level {{mcc.managerConfiguration.email_alerts.alert_level}}
Auth
Purge {{mcc.managerConfiguration.auth.purge}}
Force insert {{mcc.managerConfiguration.auth.force_insert}}
Ruleset
Ruleset settings
Command
Command settings
Active response
Active response settings
Remote
Agents events listening settings
Global JSON
{{mcc.XMLContent}}
JSON output {{mcc.managerConfiguration.global.jsonout_output}}
Log all {{mcc.managerConfiguration.global.logall}}
Log all in JSON {{mcc.managerConfiguration.global.logall_json}}
White list {{mcc.managerConfiguration.global.white_list.length <=5 ? mcc.managerConfiguration.global.white_list : mcc.managerConfiguration.global.white_list.length}}
Stats {{mcc.managerConfiguration.global.stats}}
Host information {{mcc.managerConfiguration.global.host_infomation}}
Log alert level {{mcc.managerConfiguration.alerts.log_alert_level}}
E-mail notifications {{mcc.managerConfiguration.global.email_notification}}
E-mail alert level {{ mcc.managerConfiguration.alerts.email_alert_level }}
E-mail to {{mcc.managerConfiguration.global.email_to}}
E-mail from {{mcc.managerConfiguration.global.email_from}}
SMTP server {{mcc.managerConfiguration.global.smtp_server}}
Max email per hour {{mcc.managerConfiguration.global.email_maxperhour}}
E-mail IDS name {{mcc.managerConfiguration.global.email_idsname}}
Cluster JSON
{{mcc.XMLContent}}
Disabled {{mcc.managerConfiguration.cluster.disabled}}
Hidden {{mcc.managerConfiguration.cluster.hidden}}
Name {{mcc.managerConfiguration.cluster.name}}
Interval {{mcc.managerConfiguration.cluster.interval}}
Node name {{mcc.managerConfiguration.cluster.node_name}}
Node type {{mcc.managerConfiguration.cluster.node_type}}
Port {{mcc.managerConfiguration.cluster.port}}
Bind address {{mcc.managerConfiguration.cluster.bind_addr}}
Nodes {{mcc.managerConfiguration.cluster.nodes}}
Syscheck JSON
{{mcc.XMLContent}}
Disabled {{mcc.managerConfiguration.syscheck.disabled}}
Frequency {{mcc.managerConfiguration.syscheck.frequency}}
Scan time {{mcc.managerConfiguration.syscheck.scan_time}}
Scan day {{mcc.managerConfiguration.syscheck.scan_day}}
Auto ignore {{mcc.managerConfiguration.syscheck.auto_ignore}}
Alert new files {{mcc.managerConfiguration.syscheck.alert_new_files}}
Scan on start {{mcc.managerConfiguration.syscheck.scan_on_start}}
No diff {{mcc.managerConfiguration.syscheck.nodiff}}
Skip NFS {{mcc.managerConfiguration.syscheck.skip_nfs}}
Monitoring directories
Path {{item.path}}
Realtime {{item.realtime}}
Report changes {{item.report_changes}}
Check all {{item.check_all}}
Check sum {{item.check_sum}}
Check SHA1sum {{item.check_sha1sum}}
Check MD5sum {{item.check_md5sum}}
Check size {{item.check_size}}
Check owner {{item.check_owner}}
Check group {{item.check_group}}
Check permissions {{item.check_perm}}
Check modification time {{item.check_mtime}}
Check inode {{item.check_inode}}
Restrict {{item.restrict}}
Rootcheck JSON
{{mcc.XMLContent}}
Disabled {{mcc.managerConfiguration.rootcheck.disabled}}
Rootkit files {{mcc.managerConfiguration.rootcheck.rootkit_files}}
Rootkit trojans {{mcc.managerConfiguration.rootcheck.rootkit_trojans}}
Base directory {{mcc.managerConfiguration.rootcheck.base_directory}}
Scan all {{mcc.managerConfiguration.rootcheck.scanall}}
Frequency {{mcc.managerConfiguration.rootcheck.frequency}}
Skip NFS {{mcc.managerConfiguration.rootcheck.skip_nfs}}
System audit files
File {{item}}
Ruleset JSON
{{mcc.XMLContent}}
Decoder directories
Path {{item}}
Decoder excludes
Path {{item}}
Decoder files
Path {{item}}
Rules directories
Path {{item}}
Rules files
Path {{item}}
Rule excludes
Path {{item}}
Path {{mcc.managerConfiguration.ruleset.rule_exclude}}
CDB Lists
Path {{item}}
Path {{mcc.managerConfiguration.ruleset.list}}
Syscollector JSON
{{mcc.XMLContent}}
Disabled {{mcc.managerConfiguration.syscollector.disabled}}
Interval {{mcc.managerConfiguration.syscollector.interval}}
Scan on start {{mcc.managerConfiguration.syscollector.scan_on_start}}
Hardware {{mcc.managerConfiguration.syscollector.hardware}}
OS {{mcc.managerConfiguration.syscollector.os}}
Packages {{mcc.managerConfiguration.syscollector.packages}}
Logcollector JSON
{{mcc.XMLContent}}
Location {{item.location}}
Command {{item.command}}
Log format {{item.log_format}}
Frequency {{item.frequency}}
Alias {{item.alias}}
Check diff {{item.check_diff}}
E-mail alerts JSON
{{mcc.XMLContent}}
Email to {{mcc.managerConfiguration.email_alerts.email_to}}
Alert level {{mcc.managerConfiguration.email_alerts.alert_level}}
Group {{mcc.managerConfiguration.email_alerts.group}}
Event location {{mcc.managerConfiguration.email_alerts.event_location}}
Format {{mcc.managerConfiguration.email_alerts.format}}
Rule ID {{mcc.managerConfiguration.email_alerts.rule_id}}
Do not delay {{mcc.managerConfiguration.email_alerts.do_not_delay}}
Do not group {{mcc.managerConfiguration.email_alerts.do_not_group}}
Auth JSON
{{mcc.XMLContent}}
Disabled {{mcc.managerConfiguration.auth.disabled}}
Purge {{mcc.managerConfiguration.auth.purge}}
Force insert {{mcc.managerConfiguration.auth.force_insert}}
SSL verify host {{mcc.managerConfiguration.auth.ssl_verify_host}}
Limit max agents {{mcc.managerConfiguration.auth.limit_maxagents}}
Force time {{mcc.managerConfiguration.auth.force_time}}
SSL manager key {{mcc.managerConfiguration.auth.ssl_manager_key}}
SSL manager cert {{mcc.managerConfiguration.auth.ssl_manager_cert}}
Use source IP {{mcc.managerConfiguration.auth.use_source_ip}}
Use password {{mcc.managerConfiguration.auth.use_password}}
Port {{mcc.managerConfiguration.auth.port}}
SSL auto negotiate {{mcc.managerConfiguration.auth.ssl_auto_negotiate}}
Ciphers {{mcc.managerConfiguration.auth.ciphers}}
Command JSON
{{mcc.XMLContent}}
Name {{item.name}}
Expect {{item.expect}}
Executable {{item.executable}}
Timeout allowed {{item.timeout_allowed}}
Active response JSON
{{mcc.XMLContent}}
Command {{item.command}}
Location {{item.location}}
Agent ID(s) {{item.agent_id}}
Level {{item.level}}
Timeout {{item.timeout}}
Rule ID {{item.rules_id}}
{{item.rule.file}} {{item.rule.description}}
Rules IDs {{item.rules_id}}
{{rule.file}} {{rule.description}}
Rules group {{item.rules_group}}
Repeated offenders {{item.repeated_offenders}}
Remote JSON
{{mcc.XMLContent}}
Connection {{item.connection}}
Port {{item.port}}
Protocol {{item.protocol}}