Wazuh 4.14.7 silently drops events in two of three overload scenarios
Security researchers tested Wazuh 4.14.7 under heavy log ingestion load, simulating one agent reading logs from 1,600 firewalls, and found three distinct ways events can be lost. Only one scenario — when the agent's client buffer is enabled and overwhelmed — triggers an alert, specifically rule 203, while the other two fail silently. Disabling the client buffer caused over 840,000 log lines to vanish with only a single warning written to the agent's local ossec.log file. A third scenario involving an overloaded manager dropped tens of thousands of events, leaving traces only in the manager's ossec.log and an analysisd state file. Researchers warn that if those log files are not actively monitored, busy agents or overloaded managers can lose data with no dashboard alert or rule firing.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in