Skip to content
Discussion options

You must be logged in to vote

I've tested sysmon+winlogbeat and it works fine for me.

Is it possible that Wazuh is generating an Active Response against your endpoint and blocking it in the firewall?

Have you checked your Wazuh logs for any clues?

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
3 replies
@jot49
Comment options

@Director-Fusion-zz
Comment options

@dougburks
Comment options

Answer selected by dougburks
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants