[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwc8byyx6jmwd":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":59,"categories":61,"source":63,"lang":66,"author":67,"audioState":70,"stats":71,"publishedAt":74,"renderer":75},"6abbc861ca21c797c7e9d7a8","github---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196","GitHub - xuxu298\u002Frule-doctor-lite: Free read-only check: which custom Wazuh rules never fire, and why (including rules Wazuh drops at load).","A free, read-only check for Wazuh 4.x.","news",[10,14,19,24,29,34,39,44,49,54],{"headline":11,"body":12,"imageUrl":13,"sourceImageUrl":13},"GitHub - xuxu298\u002Frule-doctor-lite: Free read-only check: which custom Wazuh…","A free, read-only check for Wazuh 4.x. It lists every custom rule that did not fire and tells you the most likely reason, including rules that Wazuh silently threw away while loading them.","https:\u002F\u002Fopengraph.githubassets.com\u002F86241ba100766067e4b5542c52a55d08c6e18cd6d824d0c07961ce18f431af8c\u002Fxuxu298\u002Frule-doctor-lite",{"headline":15,"body":16,"imageUrl":17,"images":18},"One Python 3 file, standard library only. It","One Python 3 file, standard library only. It reads files; it changes nothing on your manager and sends nothing anywhere. Or from PyPI (same file, with a rule-doctor-lite command): Manager in docker? Copy the four things it reads, then point --ossec-dir at the copy: The shadowed \u002F never-reaches-the-manager \u002F no-match split is Kislley Rodrigues's.","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F1.webp",{"local":17},{"headline":20,"body":21,"imageUrl":22,"images":23},"Every result is printed with the time window","Every result is printed with the time window it was measured over. A rule written for a quarterly event is not dead after a day.","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F2.webp",{"local":22},{"headline":25,"body":26,"imageUrl":27,"images":28},"What it reads by default (0.2.1): the current","What it reads by default (0.2.1): the current logs\u002Falerts\u002Falerts.json plus the rotated alert files of the last 7 days (logs\u002Falerts\u002F\u003Cyear>\u002F\u003CMon>\u002Fossec-alerts-\u003Cdd>.json, plain or .gz, as Wazuh writes them); change the window with --days N. From ossec.log it takes the 7617\u002F7619 warnings of the latest rule load only (the block before the last Total rules enabled), so a rule you already fixed is not reported from an older load, and lines from wazuh-analysisd -t are ignored.","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F3.webp",{"local":27},{"headline":30,"body":31,"imageUrl":32,"images":33},"wazuh\u002Fwazuh-manager:4.14.7, 27\u002F09\u002F2026. Two identical custom rules on if_sid","wazuh\u002Fwazuh-manager:4.14.7, 27\u002F09\u002F2026. Two identical custom rules on if_sid 5715, one in 0094-test.xml (sorts before the stock 0095-sshd_rules.xml), one in 0500-ok.xml. A real sshd \"Accepted password\" event fired 100081 from 0500-ok.xml; 100080 in 0094-test.xml never fired. Rule Doctor Lite reported: and, with ossec.log withheld, the same verdict from the load order alone: Chains (0.2.0, 28\u002F09\u002F2026)","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F4.webp",{"local":32},{"headline":35,"body":36,"imageUrl":37,"images":38},"Same image. Anchor 910010 on if_sid 5715 in","Same image. Anchor 910010 on if_sid 5715 in 0094-early.xml, child 910012 on if_sid 910010 and grandchild 910013 on if_sid 910012 in 0500-chain.xml. wazuh-analysisd -t exited 0; ossec.log had 7617 + 7619 for all three, each naming the rule above it as the missing parent. Lite, with ossec.log withheld:","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F5.webp",{"local":37},{"headline":40,"body":41,"imageUrl":42,"images":43},"The prediction matters because ossec.log can miss warnings","The prediction matters because ossec.log can miss warnings: analysisd buffers the warnings of each rules file in a list capped at 50 (ERRORLIST_MAXSIZE) and flushes it after the file, so a file that produces more than 50 warnings loses the oldest ones (src\u002Fanalysisd\u002Fanalysisd.c L708-750 on v4.14.7). tests\u002Frun.sh runs the fixture checks without docker.","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F6.webp",{"local":42},{"headline":45,"body":46,"imageUrl":47,"images":48},"Wazuh 4.x rule syntax. Only if_sid parents are","Wazuh 4.x rule syntax. Only if_sid parents are read; if_group, if_matched_sid and if_matched_group are not followed yet. NEVER-REACHES-MANAGER only sees loss that raised rule 203 or 204 (see the table above). SHADOW-CANDIDATE needs a replay to confirm or clear. Lite does not replay. \"Never fired\" means never fired in the alerts it read (7 days by default). Older alerts need --days or --alerts.","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F7.webp",{"local":47},{"headline":50,"body":51,"imageUrl":52,"images":53},"Step-by-step notes for what Lite points at, each","Step-by-step notes for what Lite points at, each with a one-minute check you can run yourself (measured on Wazuh 4.14.7): Full version and done-for-you fixes","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F8.webp",{"local":52},{"headline":55,"body":56,"imageUrl":57,"images":58},"ATK Rule Doctor (USD 490 per cluster per","ATK Rule Doctor (USD 490 per cluster per year) replays the real events behind every SHADOW-CANDIDATE through a throwaway manager of your version to confirm or clear it, and fixes alerts the indexer rejects with mapper_parsing_exception: https:\u002F\u002Fvct.atkvn.com\u002Frule-doctor.html","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---xuxu298rule-doctor-lite-free-read-only-check-which-587c8196\u002F9.webp",{"local":57},[60],"dev",[62],"Technology",{"name":64,"url":65},"Show HN","https:\u002F\u002Fgithub.com\u002Fxuxu298\u002Frule-doctor-lite","en",{"handle":68,"displayName":69},"spots","Spots","queued",{"views":72,"likes":73,"saves":73,"shares":73,"completions":73,"opens":73,"skips":73,"depthSum":73},3,0,"2026-09-29T14:17:05.284Z","local"]