+ + +
+
+

System Health Overview

+

Real-time health status and diagnostics for your Wazuh cluster deployment

+
+ +
+
+ Overall Status + OFFLINE +
+
+ Active Issues + ? +
+
+ Services Online + ? of 5 +
+
+ Cluster Status + UNKNOWN +
+
+ +
+ +
+ +
+
+
+ + Detected Issues +
+
+
+
+ Run a system health check to inspect active issues. +
+
+
+ + +
+
+
+ + System Check Logs +
+ +
+
Click "Run Health Check" to start system diagnostic checks...
+
+ + +
+
+
+ + Troubleshooting Wizard +
+
+
+
+
+ Welcome to the Wazuh Troubleshooting Wizard. Select a detected issue card above to start manual troubleshooting. +
+
+
+
+
+
+ + +
+
+
+
+ + Services Status +
+
+
+
+ wazuh-indexer + Unknown +
+
+ wazuh-manager + Unknown +
+
+ wazuh-dashboard + Unknown +
+
+ API Status + Unknown +
+
+ Filebeat Status + Unknown +
+
+
+ +
+
+
+ + Cluster Information +
+
+ + + + + + + + + + + + + + + + + +
Cluster Status-
Number of Nodes-
Active Shards-
Unassigned Shards-
+
+ +
+
+
+ + Memory Usage +
+
+
+ + + + + + + + + + + + + +
Total Memory-
Used Memory-
Free Memory-
+
+
+ Utilization + 0% +
+
+
+
+
+
+
+
+ + +
+
+
+ + Quick System Actions +
+
+
+ + + + +
+
+
+
+ + +
+
+

Troubleshooting Library

+

Select a known Wazuh scenario to launch interactive diagnostic workflows

+
+ +
+
+
+ +
+
Wazuh Dashboard Not Ready Yet
+
Troubleshoot opensearch host configurations, indexer status, cert credentials, and secure permissions.
+ +
+ +
+
+ +
+
Alerts Not Showing on Dashboard
+
For when no alerts are showing at all, or today's wazuh-alerts-* index isn't being created - walks the full pipeline from the Wazuh Manager through Filebeat to the Indexer.
+ +
+ +
+
+ +
+
Alerts Not Indexing
+
Diagnose active write blocks, check disk space watermark settings, and inspect cluster shard state.
+ +
+ +
+
+ +
+
Could Not Connect to API
+
Resolve credentials mismatch, incorrect API username/password keys in configuration, and listener errors.
+ +
+ +
+
+ +
+
Application Not Found
+
Diagnose dashboard plugin installation failures and path mismatches inside dashboard config modules.
+ +
+ +
+
+ +
+
Cluster Health Issues
+
Troubleshoot multi-node setups, indexer cluster health status red/yellow, and unassigned replica shards.
+ +
+ +
+
+ +
+
Filebeat Not Working
+
Having an issue in `filebeat test output` - diagnose service status, unsupported Filebeat versions, and TLS/certificate errors.
+ +
+ +
+
+ +
+
Filebeat Mapping Issue
+
Diagnose field-mapping/index-template conflicts - illegal_argument_exception, mapper_parsing_exception, or dashboard "N of M shards failed" errors.
+ +
+
+ + +
+
+
+ + Library Diagnostics Wizard +
+
+ +
+
+
+
+
+
+ Welcome to the Wazuh Library Diagnostics Wizard. Select a known Wazuh scenario card above to start interactive diagnostics, or ask any troubleshooting question below for AI-powered assistance. +
+
+
+ +
+ + +
+
+
+
+ + +
+
+

Operations Reporting Center

+

Generate environment health reports, deployment insights, and Wazuh operational intelligence metrics

+
+ + +
+
+ +
+
+ +
+
Agent Health Report
+
Review connected fleet status, disconnected agents, communication issues, and activity summaries.
+ +
+ + +
+
+ +
+
Dashboard Health Report
+
Analyze availability, uptime, connection performance, API endpoints, and configuration errors.
+ +
+ + +
+
+ +
+
Indexing & Data Flow Report
+
Track alert ingestion trends, indexing pipelines, document statistics, and pipeline write issues.
+ +
+ + +
+
+ +
+
Cluster Health Report
+
Monitor multi-node indexing state, active shards, unassigned shards, and host resource utilization.
+ +
+ + +
+
+ +
+
Environment Assessment Report
+
Generate a complete platform evaluation with risk scoring, observations, and recommendations.
+ +
+ + +
+
+ +
+
Security Events Report
+
Analyze historical alert timeline trends, top triggered rules, severity distribution, and source IPs.
+ +
+ + +
+
+ +
+
Custom Report Builder
+
Tailor a report by selecting specific modules and exporting them to HTML or PDF.
+ +
+
+ + + +
+ + + +
+ + + +
+ +
+ +
+ + + + + +
+

Wazuh Copilot

+

AI-powered Wazuh expert — investigates autonomously, proposes every state-changing fix before running it

+
+
+ +
+ +
+ Checking... +
+ + + + + + + +
+ +
+
+ + +
+
+ +
+ +
+ +
+ + + +
+
+ + + + +
+ + + +
+
+

Settings

+

Configure portal connections, refresh rates, and environment details

+
+ +
+ +
+

Connection Settings

+ +
+ + + The base URL of the FastAPI backend troubleshooter server. +
+ +
+
+
Auto Health Check
+
Automatically run health checks when the page loads.
+
+ +
+ +
+ + + Periodically check system health in the background. +
+ + +
+ + +
+

About Portal

+
+
+ Version + 1.0.0 +
+
+ Backend Framework + FastAPI + Python +
+
+ Frontend Stack + Vanilla JS + CSS +
+
+ Security Analytics + Plotly Dash (Port 7200) +
+
+

+ Wazuh Troubleshooting Portal provides guided diagnostics, interactive troubleshooting wizard scripts, and automated remediation systems for Wazuh SIEM environments. +

+
+
+
+ +