[v5.0.0]
Added
| Issue | Comment |
|---|---|
| #7464 | Added sample data generators for agents monitoring and server statistics |
| #7680 | Added prompts to some views related to problems with server API and alerts index pattern |
| #7741 | Added "Not applicable" status to SCA CheckResult enum with corresponding color mapping (#B9A888) and sample data support |
| #7920 | Added default wazuh-events-v5* index pattern
|
| #8002 | Added SSL certificate support for Wazuh API connections, allowing the dashboard to use client certificates and CA certificate validation when connecting to Wazuh Manager APIs configured with custom SSL certificates. The verify_ca value is automatically calculated based on whether certificate paths (key, cert, ca) are configured
|
| #8002 | Added "Verify CA" column in the API Connections table to display whether CA certificate verification is enabled for each API host. The value is automatically determined based on certificate configuration |
| wazuh-dashboard#1086 | Added server-api:run_as health check to warn when allow_run_as is disabled for configured API hosts
|
| #8203 | Added Indexer management Settings |
| #8229 | Added wazuh-findings-v5* index patterns
|
| #8263 | Added policy.name, policy.description, policy.file and event.outcome columns to the Configuration Assessment Findings table
|
| #8246 | Added wazuh-state-fim* index pattern
|
| #8272 | Added Indexer configuration UI section in Server Management Settings |
| #8275 | Added CMMC regulatory compliance module |
| #8276 | Added FedRAMP regulatory compliance module |
| #8277 | Added ISO 27001 regulatory compliance module |
| #8278 | Added NIS2 regulatory compliance module |
| #8279 | Added NIST 800-171 regulatory compliance module |
| wazuh-dashboard-security-analytics#213 | Added wazuh-threatintel-enrichments* index patterns
|
| #8391 | Added Refresh button to the suggested filters search bar |
| #8401 | Added ability to generate PDF report in Vulnerabilities dashboard |
| #8428 | Added wazuh-metrics-normalization* index pattern
|
| #8428 | Added Normalization tab and dashboard in Server Management > Statistics
|
| #8556 | Added Case Management tab to Findings document details flyout |
| #8557 | Created case management app |
| #8609 | Added visualizations to Vulnerability Detection > Inventory |
| #8595 | Added Incident Response app |
| wazuh-dashboard-security-analytics#342 | Added wazuh.disabledSettings configuration to hide specific settings in the Indexer Settings UI
|
| #8718 | Expanded the case management form with title, description, severity, priority and TLP fields, comments that can be added or edited individually, and a confirmation dialog before discarding unsaved changes |
| #8768 | Added queue usage in bytes and agent cache visualizations to Server Management > Statistics, and relabeled the Comms "Queue usage" Y-axis to Bytes
|
| #8789 | Added Wazuh AI Assistant plugin |
| #8846 | Added the wazuh-agent-stats index pattern and a sample data generator for the agent statistics index
|
| #8856 | Added a success notification when an agent upgrade completes in Agent management > Summary, based on polling the agent's reported version instead of the removed upgrade task tracking |
| #8961 | Added the dispatched and failed task counters to the agent Stats tab
|
| #9067 | Added a wazuh_ai_assistant.settingsReadOnly configuration key to lock AI Assistant settings and providers to their current configuration, rejecting write requests regardless of the caller's own indexer permissions
|
| #9020 | Added "Scan vulnerabilities" action to request an on-demand vulnerability scan for one or multiple agents from the agents table |
| #9061 | Added the HTTPS, legacy, and agents settings sections to Server management > Settings > Global configuration > Remote
|
| #9103 | Added an SSL verification switch and an optional manager CA file path to the Deploy new agent wizard's optional settings, so the generated enrollment command can pin the manager CA or explicitly opt out of TLS verification |
| #9145 | Added an enrollment token step to the Deploy new agent wizard: the server mints the token for the typed address, with an optional lifetime, number of enrollments and description, or the operator reuses a token kept from an earlier deployment, and the generated command installs the agent with WAZUH_ENROLLMENT_TOKEN
|
| #9145 | Folded the Deploy new agent wizard's optional inputs behind a View advanced options link in the Server address and Enrollment token steps, so the default path is the address plus one click to generate a token |
| #9145 | Added an Enrollment tokens app to Agents management, listing the tokens the server has minted and letting them be created, revoked and purged
|
| #9110 | Redesigned Server management > Configuration and the agent Configuration tab: every setting is now shown directly, grouped by category and subsection, instead of behind a click-through overview; a search box filters this same view in place by name, category, description, or value
|
| #9193 | Added an Add new group action to the Deploy new agent wizard's group selector, sharing the popover of Agents management > Groups, and selecting the created group for the enrollment command
|
| #9173 | Added a server-api:certificate-validity health check that warns when a manager node's listener or CA certificates approach expiry, and reports an error once they are about to expire, have expired, or the CA bundle no longer lets an agent validate the certificate the listener serves
|
Changed
| Issue | Comment |
|---|---|
| #9199 | Moved the About page (app version and community links) into a new opensearch_dashboards.yml-configurable plugin in wazuh-dashboard, and made the top-right help menu's version and links configurable the same way
|
| #9053 | Adapted the agent Communication view and the Deploy new agent wizard to the unified agent <endpoint>: the view renders the single reported endpoint instead of the address/port table, and the wizard collects the address, port and path prefix separately and generates WAZUH_MANAGER_ENDPOINT. Removed the WAZUH_PROTOCOL parameter
|
| #8641 | Reduced peak resource usage during plugin startup by processing index-pattern initialization tasks in small batches instead of all at once |
| wazuh-dashboard#1090 | Changed default index pattern settings key from defaultIndex to wazuh-events-v5*
|
| #7839 | Adapted alerts sample data to Wazuh Common Schema |
| #7688 | Set cluster mode as default for all Wazuh installations, including single-node deployments. Updated RBAC permissions to cluster:* actions
|
| #7578 | Rework SCA modules visualizations, global detail for all agents without pinning, replaced /sca endpoint with wazuh-states-sca-* index pattern, added sample data section
|
| #7601 | Split the FIM registry inventory into 2 index patterns and change some fields in the FIM files and registries sample data |
| #7610 | Reworked health check |
| #7610 | Reworked some view components to use data source |
| #7740 | Fixed date and more format errors |
| #7808 | Upgraded the brace-expansion dependency to 1.1.12 and 2.0.2
|
| #7808 | Upgraded the tar-fs dependency to 2.1.4
|
| wazuh-dashboard#985 | Migrated the wazuh.yml settings to opensearch_dashboards.yml and advanced settings
|
| wazuh-dashboard#985 | Changed the sample data index names |
| #7895 | Rework generate report button |
| #7815 | Changed dashboards renderer by saved objects |
| #7925 | Changed rule.groups filter to wazuh.integration.decoders
|
| #7965 | Applied the new home page navigation style to all dashboards |
| #8059 | Updated Office 365 dashboards to use new index pattern |
| #8058 | Updated GitHub dashboards to use new index pattern |
| #8044 | Updated File Integrity Monitoring dashboards to use new index pattern |
| #8054 | Updated Google Cloud dashboard to use new index pattern |
| #8055 | Updated Amazon web services dashboard to use new index pattern |
| #8056 | Updated Microsoft Graph API dashboard to use new index pattern |
| #8042 | Updated Threat Hunting dashboard with new index pattern definition |
| #8123 | Upgraded the axios dependency to 1.15.2
|
| #8123 | Upgraded loglovel to 1.9.2 |
| #8057 | Updated Docker module under Cloud Security, with new index pattern definition |
| #8134 | Changed Ossec references to wazuh-manager |
| wazuh-dashboard#1118 | Changed default Dev Tools request from deprecated GET /manager/info to GET /cluster/<NODE_NAME>/info
|
| #8120 | Upgraded ESLint from version 8 to version 10 and migrated configuration from legacy .eslintrc.json to the new flat config format (eslint.config.mjs)
|
| #8138 | Updated Malware Detection dashboard with new index pattern definition |
| #8170 | Removed Manager UUID from Server APIs table and added Cluster UUID on About page |
| #8139 | Updated Security Operations dashboards with new index pattern definition |
| #8223 | Changed the monitoring and statistics index patterns to wazuh-metrics-agents* and wazuh-metrics-comms-v4*, and noted that Comms metrics only refer to 4.x agents
|
| #8227 | Renamed Events tab to Findings
|
| #8226 | Replaced the broken visualization in Configuration Assessment |
| #8225 | Swapped menu positions of Vulnerability detection and MITRE ATT&CK |
| #8219 | Removed the Cluster app and relocated some panels to the Status app |
| #8234 | Changed the default value of wazuh.updates.disabled from false to true
|
| #8228 | Centralized regulatory compliance modules (PCI DSS, GDPR, HIPAA, NIST 800-53, and TSC) into a single "Regulatory Compliance" application |
| #8261 | Updated Vulnerability Detection Discover tab filters, and inventory columns |
| #8268 | Changed FIM table columns and index source in the agent view |
| #8305 | Changed index pattern usage in MITRE ATT&CK and Compliance panels in agent overview |
| #8274 | Updated Threat Hunting dashboard with new index pattern definition |
| #8272 | Changed Cluster and Logging configuration sections in Server Management Settings to use the full node configuration endpoint |
| #8284 | Changed last alerts home KPIs title to findings |
| #8312 | Changed IT Hygiene memory visualization |
| #8316 | Reduce the request done to get the index pattern to use in some views |
| #8319 | Changed default columns in Configuration assessment |
| #8348 | Set the downloaded local agent package name same to the remote one |
| #8550 | Updated agent install and download commands to use the release stage for package naming |
| #8416 | Changed FIM findings default columns |
| #8344 | Allowed only 1 server API configuration per indexer |
| #8341 | Updated the OS icon source field in the Endpoints summary table to display Linux agent icons |
| #8159 | Reworked Statistics dashboard |
| #8494 | Updated the breadcrumb label in Agents management / Summary
|
| #8523 | Renamed Listener Engine tab to Comms in Server management > Statistics section |
| #8548 | Reworked FIM overview and agent tab |
| #8560 | Updated MITRE ATT&CK dashboards to use techniques, subtechniques and tactics names |
| #8613 | Condensed the setting labels and added info tooltips in the registration service configuration view |
| #8696 | Adapt management of daemons status to the new API response schema |
| wazuh-dashboard#1434 | Enhanced description of reports.csv.maxRows setting
|
| #8760 | Rework the Home page overview with more platform metrics |
| #8806 | Changed the Users form password validation to require a minimum of 12 characters, matching the manager RBAC policy |
| #8846 | Changed the endpoint stats view to read the agent statistics from the wazuh-agent-stats index instead of the removed server API endpoints
|
| #8851 | Agent configuration reads from wazuh-agent-config, replaces client buffer with batch settings, says when the agent last reported, prompts when it never reported, and matches the report by the selected cluster so an agent with the same ID in another cluster can no longer shadow it
|
| #9042 | Improved the AI assistant explanatory answers: event substance (rule descriptions, command lines, vulnerability descriptions, integration category) now reaches the model, empty-result turns return written answers instead of canned copy, the final-answer instruction survives system-message hoisting, the 13 wazuh-states-* surfaces are queryable and discoverable, agent names resolve for id-only tools, and resolver ambiguity errors are scrubbed under privacy mode
|
| #9040 | Changed the agent Office 365 and GitHub Overview configuration panels to read the agent's reported configuration from the wazuh-agent-config* index pattern instead of the Server API, telling apart the not reported, not configured and read failed states, linking to the module documentation, and reporting an enabled GitHub module as enabled
|
| #9074 | Changed the case management comment header to always show the creation date, with the edit date now shown in a tooltip on an italic "Edited" label |
| #9090 | Changed the Home page's Top 5 techniques bar chart links to open MITRE ATT&CK Findings filtered by the selected technique, instead of the Intelligence tab |
| #9089 | Changed the Home MITRE ATT&CK top tactics chart links to open the MITRE ATT&CK Framework tab filtered by the clicked tactic, instead of the Intelligence tab |
| #9092 | Changed the Global Configuration agents settings to read agents_disconnection_time and agents_disconnection_alert_time from the node configuration instead of the deprecated monitor component, showing the configured value with its time unit
|
| #9094 | Adapted the manager configuration views to the native JSON types the manager now returns for its configuration sections (booleans, objects and arrays instead of the legacy string dialect) |
| #9107 | Added a description under the Users, Roles, Policies and Roles mapping tabs of Server management > Security clarifying they manage the manager API's accounts
|
| #9109 | Replaced the group Manage agents legacy shuttle with a single searchable table where checking a row stages it for adding or removing |
| #9148 | Changed the shared API table's Refresh and Export formatted buttons to show a loading/disabled state tied to the request in flight |
| #9183 | Changed the agent view to show which applications are pinned, why one can not be pinned, and as many shortcuts as fit in the header |
| #9182 | Updated the regulatory compliance requirement definitions of every framework |
| #9173 | Changed the health check tasks to report their own result status, so a check can report a warning without failing; the default notification channels check now reports a warning when some channel is missing instead of passing silently |
| #9202 | Changed the Wazuh plugins to use a single documented i18n message-id convention, translate the remaining wazuh-core and wazuh-check-updates UI strings, and remove the English translation catalogs that overrode the source text
|
| #9220 | Changed the policy details in the Server management > Security > Roles edition flyout to list the actions and resources one per line
|
Removed
| Issue | Comment |
|---|---|
| #9170 | Removed the Comms tab from Server Management > Statistics
|
| #7688 | Removed logic related to manager in favor to cluster management |
| #7464 | Removed the monitoring and statistics jobs in the backend side |
| #7464 | Removed the settings related to monitoring and statistics job from the configuration |
| #7464 | Removed prompt related to statistic job is disabled in Statistics app |
| #7594 | Removed the configuration for modules that relied on the following deprecated daemons: wazuh-agentlessd, wazuh-csyslogd, wazuh-dbd, wazuh-integratord, wazuh-maild, and wazuh-reportd. |
| #7632 | Removed deprecated modules OpenSCAP, CIS-CAT, Osquery |
| #7610 | Removed /health-check and /blank-screen frontend routes
|
| #7610 | Removed Miscellaneous from App Settings
|
| #7610 | Removed customization.logo.healthcheck, checks.api, checks.fields, checks.maxBuckets, checks.metaFields, checks.pattern, checks.setup, checks.template and checks.timeFilter settings
|
| wazuh-dashboard#985 | Removed customization.*, alerts.sample.prefix, configuration.ui_api_editable, ip.selector settings
|
| wazuh-dashboard#985 | Removed App Settings app
|
| wazuh-dashboard#985 | Removed GET /elastic/alerts and /utils/configuration* endpoints
|
| wazuh-dashboard#985 | Removed task to sanitize the custom logos |
| wazuh-dashboard#985 | Removed task to migrate the reports directory |
| #7898 | Removed the Rules, Decoders, CDB List and Ruleset test apps, whose capabilities are now provided by the Ruleset management plugin
|
| #7813 | Removed the legacy reporting application, including its server routes, UI, PDF generation logic, and related customization settings |
| #7888 | Removed some sections in Server Management > Settings and agent configuration |
| #7925 | Removed wazuh-alerts* index pattern and replaced with wazuh-events-v5* as the default index pattern. Removed index pattern selector from top navigation bar as index pattern selection is now handled through module-specific configurations
|
| #7925 | Removed ip.ignore , pattern settings
|
| #7976 | Remove references to templates for alerts and archives |
| #7837 | Remove files related to indexer resources from the source code and obtained when installing the dependencies of the wazuh plugin
|
| #8048 | Removed deprecated settings of Policy monitoring |
| #8053 | Removed the UI permission validation for the upgrade and remove agent actions on Agent management > Summary |
| #8100 | Removed hideManagerAlerts setting
|
| #8101 | Removed usage of agent 000
|
| #8123 | Removed needle dependency
|
| #8123 | Removed read-last-lines dependency
|
| #8192 | Removed Key Request configuration options from the Registration Service view |
| #8213 | Removed Sample Data app and related endpoints to manage |
| wazuh-dashboard#1169 | Removed some options of the manager and agent configuration |
| #8305 | Removed GPG13 option in Compliance panel in agent overview |
| #8836 | Removed the agents table Synced column and the agent configuration synchronization badge, deprecated with the group_config_status and mergedSum properties of the /agents endpoint
|
| #8840 | Removed the usage of the deprecated agent configuration synchronization properties: data.configuration from agents/summary/status, and agent_status.configuration and last_registered_agent.mergedSum from /overview/agents
|
| #8856 | Removed the upgrade task tracking (in-progress panel, task details modal and task_id from upgrade responses) from Agent management > Summary, as the Wazuh Server API no longer exposes /tasks/status; replaced by polling the agent's own version (see Added)
|
| #8956 | Removed the usage of the deprecated agent node_name property (the Cluster node column of the agents table, the Cluster node field of the agent details, the node_name search bar suggestion and CSV column, and the node_name field requested to the /agents endpoint) and the deprecated GET /agents/{agent_id}/daemons/stats endpoint from the API reference and the security actions metadata
|
| #9115 | Removed the unused dashboard and visualization definition files, and the panel builders they replaced, left over after the dashboards moved to saved objects (see #7815). The dashboards are unaffected: they are built from the .ndjson definitions
|
Fixed
| Issue | Comment |
|---|---|
| wazuh-dashboard#1520 | Added the missing Secure flag to the wz-api cookie, and added the X-Content-Type-Options and Strict-Transport-Security response headers
|
| #7922 | Fixed version hardcoded value in the deploy agent wizard |
| wazuh-dashboard#1052 | Fixed styling issues for v9 theme |
| #8094 | Fixed a visual bug in SCA score decimal precision on the Agent Overview |
| #8149 | Fixed the agent stats view was innaccesible for some version combinations |
| #8191 | Fixed the button tooltip showing administrator role requirement where it wasn't needed |
| wazuh-dashboard#1164 | Fixed a message in the group selector of the deploy new agent guide related to missing permissions when there was no groups available or they could not be obtained |
| #8033 | Fixed the under evaluation filter was removed on filter addition in Vulnerability Detection |
| #8266 | Fixed home KPIs not being vertically centered |
| #8309 | Fixed MITRE ATT&CK Findings data grid not spanning the full available width |
| #8470 | Fixed MITRE ATT&CK overview and pinned-agent dashboard visualization titles and layout |
| #8387 | Fixed pinned agent being lost when opening module links (FIM, SCA, Vulnerability Detection, MITRE ATT&CK, agent menu) in a new tab from the agent overview |
| #8471 | Fixed File Integrity Monitoring files inventory table layout by using smaller default widths for file.owner, file.uid, and file.size, allowing file.path to use more horizontal space
|
| #8325 | Fixed long labels in IT Hygiene horizontal bar visualizations causing display issues |
| #8515 | Fixed rendering of the Tactics and Techniques cells in the MITRE ATT&CK flyout |
| wazuh-dashboard-reporting#133 | Fixed custom filter buttons not being rendered in pdf reports |
| #8575 | Fixed MITRE technique fields being truncated in the Document Details flyout by showing the full list of clickable items |
| #8607 | Fixed FIM visualizations height |
| #8652 | Fixed the GitHub link in the About page pointing to the legacy wazuh-kibana-app repository
|
| #8694 | Fixed SCA module columns width |
| #8705 | Fixed Home KPI's visualization persistent filters |
| #8766 | Fixed Server Management Settings crashing or showing a blank page for users without permission to read the manager configuration |
| #8775 | Fixed MITRE ATT&CK Framework tab not applying the date range and fetch filters |
| #9015 | Fixed the Controls tab showing 0 results by adding missing regulatory compliance requirement definitions for PCI DSS, GDPR, HIPAA, NIST 800-53, FedRAMP, ISO 27001, CMMC, TSC, and NIS2, and added an "Others" breakdown showing findings tagged with unrecognized requirement values |
| #9023 | Fixed sorting not working in the Server management > Security tables (Roles, Policies, Users and Roles mapping), and removed the sort affordance from columns the server API cannot sort |
| #9037 | Fixed the Findings data grid crashing and losing every column when a configured column's field does not exist in the index pattern |
| #9048 | Fixed the Server API proxy reporting rejected requests as server errors: POST /api/request now answers with the status the Server API returned instead of turning every 400 or 404 into a 500
|
| #9114 | Fixed Settings, Management, and the Dev Tools app rendering a blank page when navigated to with a missing or unrecognized tab query parameter
|
| #9116 | Fixed the API console's request and RBAC action catalogues drifting from the Server API |
| #9108 | Fixed the PCI DSS compliance requirement descriptions being a stale mix of v3.2.1 and v4.0 wording by rewriting the whole dictionary against PCI DSS v4.0, adding the requirement codes the detection rules report, and dropping the ones v4.0 retired |
| #9112 | Fixed the IT Hygiene System > Hardware dashboard showing the Overview dashboard memory panel instead of its own |
| #9130 | Fixed the agent Configuration view caching the reported configuration for the whole visit with no way to refresh it; added a Refresh control in agent context |
| wazuh-dashboard#1586 | Fixed the saved-objects:index-patterns health check reporting a TypeError instead of the error that prevented the wazuh-events-v5* index pattern initialization, caused by passing the internal saved objects repository where a saved objects client was expected
|
| #9167 | Fixed Vulnerability Detection > Inventory warning that the module was not enabled, and the deploy agent wizard omitting the registration password, when the server reports these settings as native booleans |
| #9174 | Fixed the modules with sub tabs rendering an empty view when moving between two tabs that have sub tabs, for example IT Hygiene System > Software, by selecting the first sub tab whenever the tabSubView query parameter does not match any of the current sub tabs
|
| #9135 | Fixed match_only_text fields (e.g. file.diff) being generated as aggregatable and doc-values-backed in known-fields/index-pattern definitions, which don't support either; and stopped offering a sort control on non-aggregatable columns across Discover-style tables, which OpenSearch rejects
|
| #9177 | Fixed the agent Summary page crashing when pinning Incident Response, and made the pinned application shortcuts honor the agent operating system support |
| #9184 | Fixed multiple React console warnings across plugins/main: deprecated ReactDOM.render/defaultProps usage, EuiBasicTable/EuiButtonGroup prop-type mismatches, invalid HTML nesting, missing key props, useDataGrid prop leakage onto EuiDataGrid, and a NaN row count on Discover
|
| #9230 | Fixed the group Manage agents Pending changes hint telling users to click a row, which does not stage it; it now points to the row checkbox, and the apply button reads "Apply 1 change" for a single change |
| #9231 | Fixed the agent Configuration > Commands "Command status" field showing the raw disabled value instead of enabled/disabled
|
| #9234 | Fixed the group agents table Go to the agent action opening an empty page instead of the agent view |
| #9235 | Fixed the agent name missing from the breadcrumb in the agent view, its Stats and its Configuration, which left no breadcrumb link to return to the agent |
| #9238 | Fixed the group Manage agents Pending changes header reading "nothing written yet" after the changes were applied; it now shows no summary when nothing is staged |
| #9250 | Fixed the filter badges in the search bar displaying in bold instead of normal font weight |
| #9244 | Fixed AI Assistant conversations not being saved for users without write access to the sessions index, and a denied chat request now reports the missing permission instead of a generic error |
| #9282 | Fixed screen readers announcing "[object Object]" instead of the value for each stat of the agent details ribbon |
| #9284 | Fixed every Wazuh view waiting on extra Server API calls before loading data: POST /api/check-stored-api reuses the cached login and fetches the cluster info once, and the security platform is requested once
|