github wazuh/wazuh-dashboard-plugins v5.0.0-rc1

pre-release3 hours ago

[v5.0.0]

Added

Issue Comment
#7464 Added sample data generators for agents monitoring and server statistics
#7680 Added prompts to some views related to problems with server API and alerts index pattern
#7741 Added "Not applicable" status to SCA CheckResult enum with corresponding color mapping (#B9A888) and sample data support
#7920 Added default wazuh-events-v5* index pattern
#8002 Added SSL certificate support for Wazuh API connections, allowing the dashboard to use client certificates and CA certificate validation when connecting to Wazuh Manager APIs configured with custom SSL certificates. The verify_ca value is automatically calculated based on whether certificate paths (key, cert, ca) are configured
#8002 Added "Verify CA" column in the API Connections table to display whether CA certificate verification is enabled for each API host. The value is automatically determined based on certificate configuration
wazuh-dashboard#1086 Added server-api:run_as health check to warn when allow_run_as is disabled for configured API hosts
#8203 Added Indexer management Settings
#8229 Added wazuh-findings-v5* index patterns
#8263 Added policy.name, policy.description, policy.file and event.outcome columns to the Configuration Assessment Findings table
#8246 Added wazuh-state-fim* index pattern
#8272 Added Indexer configuration UI section in Server Management Settings
#8275 Added CMMC regulatory compliance module
#8276 Added FedRAMP regulatory compliance module
#8277 Added ISO 27001 regulatory compliance module
#8278 Added NIS2 regulatory compliance module
#8279 Added NIST 800-171 regulatory compliance module
wazuh-dashboard-security-analytics#213 Added wazuh-threatintel-enrichments* index patterns
#8391 Added Refresh button to the suggested filters search bar
#8401 Added ability to generate PDF report in Vulnerabilities dashboard
#8428 Added wazuh-metrics-normalization* index pattern
#8428 Added Normalization tab and dashboard in Server Management > Statistics
#8556 Added Case Management tab to Findings document details flyout
#8557 Created case management app
#8609 Added visualizations to Vulnerability Detection > Inventory
#8595 Added Incident Response app
wazuh-dashboard-security-analytics#342 Added wazuh.disabledSettings configuration to hide specific settings in the Indexer Settings UI
#8718 Expanded the case management form with title, description, severity, priority and TLP fields, comments that can be added or edited individually, and a confirmation dialog before discarding unsaved changes
#8768 Added queue usage in bytes and agent cache visualizations to Server Management > Statistics, and relabeled the Comms "Queue usage" Y-axis to Bytes
#8789 Added Wazuh AI Assistant plugin
#8846 Added the wazuh-agent-stats index pattern and a sample data generator for the agent statistics index
#8856 Added a success notification when an agent upgrade completes in Agent management > Summary, based on polling the agent's reported version instead of the removed upgrade task tracking
#8961 Added the dispatched and failed task counters to the agent Stats tab
#9067 Added a wazuh_ai_assistant.settingsReadOnly configuration key to lock AI Assistant settings and providers to their current configuration, rejecting write requests regardless of the caller's own indexer permissions
#9020 Added "Scan vulnerabilities" action to request an on-demand vulnerability scan for one or multiple agents from the agents table
#9061 Added the HTTPS, legacy, and agents settings sections to Server management > Settings > Global configuration > Remote
#9103 Added an SSL verification switch and an optional manager CA file path to the Deploy new agent wizard's optional settings, so the generated enrollment command can pin the manager CA or explicitly opt out of TLS verification
#9145 Added an enrollment token step to the Deploy new agent wizard: the server mints the token for the typed address, with an optional lifetime, number of enrollments and description, or the operator reuses a token kept from an earlier deployment, and the generated command installs the agent with WAZUH_ENROLLMENT_TOKEN
#9145 Folded the Deploy new agent wizard's optional inputs behind a View advanced options link in the Server address and Enrollment token steps, so the default path is the address plus one click to generate a token
#9145 Added an Enrollment tokens app to Agents management, listing the tokens the server has minted and letting them be created, revoked and purged
#9110 Redesigned Server management > Configuration and the agent Configuration tab: every setting is now shown directly, grouped by category and subsection, instead of behind a click-through overview; a search box filters this same view in place by name, category, description, or value
#9193 Added an Add new group action to the Deploy new agent wizard's group selector, sharing the popover of Agents management > Groups, and selecting the created group for the enrollment command
#9173 Added a server-api:certificate-validity health check that warns when a manager node's listener or CA certificates approach expiry, and reports an error once they are about to expire, have expired, or the CA bundle no longer lets an agent validate the certificate the listener serves

Changed

Issue Comment
#9199 Moved the About page (app version and community links) into a new opensearch_dashboards.yml-configurable plugin in wazuh-dashboard, and made the top-right help menu's version and links configurable the same way
#9053 Adapted the agent Communication view and the Deploy new agent wizard to the unified agent <endpoint>: the view renders the single reported endpoint instead of the address/port table, and the wizard collects the address, port and path prefix separately and generates WAZUH_MANAGER_ENDPOINT. Removed the WAZUH_PROTOCOL parameter
#8641 Reduced peak resource usage during plugin startup by processing index-pattern initialization tasks in small batches instead of all at once
wazuh-dashboard#1090 Changed default index pattern settings key from defaultIndex to wazuh-events-v5*
#7839 Adapted alerts sample data to Wazuh Common Schema
#7688 Set cluster mode as default for all Wazuh installations, including single-node deployments. Updated RBAC permissions to cluster:* actions
#7578 Rework SCA modules visualizations, global detail for all agents without pinning, replaced /sca endpoint with wazuh-states-sca-* index pattern, added sample data section
#7601 Split the FIM registry inventory into 2 index patterns and change some fields in the FIM files and registries sample data
#7610 Reworked health check
#7610 Reworked some view components to use data source
#7740 Fixed date and more format errors
#7808 Upgraded the brace-expansion dependency to 1.1.12 and 2.0.2
#7808 Upgraded the tar-fs dependency to 2.1.4
wazuh-dashboard#985 Migrated the wazuh.yml settings to opensearch_dashboards.yml and advanced settings
wazuh-dashboard#985 Changed the sample data index names
#7895 Rework generate report button
#7815 Changed dashboards renderer by saved objects
#7925 Changed rule.groups filter to wazuh.integration.decoders
#7965 Applied the new home page navigation style to all dashboards
#8059 Updated Office 365 dashboards to use new index pattern
#8058 Updated GitHub dashboards to use new index pattern
#8044 Updated File Integrity Monitoring dashboards to use new index pattern
#8054 Updated Google Cloud dashboard to use new index pattern
#8055 Updated Amazon web services dashboard to use new index pattern
#8056 Updated Microsoft Graph API dashboard to use new index pattern
#8042 Updated Threat Hunting dashboard with new index pattern definition
#8123 Upgraded the axios dependency to 1.15.2
#8123 Upgraded loglovel to 1.9.2
#8057 Updated Docker module under Cloud Security, with new index pattern definition
#8134 Changed Ossec references to wazuh-manager
wazuh-dashboard#1118 Changed default Dev Tools request from deprecated GET /manager/info to GET /cluster/<NODE_NAME>/info
#8120 Upgraded ESLint from version 8 to version 10 and migrated configuration from legacy .eslintrc.json to the new flat config format (eslint.config.mjs)
#8138 Updated Malware Detection dashboard with new index pattern definition
#8170 Removed Manager UUID from Server APIs table and added Cluster UUID on About page
#8139 Updated Security Operations dashboards with new index pattern definition
#8223 Changed the monitoring and statistics index patterns to wazuh-metrics-agents* and wazuh-metrics-comms-v4*, and noted that Comms metrics only refer to 4.x agents
#8227 Renamed Events tab to Findings
#8226 Replaced the broken visualization in Configuration Assessment
#8225 Swapped menu positions of Vulnerability detection and MITRE ATT&CK
#8219 Removed the Cluster app and relocated some panels to the Status app
#8234 Changed the default value of wazuh.updates.disabled from false to true
#8228 Centralized regulatory compliance modules (PCI DSS, GDPR, HIPAA, NIST 800-53, and TSC) into a single "Regulatory Compliance" application
#8261 Updated Vulnerability Detection Discover tab filters, and inventory columns
#8268 Changed FIM table columns and index source in the agent view
#8305 Changed index pattern usage in MITRE ATT&CK and Compliance panels in agent overview
#8274 Updated Threat Hunting dashboard with new index pattern definition
#8272 Changed Cluster and Logging configuration sections in Server Management Settings to use the full node configuration endpoint
#8284 Changed last alerts home KPIs title to findings
#8312 Changed IT Hygiene memory visualization
#8316 Reduce the request done to get the index pattern to use in some views
#8319 Changed default columns in Configuration assessment
#8348 Set the downloaded local agent package name same to the remote one
#8550 Updated agent install and download commands to use the release stage for package naming
#8416 Changed FIM findings default columns
#8344 Allowed only 1 server API configuration per indexer
#8341 Updated the OS icon source field in the Endpoints summary table to display Linux agent icons
#8159 Reworked Statistics dashboard
#8494 Updated the breadcrumb label in Agents management / Summary
#8523 Renamed Listener Engine tab to Comms in Server management > Statistics section
#8548 Reworked FIM overview and agent tab
#8560 Updated MITRE ATT&CK dashboards to use techniques, subtechniques and tactics names
#8613 Condensed the setting labels and added info tooltips in the registration service configuration view
#8696 Adapt management of daemons status to the new API response schema
wazuh-dashboard#1434 Enhanced description of reports.csv.maxRows setting
#8760 Rework the Home page overview with more platform metrics
#8806 Changed the Users form password validation to require a minimum of 12 characters, matching the manager RBAC policy
#8846 Changed the endpoint stats view to read the agent statistics from the wazuh-agent-stats index instead of the removed server API endpoints
#8851 Agent configuration reads from wazuh-agent-config, replaces client buffer with batch settings, says when the agent last reported, prompts when it never reported, and matches the report by the selected cluster so an agent with the same ID in another cluster can no longer shadow it
#9042 Improved the AI assistant explanatory answers: event substance (rule descriptions, command lines, vulnerability descriptions, integration category) now reaches the model, empty-result turns return written answers instead of canned copy, the final-answer instruction survives system-message hoisting, the 13 wazuh-states-* surfaces are queryable and discoverable, agent names resolve for id-only tools, and resolver ambiguity errors are scrubbed under privacy mode
#9040 Changed the agent Office 365 and GitHub Overview configuration panels to read the agent's reported configuration from the wazuh-agent-config* index pattern instead of the Server API, telling apart the not reported, not configured and read failed states, linking to the module documentation, and reporting an enabled GitHub module as enabled
#9074 Changed the case management comment header to always show the creation date, with the edit date now shown in a tooltip on an italic "Edited" label
#9090 Changed the Home page's Top 5 techniques bar chart links to open MITRE ATT&CK Findings filtered by the selected technique, instead of the Intelligence tab
#9089 Changed the Home MITRE ATT&CK top tactics chart links to open the MITRE ATT&CK Framework tab filtered by the clicked tactic, instead of the Intelligence tab
#9092 Changed the Global Configuration agents settings to read agents_disconnection_time and agents_disconnection_alert_time from the node configuration instead of the deprecated monitor component, showing the configured value with its time unit
#9094 Adapted the manager configuration views to the native JSON types the manager now returns for its configuration sections (booleans, objects and arrays instead of the legacy string dialect)
#9107 Added a description under the Users, Roles, Policies and Roles mapping tabs of Server management > Security clarifying they manage the manager API's accounts
#9109 Replaced the group Manage agents legacy shuttle with a single searchable table where checking a row stages it for adding or removing
#9148 Changed the shared API table's Refresh and Export formatted buttons to show a loading/disabled state tied to the request in flight
#9183 Changed the agent view to show which applications are pinned, why one can not be pinned, and as many shortcuts as fit in the header
#9182 Updated the regulatory compliance requirement definitions of every framework
#9173 Changed the health check tasks to report their own result status, so a check can report a warning without failing; the default notification channels check now reports a warning when some channel is missing instead of passing silently
#9202 Changed the Wazuh plugins to use a single documented i18n message-id convention, translate the remaining wazuh-core and wazuh-check-updates UI strings, and remove the English translation catalogs that overrode the source text
#9220 Changed the policy details in the Server management > Security > Roles edition flyout to list the actions and resources one per line

Removed

Issue Comment
#9170 Removed the Comms tab from Server Management > Statistics
#7688 Removed logic related to manager in favor to cluster management
#7464 Removed the monitoring and statistics jobs in the backend side
#7464 Removed the settings related to monitoring and statistics job from the configuration
#7464 Removed prompt related to statistic job is disabled in Statistics app
#7594 Removed the configuration for modules that relied on the following deprecated daemons: wazuh-agentlessd, wazuh-csyslogd, wazuh-dbd, wazuh-integratord, wazuh-maild, and wazuh-reportd.
#7632 Removed deprecated modules OpenSCAP, CIS-CAT, Osquery
#7610 Removed /health-check and /blank-screen frontend routes
#7610 Removed Miscellaneous from App Settings
#7610 Removed customization.logo.healthcheck, checks.api, checks.fields, checks.maxBuckets, checks.metaFields, checks.pattern, checks.setup, checks.template and checks.timeFilter settings
wazuh-dashboard#985 Removed customization.*, alerts.sample.prefix, configuration.ui_api_editable, ip.selector settings
wazuh-dashboard#985 Removed App Settings app
wazuh-dashboard#985 Removed GET /elastic/alerts and /utils/configuration* endpoints
wazuh-dashboard#985 Removed task to sanitize the custom logos
wazuh-dashboard#985 Removed task to migrate the reports directory
#7898 Removed the Rules, Decoders, CDB List and Ruleset test apps, whose capabilities are now provided by the Ruleset management plugin
#7813 Removed the legacy reporting application, including its server routes, UI, PDF generation logic, and related customization settings
#7888 Removed some sections in Server Management > Settings and agent configuration
#7925 Removed wazuh-alerts* index pattern and replaced with wazuh-events-v5* as the default index pattern. Removed index pattern selector from top navigation bar as index pattern selection is now handled through module-specific configurations
#7925 Removed ip.ignore , pattern settings
#7976 Remove references to templates for alerts and archives
#7837 Remove files related to indexer resources from the source code and obtained when installing the dependencies of the wazuh plugin
#8048 Removed deprecated settings of Policy monitoring
#8053 Removed the UI permission validation for the upgrade and remove agent actions on Agent management > Summary
#8100 Removed hideManagerAlerts setting
#8101 Removed usage of agent 000
#8123 Removed needle dependency
#8123 Removed read-last-lines dependency
#8192 Removed Key Request configuration options from the Registration Service view
#8213 Removed Sample Data app and related endpoints to manage
wazuh-dashboard#1169 Removed some options of the manager and agent configuration
#8305 Removed GPG13 option in Compliance panel in agent overview
#8836 Removed the agents table Synced column and the agent configuration synchronization badge, deprecated with the group_config_status and mergedSum properties of the /agents endpoint
#8840 Removed the usage of the deprecated agent configuration synchronization properties: data.configuration from agents/summary/status, and agent_status.configuration and last_registered_agent.mergedSum from /overview/agents
#8856 Removed the upgrade task tracking (in-progress panel, task details modal and task_id from upgrade responses) from Agent management > Summary, as the Wazuh Server API no longer exposes /tasks/status; replaced by polling the agent's own version (see Added)
#8956 Removed the usage of the deprecated agent node_name property (the Cluster node column of the agents table, the Cluster node field of the agent details, the node_name search bar suggestion and CSV column, and the node_name field requested to the /agents endpoint) and the deprecated GET /agents/{agent_id}/daemons/stats endpoint from the API reference and the security actions metadata
#9115 Removed the unused dashboard and visualization definition files, and the panel builders they replaced, left over after the dashboards moved to saved objects (see #7815). The dashboards are unaffected: they are built from the .ndjson definitions

Fixed

Issue Comment
wazuh-dashboard#1520 Added the missing Secure flag to the wz-api cookie, and added the X-Content-Type-Options and Strict-Transport-Security response headers
#7922 Fixed version hardcoded value in the deploy agent wizard
wazuh-dashboard#1052 Fixed styling issues for v9 theme
#8094 Fixed a visual bug in SCA score decimal precision on the Agent Overview
#8149 Fixed the agent stats view was innaccesible for some version combinations
#8191 Fixed the button tooltip showing administrator role requirement where it wasn't needed
wazuh-dashboard#1164 Fixed a message in the group selector of the deploy new agent guide related to missing permissions when there was no groups available or they could not be obtained
#8033 Fixed the under evaluation filter was removed on filter addition in Vulnerability Detection
#8266 Fixed home KPIs not being vertically centered
#8309 Fixed MITRE ATT&CK Findings data grid not spanning the full available width
#8470 Fixed MITRE ATT&CK overview and pinned-agent dashboard visualization titles and layout
#8387 Fixed pinned agent being lost when opening module links (FIM, SCA, Vulnerability Detection, MITRE ATT&CK, agent menu) in a new tab from the agent overview
#8471 Fixed File Integrity Monitoring files inventory table layout by using smaller default widths for file.owner, file.uid, and file.size, allowing file.path to use more horizontal space
#8325 Fixed long labels in IT Hygiene horizontal bar visualizations causing display issues
#8515 Fixed rendering of the Tactics and Techniques cells in the MITRE ATT&CK flyout
wazuh-dashboard-reporting#133 Fixed custom filter buttons not being rendered in pdf reports
#8575 Fixed MITRE technique fields being truncated in the Document Details flyout by showing the full list of clickable items
#8607 Fixed FIM visualizations height
#8652 Fixed the GitHub link in the About page pointing to the legacy wazuh-kibana-app repository
#8694 Fixed SCA module columns width
#8705 Fixed Home KPI's visualization persistent filters
#8766 Fixed Server Management Settings crashing or showing a blank page for users without permission to read the manager configuration
#8775 Fixed MITRE ATT&CK Framework tab not applying the date range and fetch filters
#9015 Fixed the Controls tab showing 0 results by adding missing regulatory compliance requirement definitions for PCI DSS, GDPR, HIPAA, NIST 800-53, FedRAMP, ISO 27001, CMMC, TSC, and NIS2, and added an "Others" breakdown showing findings tagged with unrecognized requirement values
#9023 Fixed sorting not working in the Server management > Security tables (Roles, Policies, Users and Roles mapping), and removed the sort affordance from columns the server API cannot sort
#9037 Fixed the Findings data grid crashing and losing every column when a configured column's field does not exist in the index pattern
#9048 Fixed the Server API proxy reporting rejected requests as server errors: POST /api/request now answers with the status the Server API returned instead of turning every 400 or 404 into a 500
#9114 Fixed Settings, Management, and the Dev Tools app rendering a blank page when navigated to with a missing or unrecognized tab query parameter
#9116 Fixed the API console's request and RBAC action catalogues drifting from the Server API
#9108 Fixed the PCI DSS compliance requirement descriptions being a stale mix of v3.2.1 and v4.0 wording by rewriting the whole dictionary against PCI DSS v4.0, adding the requirement codes the detection rules report, and dropping the ones v4.0 retired
#9112 Fixed the IT Hygiene System > Hardware dashboard showing the Overview dashboard memory panel instead of its own
#9130 Fixed the agent Configuration view caching the reported configuration for the whole visit with no way to refresh it; added a Refresh control in agent context
wazuh-dashboard#1586 Fixed the saved-objects:index-patterns health check reporting a TypeError instead of the error that prevented the wazuh-events-v5* index pattern initialization, caused by passing the internal saved objects repository where a saved objects client was expected
#9167 Fixed Vulnerability Detection > Inventory warning that the module was not enabled, and the deploy agent wizard omitting the registration password, when the server reports these settings as native booleans
#9174 Fixed the modules with sub tabs rendering an empty view when moving between two tabs that have sub tabs, for example IT Hygiene System > Software, by selecting the first sub tab whenever the tabSubView query parameter does not match any of the current sub tabs
#9135 Fixed match_only_text fields (e.g. file.diff) being generated as aggregatable and doc-values-backed in known-fields/index-pattern definitions, which don't support either; and stopped offering a sort control on non-aggregatable columns across Discover-style tables, which OpenSearch rejects
#9177 Fixed the agent Summary page crashing when pinning Incident Response, and made the pinned application shortcuts honor the agent operating system support
#9184 Fixed multiple React console warnings across plugins/main: deprecated ReactDOM.render/defaultProps usage, EuiBasicTable/EuiButtonGroup prop-type mismatches, invalid HTML nesting, missing key props, useDataGrid prop leakage onto EuiDataGrid, and a NaN row count on Discover
#9230 Fixed the group Manage agents Pending changes hint telling users to click a row, which does not stage it; it now points to the row checkbox, and the apply button reads "Apply 1 change" for a single change
#9231 Fixed the agent Configuration > Commands "Command status" field showing the raw disabled value instead of enabled/disabled
#9234 Fixed the group agents table Go to the agent action opening an empty page instead of the agent view
#9235 Fixed the agent name missing from the breadcrumb in the agent view, its Stats and its Configuration, which left no breadcrumb link to return to the agent
#9238 Fixed the group Manage agents Pending changes header reading "nothing written yet" after the changes were applied; it now shows no summary when nothing is staged
#9250 Fixed the filter badges in the search bar displaying in bold instead of normal font weight
#9244 Fixed AI Assistant conversations not being saved for users without write access to the sessions index, and a denied chat request now reports the missing permission instead of a generic error
#9282 Fixed screen readers announcing "[object Object]" instead of the value for each stat of the agent details ribbon
#9284 Fixed every Wazuh view waiting on extra Server API calls before loading data: POST /api/check-stored-api reuses the cached login and fetches the cluster info once, and the security platform is requested once

Don't miss a new wazuh-dashboard-plugins release

NewReleases is sending notifications on new releases.