Added
- Added documentation for the reporting plugin in the Wazuh dashboard package generation guide. (#8682)
- Added references for FIM (Syscheck) and inventory (Syscollector) state persistence settings. (#8801)
- Added documentation for SCA state persistence settings. (#8841)
- Added ARM64 support for Linux and macOS WPK packages. (#8851)
- Added
integrity_intervalto the syschecksynchronizationconfiguration and updated theresponse_timeoutdefault value. (#9099) - Added
integrity_intervalto the SCA and the syscollectorsynchronizationconfiguration. (#9164) - Added Upgrading to Wazuh 5.x sub-section to the Upgrade guide. (#9435)
- Added the Data analysis documentation to the User manual. (#9743)
- Added the Migration guide documentation. (#9772) (#9792) (#9817) (#9873) (#10028) (#10067) (#10264)
- Added the Security configuration assessment use case to the Proof of concept guide. (#9777)
- Added the Network IDS integration use case to the Proof of concept guide. (#9831) (#10228)
- Added the Detecting a Cross-Site Scripting (XSS) attack use case to the Proof of concept guide. (#9916)
- Added the Wazuh CTI documentation as a new top-level section. (#9989) (#9990) (#10250)
- Added the Incident response dashboard section, the Email notification channel, and the AI Assistant configuration documentation to the Wazuh dashboard section. (#10033)
- Added the Installation Assistant and Certs tool documentation to the Reference section. (#10047)
- Added a note to the Regulatory compliance index page stating that the rule and control mappings are indicative and require an independent qualified assessor for formal certification. (#10191)
Changed
- Replaced
indexer_cluster_initial_master_nodeswithindexer_initial_cluster_manager_nodesin Puppet deployment documentation. (#8666) - Updated the File Integrity Monitoring documentation to remove deprecated settings (
max_interval,queue_size,thread_pool,database, andregistry_enabled), add the missingcheck_devicesetting, and fix themax_epsdefinition in the synchronization settings table. (#8735) - Updated the FIM documentation to change the default FIM who-data mode provider to eBPF. (#8805)
- Updated references in steps and links to 5.x. (#8853) (#9658) (#9660)
- Updated version numbers in commands in the Installation from sources documentation. (#9397)
- Updated the Installation guide. (#9545) (#9682) (#9692) (#9736) (#9771) (#9962) (#9968) (#9969) (#9994) (#10002) (#10019) (#10187) (#10212) (#10221) (#10239) (#10251) (#10252) (#10255)
- Updated the Installation alternatives documentation. (#9587) (#9576) (#9589) (#9591) (#9591) (#9597) (#9606) (#9607) (#9674)
- Updated the Wazuh agent documentation in User manual. (#9665) (#9669) (#9701) (#9702) (#9812) (#9993) (#10035) (#10065) (#10212) (#10214) (#10263) (#10266)
- Updated the Wazuh dashboard documentation in User manual. (#9688) (#10033) (#10036) (#10213) (#10249)
- Updated the Quickstart documentation. (#9680) (#9769) (#10234) (#10248) (#10258)
- Updated the Wazuh server documentation to the new Wazuh manager documentation in the User manual. (#9728) (#9737) (#10064) (#10237)
- Updated the User administration documentation. (#9745) (#9758) (#9765) (#9766) (#9775) (#10040) (#10236) (#10259) (#10265)
- Updated the Monitoring GitHub documentation. (#9836) (#9840) (#9949)
- Updated the Monitoring Office 365 documentation. (#9935)
- Updated the Proof of concept guide use cases for File integrity monitoring, Vulnerability detection, Monitoring Docker events, Detecting an SQL injection attack, Network IDS integration, Monitoring AWS infrastructure, Detecting hidden processes, and Blocking a known malicious actor. (#9777) (#9831) (#9916)
- Updated the Container security documentation. (#9816) (#9819) (#9823) (#10206)
- Updated the System inventory documentation. (#9820) (#9832) (#10215) (#10216) (#10228)
- Updated the Security configuration assessment capability documentation. (#9834) (#9849) (#10178)
- Updated the Vulnerability detection capability documentation and added a Use cases section. (#9835) (#9841) (#10018) (#10228)
- Updated the Command monitoring capability documentation. (#9883) (#9915)
- Updated the File integrity monitoring capability documentation to Wazuh 5.0. (#9961) (#10165)
- Updated the minimum required password length for Wazuh API users to 12 characters in the Deploying with Kubernetes documentation. (#9941)
- Updated the Using Wazuh for GDPR compliance documentation in Regulatory compliance to Wazuh 5.0. (#9944) (#10191)
- Updated the Monitoring Linux system calls capability documentation to Wazuh 5.0. (#10010)
- Updated the Wazuh indexer API reference, removing the non-tracked version number from its page header, grouping its sections by plugin, and fixing a duplicate tag name that could merge two unrelated sections. (#10015) (#10016) (#10017) (#10025) (#10041) (#10042) (#10043) (#10044) (#10048)
- Updated the Using Wazuh for TSC compliance documentation in Regulatory compliance to Wazuh 5.0. (#10027) (#10045) (#10191)
- Updated the Log data collection capability documentation to Wazuh 5.0, covering Wazuh agent configuration, collecting logs from files and operating systems, log data analysis, and new use cases. (#10034) (#10037)
- Updated the Reference documentation to Wazuh 5.0, splitting the local configuration reference into separate
wazuh-manager.confandossec.confsections, renaming manager daemons and tools with thewazuh-manager-prefix, updating the internal configuration, daemons, and tools references, and removing documentation for configuration sections and CLI tools no longer supported in Wazuh 5.0. (#10047) (#10070) (#10071) (#10072) (#10177) (#10215) (#10266) - Updated the Active response capability documentation to Wazuh 5.0, covering configuration from the Wazuh dashboard, the consolidated
block-ipscript, developing custom scripts, migrating custom scripts from Wazuh 4.x, and new use cases for blocking web attacks and removing malicious files. (#10062) (#10228) - Replaced the
adminuser with the dedicatedwazuh-manageruser in the Wazuh indexer connector credential examples, and standardized the indexer connector certificate name toindexer-connector.pem/indexer-connector-key.pemacross the Installation guide, Deployment options, and User manual documentation, also correcting the certificate ownership and permissions in the Installation guide's certificate deployment step so the Wazuh manager can read them after dropping privileges. (#10063) - Updated the Using Wazuh for PCI DSS compliance documentation in Regulatory compliance to Wazuh 5.0. (#10066) (#10191)
- Updated the Getting started documentation to Wazuh 5.0, covering the dashboard screenshot gallery and the Architecture section's component communication and required ports. (#10069) (#10073) (#10231) (#10239) (#10244) (#10246)
- Updated the Using Wazuh for HIPAA compliance documentation in Regulatory compliance to Wazuh 5.0. (#10083) (#10191)
- Updated the Monitoring Google Cloud documentation in Cloud security to Wazuh 5.0, covering the Wazuh agent-only prerequisites, enabling the integration from the Wazuh dashboard, a consolidated log sink export flow, and configuring the Wazuh modules for Pub/Sub and Storage buckets. (#10092)
- Updated the Wazuh indexer documentation in User manual to Wazuh 5.0, covering data streams and stateful indices, the Wazuh Common Schema, Sigma rules, index templates, the Setup, Content Manager, Reporting, Security Analytics, Notifications, and Alerting modules, indexer tuning, migrating indices, backup and restore, and role-based access control. (#10093)
- Updated the Monitoring Microsoft Azure documentation in Cloud security to Wazuh 5.0, covering the Wazuh agent-only prerequisites, enabling the integration from the Wazuh dashboard, configuring credentials for Azure Log Analytics, Azure Storage, and the standalone Wazuh module for Microsoft Graph, the Microsoft Intune integration, and use cases. (#10139)
- Updated the Wazuh indexer cluster documentation in User manual to Wazuh 5.0, covering cluster architecture and node types, required ports, cluster configuration, certificate deployment, cluster tuning, security initialization, adding and removing nodes, cluster management, and troubleshooting. (#10183) (#10185) (#10228)
- Corrected an internal link in the Wazuh Docker utilities documentation that pointed to a bare path instead of the built page. (#10212)
Removed
- Removed all
agent-authreferences as this tool is now deprecated. (#8718) - Removed
compatibility.override_main_response_versionsetting from Wazuh Indexer configuration as it is no longer supported in OpenSearch 3.0. (#8609) - Removed several Rootcheck configuration options and added a corresponding note to the central components upgrade guide. (#8759)
- Removed references to the server version of the
manage_agentstool. (#8792) - Removed
cron.prefix,cron.statistics.*, andwazuh.monitoring.*configuration settings from the Wazuh dashboard. (#8790) - Removed references to deprecated client communication and FIM configuration options. (#8809)
- Removed documentation and references to deprecated Wazuh Manager daemons:
wazuh-agentlessd,wazuh-csyslogd,wazuh-dbd,wazuh-integratord,wazuh-maild, andwazuh-reportd. (#8778) - Removed documentation and references to deprecated CLI tools:
clear_stats,update_ruleset, andwazuh-regex. (#8778) - Removed documentation to deprecated
fluent-forwardtool. (#8778) - Removed support for legacy operating systems, including Red Hat 5, CentOS 5, Oracle Linux 5, SUSE Linux Enterprise Server 11, AIX, HP-UX, Solaris, Windows XP, Windows Vista, and Windows Server 2003. (#8894)
- Removed deprecated configuration variables in the Deployment with Puppet documentation. (#9378)
- Removed Osquery references as this capability is now deprecated. (#8958)