Rule Doctor reads your manager and names the reason each custom rule stayed silent — including the
rules Wazuh throws away while loading them, while wazuh-analysisd -t still exits 0 and the manager starts normally.
$ python3 rule-doctor-lite.py --ossec-dir tests/fixtureATK Rule Doctor Lite 0.2.1 — silent custom rulesmeasurement window: 2026-09-25T00:00:00.000+0000 -> 2026-09-25T02:00:00.000+0000 (1 alerts file(s), 1 ossec.log file(s))rules read: 11 (stock 2, custom 9) rule ids that fired: 3 silent custom: 7 event loss (203/204): no 910001 level 5 0300-custom.xml SHADOW-CANDIDATE fired sibling(s) evaluated first: 910002 (level 12), 910004 (level 8) 910003 level 8 0300-custom.xml SHADOW-CANDIDATE fired sibling(s) evaluated first: 910002 (level 12), 910004 (level 8) 910006 level 7 0300-custom.xml SHADOW-CANDIDATE fired sibling(s) evaluated first: 910002 (level 12), 910004 (level 8) 910010 level 10 0094-early.xml DROPPED-AT-LOAD ossec.log 7617: parent 5715 not found when the rule loaded 910011 level 6 0400-typo.xml DROPPED-AT-LOAD predicted: parent 57150 is not defined anywhere 910012 level 10 0500-chain.xml DROPPED-AT-LOAD predicted: parent 910010 is itself dropped at load 910013 level 12 0500-chain.xml DROPPED-AT-LOAD predicted: parent 910012 is itself dropped at load totals: DROPPED-AT-LOAD=4, SHADOW-CANDIDATE=3A rule written for a rare event is not dead after a short window: check the dates above.DROPPED-AT-LOAD: rename the file so it sorts after the file holding the parent, or fix the if_sid.$
This is the tool’s actual output on the test fixture shipped in its repository, not a customer’s manager. Run the same command and you get the same lines.
ossec.log writes when a rule is dropped at load. The config check still exits 0.A child rule in a file that sorts before its parent’s file is dropped at load. Its children go with it. The video shows the chain we measured on 28 September, the one-minute check, and the fix.
Each silent custom rule gets the most likely cause, so you know whether to rename a file, replay an event, or look at the pipeline.
Every option starts from the same free scan. Pay nothing to find the rules; pay for an answer, a fix, or the tool.
--jsonetc/rules/*.xmlThen email the JSON and your rules to dongnx@atkvn.com. Bank transfer also possible.
Invoiced by ATK, paid by bank transfer or PayPal. We never ask for write access to your systems.
mapper_parsing_exception fixCards accepted through PayPal; an ATK invoice on request. 14-day refund.
ATK New Technology One Member Company Limited, Hanoi · Tax ID 0110935486
Every measurement is published with its method and limits; the research reports include the raw data
PayPal or bank transfer, ATK invoice, written refund policy
Run it on the Wazuh manager, or on a copy of /var/ossec. It reads rule files, ossec.log and the alerts files. Nothing is installed as a service and nothing leaves the machine.
curl -sLO https://github.com/xuxu298/rule-doctor-lite/releases/latest/download/rule-doctor-lite.py
sudo python3 rule-doctor-lite.py
pipx install rule-doctor-lite
sudo "$(command -v rule-doctor-lite)"
One command on the manager. Add --days 30 for a longer window, --json report.json to keep the result.
Each silent rule comes with its cause and the time window it was measured over. A rule for a quarterly event is not dead after a day.
Every label has a fix note with a one-minute check. If you would rather not, send the JSON for a USD 49 review or book a Fix Pack.
rule-doctor silentReads the custom rules on your manager and your recent alerts, and sorts the rules that never fired into three common causes: shadowed by a sibling rule that matches first, an event that never reaches the manager, or no event that matches it. Candidates for “shadowed” are confirmed by replaying real events through wazuh-logtest on a throwaway manager of your version, started and removed by the tool. Every result is printed with the time window it was measured over.
rule-doctor mappingFor mapper_parsing_exception caused by a field that is an object in some events and a string in others: builds the pipeline change and the index template from your current pipeline, verifies them against your sample alerts in an isolated index, applies them, and rolls them back byte-for-byte if you ask.
After checkout you receive the software (version 1.0.0, a single archive with a README) and your licence details by email within one business day. Updates during the licence term are sent the same way. A licence covers one Wazuh cluster (one manager cluster and its indexer) for 12 months.
Wazuh 4.x on Linux, Python 3, and Docker on the machine that runs the replay step. Read access to the manager’s rule files and alerts; the mapping fix needs an indexer account that can change index templates and ingest pipelines. Replay needs full_log in the alerts; Windows event-channel and JSON sources are not yet validated. A mapping fix takes effect from the next daily index. Version 1.0.0 does not yet detect rules dropped at load — Lite does.
Not with Lite: it reads local files and prints to your terminal, or to a JSON file if you ask. For a review or a Fix Pack, only the files you choose to email reach us.
Wazuh 4.x rule syntax. Measured on a real 4.14.7 manager; 4.14.8 ships byte-identical rule-loading source files. Lite follows if_sid parents; if_group and if_matched_* parents are not followed yet.
Copy the rule directories, ossec.log and the alerts file out of the container and point --ossec-dir at the copy. The exact commands are in the README.
Lite reads rotated .gz alerts files inside the --days window (7 days by default), and takes load warnings from the latest load only.
PayPal (cards accepted) or bank transfer. ATK New Technology issues the invoice. A Fix Pack is invoiced only after the fix fires on your cluster.
The licence has a 14-day refund, no questions asked; the review is refunded if it finds nothing you can act on. See the refund policy.
Run Lite on your manager. If the output raises more questions than it answers, a written review is USD 49 and comes back within one business day.
Sold by ATK New Technology One Member Company Limited, Hanoi, Vietnam. Terms · Refund policy · Privacy policy · dongnx@atkvn.com