For Wazuh 4.x · measured on 4.14.7

Find the Wazuh rules that never fire.

Rule Doctor reads your manager and names the reason each custom rule stayed silent — including the rules Wazuh throws away while loading them, while wazuh-analysisd -t still exits 0 and the manager starts normally.

read-only · changes nothing1 file · Python 3 stdlibApache-2.0pipx install rule-doctor-lite

This is the tool’s actual output on the test fixture shipped in its repository, not a customer’s manager. Run the same command and you get the same lines.

7617 / 7619
The warnings ossec.log writes when a rule is dropped at load. The config check still exits 0.
4 labels
Dropped at load, shadow candidate, never reaches the manager, no match — each printed with its time window.
0 deps
Python 3 standard library only. Reads files, changes nothing, sends nothing anywhere.
4.14.7
Measured on a real manager. 4.14.8 ships byte-identical rule-loading source.
Watch · 3 min 24 s

Why a rule that passes every check never fires.

A child rule in a file that sorts before its parent’s file is dropped at load. Its children go with it. The video shows the chain we measured on 28 September, the one-minute check, and the fix.

Read the fix note instead →

English · captionsWazuh 4.14.74.3 MB · loads only when you press play
What the labels mean

Silent is not one problem. It is four.

Each silent custom rule gets the most likely cause, so you know whether to rename a file, replay an event, or look at the pipeline.

DROPPED-AT-LOAD

Wazuh ignored the rule while loading: its if_sid parent was not loaded yet (the file name sorts first) or does not exist. Chains are followed — a child of a dropped rule is dropped too. Read from ossec.log when present, otherwise predicted from the load order.

SHADOW-CANDIDATE

A sibling that Wazuh evaluates first did fire. A candidate, not a finding: it proves the sibling matched something, not that your rule would have matched the same event. The full tool replays to confirm or clear it.

NEVER-REACHES-MANAGER

No related rule fired and the manager logged event loss (rules 203/204).

NO-MATCH

A related rule fired but this one did not, or nothing suggests event loss.

Pricing

Pick how much of it you want done for you.

Every option starts from the same free scan. Pay nothing to find the rules; pay for an answer, a fix, or the tool.

Find them

Rule Doctor Lite

Free
  • Every custom rule that never fired, with the likely reason
  • Rules dropped at load, including chains of them
  • JSON report with --json
  • Open source, Apache-2.0
Install Lite →
Understand them1 business day

Silent Rule Review

USD 49
  • Send the Lite JSON and your etc/rules/*.xml
  • A written review of every silent rule: the cause, the exact change, which ones you can fix yourself
  • Comes off a Fix Pack ordered within 30 days
  • Nothing you can act on ⇒ the USD 49 comes back
Pay USD 49 with PayPal →

Then email the JSON and your rules to dongnx@atkvn.com. Bank transfer also possible.

Have one fixed

Rule Fix Pack

USD 490fixed
USD 390 for MSPs and Wazuh partners
  • One silent rule or one mapping conflict
  • Written and tested on your exact Wazuh version, against the events you send
  • Files plus apply and rollback steps
  • You pay only after it fires on your cluster
Book a Fix Pack →

Invoiced by ATK, paid by bank transfer or PayPal. We never ask for write access to your systems.

Fix them yourself

Rule Doctor licence

USD 490/ cluster / year
  • Confirms or clears each shadow candidate by replaying real events on a throwaway manager of your version
  • Builds, verifies, applies and rolls back the mapper_parsing_exception fix
  • Every update for 12 months, email support
Buy a licence with PayPal →

Cards accepted through PayPal; an ATK invoice on request. 14-day refund.

Registered company

ATK New Technology One Member Company Limited, Hanoi · Tax ID 0110935486

Open source you can read

Rule Doctor Lite on GitHub and PyPI, Apache-2.0

Methods published

Every measurement is published with its method and limits; the research reports include the raw data

Plain terms

PayPal or bank transfer, ATK invoice, written refund policy

Install

Two minutes on the manager.

Run it on the Wazuh manager, or on a copy of /var/ossec. It reads rule files, ossec.log and the alerts files. Nothing is installed as a service and nothing leaves the machine.

Source on GitHub → PyPI →

One file
curl -sLO https://github.com/xuxu298/rule-doctor-lite/releases/latest/download/rule-doctor-lite.py
sudo python3 rule-doctor-lite.py
From PyPI
pipx install rule-doctor-lite
sudo "$(command -v rule-doctor-lite)"
01

Run Lite

One command on the manager. Add --days 30 for a longer window, --json report.json to keep the result.

02

Read the label

Each silent rule comes with its cause and the time window it was measured over. A rule for a quarterly event is not dead after a day.

03

Fix it, or send it

Every label has a fix note with a one-minute check. If you would rather not, send the JSON for a USD 49 review or book a Fix Pack.

Fix notes

The problems it points at, each with a one-minute check.

The licence in detail

What the full tool does that Lite cannot.

rule-doctor silent

Reads the custom rules on your manager and your recent alerts, and sorts the rules that never fired into three common causes: shadowed by a sibling rule that matches first, an event that never reaches the manager, or no event that matches it. Candidates for “shadowed” are confirmed by replaying real events through wazuh-logtest on a throwaway manager of your version, started and removed by the tool. Every result is printed with the time window it was measured over.

rule-doctor mapping

For mapper_parsing_exception caused by a field that is an object in some events and a string in others: builds the pipeline change and the index template from your current pipeline, verifies them against your sample alerts in an isolated index, applies them, and rolls them back byte-for-byte if you ask.

How you receive it

After checkout you receive the software (version 1.0.0, a single archive with a README) and your licence details by email within one business day. Updates during the licence term are sent the same way. A licence covers one Wazuh cluster (one manager cluster and its indexer) for 12 months.

Requirements and limits

Wazuh 4.x on Linux, Python 3, and Docker on the machine that runs the replay step. Read access to the manager’s rule files and alerts; the mapping fix needs an indexer account that can change index templates and ingest pipelines. Replay needs full_log in the alerts; Windows event-channel and JSON sources are not yet validated. A mapping fix takes effect from the next daily index. Version 1.0.0 does not yet detect rules dropped at load — Lite does.

Questions

Before you run it.

Does anything leave my manager?

Not with Lite: it reads local files and prints to your terminal, or to a JSON file if you ask. For a review or a Fix Pack, only the files you choose to email reach us.

Which Wazuh versions?

Wazuh 4.x rule syntax. Measured on a real 4.14.7 manager; 4.14.8 ships byte-identical rule-loading source files. Lite follows if_sid parents; if_group and if_matched_* parents are not followed yet.

My manager runs in Docker.

Copy the rule directories, ossec.log and the alerts file out of the container and point --ossec-dir at the copy. The exact commands are in the README.

Rotated or compressed alerts?

Lite reads rotated .gz alerts files inside the --days window (7 days by default), and takes load warnings from the latest load only.

How do I pay, and can I get an invoice?

PayPal (cards accepted) or bank transfer. ATK New Technology issues the invoice. A Fix Pack is invoiced only after the fix fires on your cluster.

Refunds?

The licence has a 14-day refund, no questions asked; the review is refunded if it finds nothing you can act on. See the refund policy.

Two minutes to know which rules are dead.

Run Lite on your manager. If the output raises more questions than it answers, a written review is USD 49 and comes back within one business day.

Sold by ATK New Technology One Member Company Limited, Hanoi, Vietnam. Terms · Refund policy · Privacy policy · dongnx@atkvn.com