Software · pricing

ATK Rule Doctor for Wazuh.

A command-line tool you run on your own infrastructure. It tells you why a Wazuh rule stays silent, and it fixes alerts that never reach the indexer because a field changes shape. Nothing is sent to us.


Price

USD 490 per Wazuh cluster, per year.
Includes every update released during the year and support by email. Paid by PayPal (cards accepted); an ATK invoice on request.

Buy a licence with PayPal →

Try the free lite version first

ATK Rule Doctor Lite lists every custom rule that never fired and the likely reason, including rules Wazuh throws away while loading them (warnings 7617/7619 in ossec.log, while wazuh-analysisd -t still exits 0). One Python file, read-only, nothing sent anywhere, Apache-2.0. Tested on a real Wazuh 4.14.7 manager.

curl -sO https://raw.githubusercontent.com/xuxu298/rule-doctor-lite/main/rule-doctor-lite.py
sudo python3 rule-doctor-lite.py

Rule Doctor Lite on GitHub →

The paid version adds what the lite one cannot do: it replays the real events behind each shadow candidate through a throwaway manager of your version, and it builds and verifies the mapping fix.

Step-by-step notes for the problems it points at, each with a one-minute check: rule dropped at load (7617/7619) · passes logtest, never fires · shadowed by a sibling rule · mapper_parsing_exception · Cannot read 'srcip' from data · <hostname> and agent events.

Not sure what the output means? Silent Rule Review, USD 49

Run Lite with --json report.json and send us that file with your etc/rules/*.xml. Within one business day you get a written review of every silent rule: the cause, the exact change, and which ones you can fix yourself. Paid up front by PayPal or bank transfer. If you order a Fix Pack within 30 days, the USD 49 comes off its price. If the review finds nothing you can act on, you get the USD 49 back.

Pay USD 49 with PayPal →

Then email the JSON and your rules to dongnx@atkvn.com. The review starts when both have arrived.

Or have it fixed for you

Rule Fix Pack, USD 490 fixed (USD 390 for MSPs and Wazuh partners). One silent rule or one mapping conflict: I write and test the fix on your exact Wazuh version against the events you send, deliver the files with apply and rollback steps, and you pay only after it fires on your cluster. Invoiced by ATK, paid by bank transfer or PayPal.

Book a Fix Pack →

What you get

  1. rule-doctor silent — reads the custom rules on your manager and your recent alerts, and sorts the rules that never fired into three common causes: shadowed by a sibling rule that matches first, an event that never reaches the manager, or no event that matches it. Candidates for “shadowed” are confirmed by replaying real events through wazuh-logtest on a throwaway manager of your version, started and removed by the tool. Every result is printed with the time window it was measured over.
  2. rule-doctor mapping — for mapper_parsing_exception caused by a field that is an object in some events and a string in others: builds the pipeline change and the index template from your current pipeline, verifies them against your sample alerts in an isolated index, applies them, and rolls them back byte-for-byte if you ask.
  3. A licence for one Wazuh cluster (one manager cluster and its indexer) for 12 months.

How you receive it

After checkout you receive the software (version 1.0.0, a single archive with a README) and your licence details by email within one business day. Updates during the licence term are sent the same way.

Requirements and limits

  1. Wazuh 4.x on Linux, Python 3, and Docker on the machine that runs the replay step.
  2. Read access to the manager’s rule files and alerts. The mapping fix needs an indexer account that can change index templates and ingest pipelines.
  3. Replay needs full_log in the alerts. Windows event-channel and JSON sources are not yet validated.
  4. A mapping fix takes effect from the next daily index; the current day’s index keeps its mapping.
  5. A fourth cause is not detected yet: rules that Wazuh drops while loading (for example a child rule loaded before its parent). The manager still starts, so check ossec.log for “will be ignored”.

Refunds

14 days, no questions asked. See the refund policy.


Sold by ATK New Technology One Member Company Limited, Hanoi, Vietnam. Terms · Refund policy · Privacy policy · dongnx@atkvn.com