Wazuh indices

The Wazuh indexer stores data using data streams and stateful indices.

Data streams handle continuously generated, time-based data such as events, findings, active response requests, and operational metrics. Each data stream writes to a sequence of backing indices, which Wazuh rolls over and retains according to its lifecycle policy. Wazuh automatically manages data streams using rollover and retention policies to maintain consistent performance as data volume grows.

Stateful indices store the latest known state of monitored endpoints, including inventory, vulnerability, and security-configuration assessment data.

Data streams

A data stream is a logical collection of backing indices that stores continuously generated, time-based data. Wazuh writes data to the stream name while managing the underlying backing indices automatically. Backing indices are the individual indices that sit behind a data stream and hold its actual data.

Each data stream is associated with an index template that defines its mappings and settings and applies its rollover and retention policy.

The following table lists the Wazuh data streams and the type of information each stores:

Data stream

Description

wazuh-events-raw-v5

Stores incoming events before processing and normalization.

wazuh-events-v5-<category>

Stores normalized and categorized events using the Wazuh Common Schema (WCS).

wazuh-events-v5-unclassified

Stores events that could not be assigned to a category.

wazuh-findings-v5-<category>

Stores findings generated when Security Analytics detectors match Sigma rules.

wazuh-active-responses

Stores active response execution requests.

wazuh-metrics-agents

Stores operational metrics for monitored endpoints.

wazuh-metrics-comms

Stores communication and performance metrics for the Wazuh manager.

Event data streams

Events collected from monitored endpoints pass through several stages before becoming searchable security data.

When an event arrives, Wazuh indexer stores the original event in the raw events data stream. The event is then normalized according to the Wazuh Common Schema and routed to the appropriate category-specific data stream. Events that cannot be categorized are stored in the unclassified data stream for further analysis. The event data streams are wazuh-events-raw-v5, wazuh-events-v5-<category>, and wazuh-events-v5-unclassified.

Findings data streams

The Security Analytics module stores detector findings in category-specific findings data streams.

A finding is generated when an event matches a Sigma detection rule. Each finding contains the detection result, the triggering event, rule metadata, and investigation information such as case status, analyst comments, and tags. Findings are stored using the wazuh-findings-v5-<category> index pattern.

Active response data stream

The active response data stream stores response execution requests generated by Wazuh.

When a rule triggers an active response action, Wazuh creates a document describing the action to perform. The Wazuh manager then reads these documents and distributes the actions to the correct agents.

Each document contains information about:

  • The event that triggered the response.

  • The configured response action.

  • The target agent or agents.

  • Execution parameters and response state.

  • Agent and cluster metadata.

This provides a complete audit trail linking response actions to the events that generated them. The template for this data stream is stored at templates/streams/active-responses.json. It matches the wazuh-active-responses* index pattern, uses wazuh-active-responses as its rollover alias, and is set to priority 1. Its fields follow the Wazuh Common Schema with the following fields included:

Field

Description

@timestamp

When the document was added to the wazuh-active-responses* index (at indexing time).

event.doc_id

Document ID of the matched alert that triggered the active response.

event.index

Source index of the matched alert that triggered the active response.

wazuh.active_response.name

Name of the active response configured in the channel.

wazuh.active_response.executable

Executable configured in the active response channel.

wazuh.active_response.extra_arguments

Arguments configured in the channel.

wazuh.active_response.location

Where to execute the response: local, defined-agent, or all.

wazuh.active_response.agent_id

Agent configured in the channel.

wazuh.active_response.type

Response type: stateless or stateful.

wazuh.active_response.stateful_timeout

Seconds configured in the channel for a stateful response.

wazuh.agent.*

Agent metadata.

wazuh.cluster.*

Cluster information.

wazuh.space.name

Wazuh space or tenant information.

Stateful indices

Stateful indices store information that changes over time and reflects the current state of monitored endpoints.

Unlike data streams, stateful information is continuously updated as the monitored environment changes.

The following stateful indices are available:

Index pattern

Description

wazuh-states-sca

Security Configuration Assessment results.

wazuh-states-fim-files

File Integrity Monitoring file metadata.

wazuh-states-fim-registry-keys

Monitored Windows registry keys.

wazuh-states-fim-registry-values

Monitored Windows registry values.

wazuh-states-vulnerabilities

Vulnerability assessment results.

wazuh-states-inventory-users

User account inventory.

wazuh-states-inventory-groups

Local group inventory.

wazuh-states-inventory-packages

Installed software inventory.

wazuh-states-inventory-processes

Running process inventory.

wazuh-states-inventory-services

Service inventory.

wazuh-states-inventory-ports

Open port inventory.

wazuh-states-inventory-networks

Network address inventory.

wazuh-states-inventory-interfaces

Network interface information.

wazuh-states-inventory-protocols

Routing and protocol information.

wazuh-states-inventory-hardware

Hardware inventory.

wazuh-states-inventory-system

Operating system and host information.

wazuh-states-inventory-hotfixes

Installed updates and hotfixes.

wazuh-states-inventory-browser-extensions

Browser extension inventory.

Data stream lifecycle

Wazuh automatically manages data stream growth through rollover and retention policies.

A rollover occurs when the active backing index reaches a configured size or document count threshold. After rollover, new documents are written to a new backing index while existing data remains searchable.

Retention policies determine how long data is preserved before it is deleted. This approach keeps storage consumption predictable while maintaining access to the data required for investigation, threat hunting, and compliance activities.

By default, Wazuh rolls over a data stream when either of the following limits is reached:

  • 20 GB primary shard size.

  • 200 million documents.

The default retention periods are shown below.

Data stream

Retention period

wazuh-events-raw-v5

10 minutes

wazuh-events-v5-*

1 hour

wazuh-findings-v5-*

90 days

wazuh-active-responses

3 days

The following diagram illustrates the lifecycle of a data stream:

Data stream lifecycle

Note

Data stream rollover and retention are managed automatically through Index State Management (ISM) policies. In most deployments, no manual intervention is required.

Each lifecycle policy moves an index through two stages during its lifetime. When an index is first created, it enters the active stage, where it accepts new data. It remains in this stage until one of the configured rollover conditions, such as age or size, is met. At that point, Wazuh creates a new active index, and the previous index stops accepting new data.

The previous index is retained until its configured retention period expires. It then enters the delete stage, where Wazuh permanently removes it. If the deletion fails, Wazuh automatically retries the operation up to three times with increasing delays between attempts.

The ISM policy below keeps matching indices in the hot state while they receive data. It rolls them over when they reach 200 million documents or a 20 GB primary shard size. After the configured retention period expires, the policy moves the index to the delete state and removes it. Failed actions are retried up to three times using exponential backoff.

{
  "policy": {
    "policy_id": "<index-name>-policy",
    "description": "<POLICY_DESCRIPTION>",
    "last_updated_time": <UNIX_TIMESTAMP_IN-MILLISECONDS>,
    "schema_version": 1,
    "default_state": "hot",
    "states": [
      {
        "name": "hot",
        "actions": [
          {
            "retry": {
              "count": 3,
              "backoff": "exponential",
              "delay": "1m"
            },
            "rollover": {
              "min_doc_count": 200000000,
              "min_primary_shard_size": "20gb"
            }
          }
        ],
        "transitions": [
          {
            "state_name": "delete",
            "conditions": {
              "min_index_age": "<RETENTION_TIME>"
            }
          }
        ]
      },
      {
        "name": "delete",
        "actions": [
          {
            "retry": {
              "count": 3,
              "backoff": "exponential",
              "delay": "1m"
            },
            "delete": {}
          }
        ],
        "transitions": []
      }
    ],
    "ism_template": [
      {
        "index_patterns": [
          "wazuh-<pattern>-*"
        ],
        "priority": <PRIORITY_INT>
      }
    ]
  }
}

Enabling unclassified events storage

Wazuh agent collects logs from endpoints and forwards them to the Wazuh manager. The Wazuh manager normalizes, decodes, and enriches events and sends them to the Wazuh indexer for rule matching, indexing, and security analytics. The Wazuh dashboard allows teams to view and investigate findings, search historical events, and manage the platform. Events that match detection rules generate findings. Events that cannot be decoded or classified are stored in the wazuh-events-v5-unclassified index when unclassified event indexing is enabled for the relevant space.

Unclassified event indexing is configured per space. You can enable unclassified event indexing in the Draft or Standard space. Follow the steps below to enable the storage of unclassified events:

  1. Navigate to the Security Analytics dashboard, select the space you want to enable unclassified events for, click the Actions drop-down menu, and select Edit:

    Edit a Security Analytics space
  2. Toggle on Index unclassified events, and click Save:

    Enable Index unclassified events

Verifying index templates

Index templates define the mappings, settings, and lifecycle policies applied to Wazuh indices and data streams.

To verify that the Wazuh templates are installed, query the Wazuh indexer from the Wazuh dashboard. Navigate to Indexer management > Dev Tools and run the query below:

GET /_index_template/wazuh-*

The response lists all deployed Wazuh index templates and the index patterns associated with each template.

{
  "index_templates": [
    {
      "name": "wazuh-findings-v5-network-activity-template",
      "index_template": {
        "index_patterns": [
          "wazuh-findings-v5-network-activity*"
        ],
        "template": {
          "settings": {
            "index": {
              "codec": "zstd",
              "mapping": {
                "nested_fields": {
                  "limit": "50"
                },
                "total_fields": {
                  "limit": "1000"
                }
              },
              "refresh_interval": "2s",
              "number_of_shards": "1",
              "auto_expand_replicas": "0-1",
              "plugins": {
                "index_state_management": {
                  "policy_id": "stream-findings-policy"
                }
              },
              "max_docvalue_fields_search": "200",
              "query": {
                "default_field": [
                  "agent.host.architecture",
                  "agent.host.ip",
                  "agent.id",
                  "agent.name",
                  "agent.version",
                  "wazuh.cluster.name",
                  "wazuh.cluster.node",
                  "wazuh.schema.version"
                ]
              },
              "number_of_replicas": "0"
            }
          }
        }
      }
    }
    ...