How to check in one minute
grep -B3 'String limit reached' /var/ossec/logs/ossec.log | tail -n 20
The lines just before the warning name the module that was running, for example wazuh-modulesd:command: INFO: Starting command 'yourtag'. or the AWS, Azure or GCP module. Then measure how much that program prints in one run, outside Wazuh:
/path/to/the/command | wc -c
Anything above 67,108,864 bytes hits the limit.
Why it happens
In 4.14.7, src/wazuh_modules/wm_exec.c reads a child program's output into one string. The cap is WM_STRING_MAX, defined in wmodules.h as 67108864 (64 MB). When the next read would pass it, the reader logs String limit reached. and breaks out of the loop. The output collected so far is kept; the rest is never read. The Windows reader in the same file (around line 235, reading the pipe with ReadFile) has the same cap and prints the same warning.
The same execution path is used by modules that run an external program: the command wodle, and, from the source, the AWS, Azure and GCP modules and SCA commands.
We configured a command wodle whose script prints a first line, 70,000,000 bytes, then a last line:
| Measured (Wazuh 4.14.7) | Result |
|---|---|
ossec.log | wazuh-modulesd: WARNING: String limit reached. one second after the command started |
first line of the output in archives.log | present |
last line of the output in archives.log | missing |
Fix
The limit is a compile-time constant, not a setting, so the fix is on the producing side: make each run print less than 64 MB.
- Command wodle: run it more often over a smaller window (for example a time range per run), filter in the script, or drop fields you do not alert on.
- Or write to a file and read it with
<localfile>, which reads line by line instead of one string per run. Rotate the file. - Cloud modules: narrow what one run fetches (fewer services or buckets per module block, a shorter interval so each run covers less time).
After the change, run the program by hand and pipe it to wc -c again; stay well below the limit, since a busy day produces more than a quiet one.
Limits of what we measured
Measured with the command wodle only, on a Wazuh 4.14.7 manager container, with one run of about 70 MB. That the AWS, Azure, GCP and SCA paths share the limit comes from reading the source, not from a run. We did not measure the <localfile> alternative at this volume, or how each cloud module splits its work between runs.