Wazuh fix note · wazuh-modulesd

wazuh-modulesd: String limit reached

A Wazuh module ran an external program and the program printed more than 64 MB in one run. wazuh-modulesd stops reading at that point, logs this warning, and drops everything after it. Nothing fails loudly: you get the first part of the output and lose the rest. We reproduced it on Wazuh 4.14.7.

Dong Nguyen, ATK New Technology · 2 October 2026 · measured on Wazuh 4.14.7 (manager container)

Stuck on this right now? Email your custom rules or decoders, one sample log line and your Wazuh version to dongnx@atkvn.com. We run them on that exact version and reply within 24 hours with what we find. Free. Remove hostnames, IPs and usernames first. Rather not send them? Run the free pre-check in your browser; your files never leave your machine. Rather have it fixed? USD 149 fixed price per problem, reproduced on your version, and you pay only after it works on your system. Our first three customers pay USD 49 for one fix, in exchange for an anonymised write-up we can publish.


How to check in one minute

grep -B3 'String limit reached' /var/ossec/logs/ossec.log | tail -n 20

The lines just before the warning name the module that was running, for example wazuh-modulesd:command: INFO: Starting command 'yourtag'. or the AWS, Azure or GCP module. Then measure how much that program prints in one run, outside Wazuh:

/path/to/the/command | wc -c

Anything above 67,108,864 bytes hits the limit.

Why it happens

In 4.14.7, src/wazuh_modules/wm_exec.c reads a child program's output into one string. The cap is WM_STRING_MAX, defined in wmodules.h as 67108864 (64 MB). When the next read would pass it, the reader logs String limit reached. and breaks out of the loop. The output collected so far is kept; the rest is never read. The Windows reader in the same file (around line 235, reading the pipe with ReadFile) has the same cap and prints the same warning.

The same execution path is used by modules that run an external program: the command wodle, and, from the source, the AWS, Azure and GCP modules and SCA commands.

We configured a command wodle whose script prints a first line, 70,000,000 bytes, then a last line:

Measured (Wazuh 4.14.7)Result
ossec.logwazuh-modulesd: WARNING: String limit reached. one second after the command started
first line of the output in archives.logpresent
last line of the output in archives.logmissing

Fix

The limit is a compile-time constant, not a setting, so the fix is on the producing side: make each run print less than 64 MB.

After the change, run the program by hand and pipe it to wc -c again; stay well below the limit, since a busy day produces more than a quiet one.

Limits of what we measured

Measured with the command wodle only, on a Wazuh 4.14.7 manager container, with one run of about 70 MB. That the AWS, Azure, GCP and SCA paths share the limit comes from reading the source, not from a run. We did not measure the <localfile> alternative at this volume, or how each cloud module splits its work between runs.

Have it working

Losing events to this limit? Send the module block from your ossec.conf and your Wazuh version to dongnx@atkvn.com. We reproduce it on that exact version and reply within 24 hours with what we find. Free. Rather have it fixed for you? USD 149 fixed price per problem, paid after it works on your system.