Wazuh fix note · system inventory

Not enough hardware or operating system information

This is a dashboard message, not a manager error. In Wazuh 4.14.7 the agent page shows it when the agent has no document in the hardware inventory index and none in the operating-system inventory index. The usual reason is that the agent's system inventory module, syscollector, is disabled or has never reported. We reproduced the empty state on a 4.14.7 stack and filled it in about 10 seconds by enabling the module.

Dong Nguyen, ATK New Technology · 2 October 2026 · measured on Wazuh 4.14.7 (manager, indexer, dashboard and agent containers)

Stuck on this right now? Email your custom rules or decoders, one sample log line and your Wazuh version to dongnx@atkvn.com. We run them on that exact version and reply within 24 hours with what we find. Free. Remove hostnames, IPs and usernames first. Rather not send them? Run the free pre-check in your browser; your files never leave your machine. Rather have it fixed? USD 149 fixed price per problem, reproduced on your version, and you pay only after it works on your system. Our first three customers pay USD 49 for one fix, in exchange for an anonymised write-up we can publish.


How to check in one minute

1. Does the indexer have inventory for that agent? On a host that can reach the indexer (replace the agent ID and credentials):

for ix in hardware system packages; do
  printf "%s: " $ix
  curl -sk -u USER:PASS "https://INDEXER:9200/wazuh-states-inventory-$ix-*/_count?q=agent.id:008"; echo
done

"count":0 for both hardware and system is exactly the state that produces the message.

2. Is syscollector running on the agent? On the agent:

grep syscollector /var/ossec/logs/ossec.log | tail -n 3

Module disabled. Exiting... means it is off. Evaluation finished. means it ran; if the indexer still has nothing, look at the manager side (step 3 below).

Why it happens

In wazuh-dashboard-plugins 4.14.7, syscollector-metrics.tsx fetches the first document for the agent from the hardware and system inventory data sources (the wazuh-states-inventory-hardware-* and wazuh-states-inventory-system-* indices) and renders this text when both come back empty. Those documents are produced by the agent's syscollector module and indexed by the manager.

Measured on a Wazuh 4.14.7 stackInventory documents for the agent
new agent enrolled with <wodle name="syscollector"><disabled>yes, active for over a minutehardware 0 · system 0 · packages 0
same agent, disabled set to no, agent restartedhardware 1 · system 1 · packages 82, about 10 s later

On the same stack, the manager itself (agent 000) had no hardware or system document although its own syscollector block was enabled; agents 001–007 all had one.

Fix

1. Enable syscollector on the agent, in its ossec.conf or in the group's agent.conf:

<wodle name="syscollector">
  <disabled>no</disabled>
  <interval>1h</interval>
  <scan_on_start>yes</scan_on_start>
  <hardware>yes</hardware>
  <os>yes</os>
  <packages>yes</packages>
</wodle>

Restart the agent. With scan_on_start the first inventory goes out right away; without it, wait for the interval.

2. Check hardware and os are not set to no inside an otherwise enabled block: the message needs both to be empty, but either one missing leaves part of the panel blank.

3. If the agent reports and the indexer stays empty, the problem is between the manager and the indexer (the manager's indexer connection settings or certificates), and it would affect every agent, not one. We did not reproduce that case.

Limits of what we measured

Measured on our Wazuh 4.14.7 lab stack (manager, indexer, dashboard and one temporary agent, all containers). We measured the indexer documents, not the rendered page: that the dashboard shows this text when both are empty comes from reading syscollector-metrics.tsx at 4.14.7. We did not test Windows or macOS agents, the manager-to-indexer failure case, or other versions. The temporary agent was removed afterwards.

Have it working

Inventory still empty? Send the agent's syscollector block, the last syscollector lines from its ossec.log and your Wazuh version to dongnx@atkvn.com. We reproduce it on that exact version and reply within 24 hours with what we find. Free. Rather have it fixed for you? USD 149 fixed price per problem, paid after it works on your system.