How to check in one minute
1. Does the indexer have inventory for that agent? On a host that can reach the indexer (replace the agent ID and credentials):
for ix in hardware system packages; do
printf "%s: " $ix
curl -sk -u USER:PASS "https://INDEXER:9200/wazuh-states-inventory-$ix-*/_count?q=agent.id:008"; echo
done
"count":0 for both hardware and system is exactly the state that produces the message.
2. Is syscollector running on the agent? On the agent:
grep syscollector /var/ossec/logs/ossec.log | tail -n 3
Module disabled. Exiting... means it is off. Evaluation finished. means it ran; if the indexer still has nothing, look at the manager side (step 3 below).
Why it happens
In wazuh-dashboard-plugins 4.14.7, syscollector-metrics.tsx fetches the first document for the agent from the hardware and system inventory data sources (the wazuh-states-inventory-hardware-* and wazuh-states-inventory-system-* indices) and renders this text when both come back empty. Those documents are produced by the agent's syscollector module and indexed by the manager.
| Measured on a Wazuh 4.14.7 stack | Inventory documents for the agent |
|---|---|
new agent enrolled with <wodle name="syscollector"><disabled>yes, active for over a minute | hardware 0 · system 0 · packages 0 |
same agent, disabled set to no, agent restarted | hardware 1 · system 1 · packages 82, about 10 s later |
On the same stack, the manager itself (agent 000) had no hardware or system document although its own syscollector block was enabled; agents 001–007 all had one.
Fix
1. Enable syscollector on the agent, in its ossec.conf or in the group's agent.conf:
<wodle name="syscollector">
<disabled>no</disabled>
<interval>1h</interval>
<scan_on_start>yes</scan_on_start>
<hardware>yes</hardware>
<os>yes</os>
<packages>yes</packages>
</wodle>
Restart the agent. With scan_on_start the first inventory goes out right away; without it, wait for the interval.
2. Check hardware and os are not set to no inside an otherwise enabled block: the message needs both to be empty, but either one missing leaves part of the panel blank.
3. If the agent reports and the indexer stays empty, the problem is between the manager and the indexer (the manager's indexer connection settings or certificates), and it would affect every agent, not one. We did not reproduce that case.
Limits of what we measured
Measured on our Wazuh 4.14.7 lab stack (manager, indexer, dashboard and one temporary agent, all containers). We measured the indexer documents, not the rendered page: that the dashboard shows this text when both are empty comes from reading syscollector-metrics.tsx at 4.14.7. We did not test Windows or macOS agents, the manager-to-indexer failure case, or other versions. The temporary agent was removed afterwards.