Use your real file names: Wazuh loads stock and custom rule files together in file-name order, so the name decides what exists when each rule loads. Rules go in etc/rules, decoders in etc/decoders; one box per file.
What it checks
| Finding | What Wazuh 4.14.7 does | Wazuh message |
|---|---|---|
<field name="srcip"> or any of the 17 static fields | rejects the file, manager does not start | Field 'srcip' is static + CRITICAL (1220) |
| XML not well formed | rejects the file, manager does not start | (1226) … XMLERR |
decoder <parent> that does not exist | configuration error, manager does not start | (2101) Parent decoder name invalid |
if_sid pointing at an ID that is missing, or defined only later in the load order | drops that ID; if none is left, ignores the rule | (7617), (7619) |
if_matched_sid missing | ignores the rule | (7620) |
if_group no loaded rule has | ignores the rule | (7610) |
rule ID already loaded, no overwrite="yes" | keeps the first, ignores yours | (7612) |
overwrite="yes" on an ID that does not exist | loads it as a new rule | (7613) |
How we checked it
Every finding above was produced first by the real wazuh-analysisd -t 4.14.7 on a test file, then predicted by this page from the same file. 15 test cases, 15 matches, including how if_group matches (case-insensitive substring, | alternatives, ^ anchor). On a public community pack of 69 rule files and 6 decoder files, Wazuh printed 52 load warnings of these kinds; this page found the same 52, plus 3 more.
The 3 were real. wazuh-analysisd keeps only the last 50 load messages (ERRORLIST_MAXSIZE 50 in src/analysisd/logmsg.h, oldest dropped first), so on a large pack some ignored rules never show up in -t or ossec.log. This page lists all of them.
Limits
It knows only the files you paste and the stock 4.14.7 ruleset (rule IDs, file names, groups, decoder names). Rules in files you did not paste are invisible to it. It does not run Wazuh: it does not test regex syntax, decoder field extraction, CDB lists, rule matching on real events, or whether a rule ever fires. if_group is matched like Wazuh does, as a case-insensitive substring of a loaded rule's groups; stock groups are treated as always loaded. Checks for Wazuh 5.0 are not in this version. To check what your rules do on real events, use the free file check below.