Free tool · runs in your browser

Wazuh rule pre-check

Paste your custom rule and decoder files. The page tells you what wazuh-analysisd 4.14.7 will warn about when it loads them: rules it will ignore because a parent is missing or loads later, duplicate IDs, and the mistakes that stop the manager from starting. Your files never leave this page.

ATK New Technology · version · checked against Wazuh 4.14.7 (see how we checked it) · Source & CLI/MCP: github.com/xuxu298/wazuh-rule-precheck


Use your real file names: Wazuh loads stock and custom rule files together in file-name order, so the name decides what exists when each rule loads. Rules go in etc/rules, decoders in etc/decoders; one box per file.

Nothing is uploaded. The check runs in this tab.

What it checks

FindingWhat Wazuh 4.14.7 doesWazuh message
<field name="srcip"> or any of the 17 static fieldsrejects the file, manager does not startField 'srcip' is static + CRITICAL (1220)
XML not well formedrejects the file, manager does not start(1226) … XMLERR
decoder <parent> that does not existconfiguration error, manager does not start(2101) Parent decoder name invalid
if_sid pointing at an ID that is missing, or defined only later in the load orderdrops that ID; if none is left, ignores the rule(7617), (7619)
if_matched_sid missingignores the rule(7620)
if_group no loaded rule hasignores the rule(7610)
rule ID already loaded, no overwrite="yes"keeps the first, ignores yours(7612)
overwrite="yes" on an ID that does not existloads it as a new rule(7613)

How we checked it

Every finding above was produced first by the real wazuh-analysisd -t 4.14.7 on a test file, then predicted by this page from the same file. 15 test cases, 15 matches, including how if_group matches (case-insensitive substring, | alternatives, ^ anchor). On a public community pack of 69 rule files and 6 decoder files, Wazuh printed 52 load warnings of these kinds; this page found the same 52, plus 3 more.

The 3 were real. wazuh-analysisd keeps only the last 50 load messages (ERRORLIST_MAXSIZE 50 in src/analysisd/logmsg.h, oldest dropped first), so on a large pack some ignored rules never show up in -t or ossec.log. This page lists all of them.

Limits

It knows only the files you paste and the stock 4.14.7 ruleset (rule IDs, file names, groups, decoder names). Rules in files you did not paste are invisible to it. It does not run Wazuh: it does not test regex syntax, decoder field extraction, CDB lists, rule matching on real events, or whether a rule ever fires. if_group is matched like Wazuh does, as a case-insensitive substring of a loaded rule's groups; stock groups are treated as always loaded. Checks for Wazuh 5.0 are not in this version. To check what your rules do on real events, use the free file check below.

Next step

Want it run on the real thing? Email your rules or decoders, a few sample log lines and your Wazuh version to dongnx@atkvn.com. We load them into that exact Wazuh version, run them against your lines, and reply within 24 hours. Free. Rather have it fixed? USD 149 fixed price per problem, paid after it works on your system. Our first three customers pay USD 49 for one fix, in exchange for an anonymised write-up we can publish.