{
  "id": 12536684,
  "title": "Wazuh FIM \"not detecting\" a changed file usually means it has not looked yet",
  "url": "https://urgent.news/2026/10/07/wazuh-fim-not-detecting-a-changed-file-usually-means-it-has-not",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T03:46:49.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/xuxu298/wazuh-fim-not-detecting-a-changed-file-usually-means-it-has-not-looked-yet-5d1a"
  },
  "original_language": "en",
  "account": "When you add a directory to Wazuh file integrity monitoring and then change a file within it, the system typically waits for the next scheduled scan before reporting the change. On Wazuh 4.14.7, the default scan frequency is 12 hours. This delay occurs because the system only records a baseline during the initial scan. If a file is altered after the first scan, it will only be detected in the subsequent scheduled scan, provided 12 hours have passed. Testing confirmed that a file change detected within seconds of the initial scan in a plain directory, but not in a directory with real-time monitoring due to the 12-hour interval. To adjust the monitoring, increase the frequency for specific paths to real-time, which allows for immediate detection of file changes. Simply modifying the configuration in the agent.conf file to include \"syscheck directories realtime= yes\" in the desired directories will enable real-time monitoring. However, real-time monitoring should be applied sparingly to avoid generating excessive alerts, particularly on large or frequently changing directories.",
  "summary": "You add a directory to Wazuh file integrity monitoring, change a file, and nothing happens. On Wazuh 4.14.7 the usual reason is the schedule, not a bug. We measured it on a manager container. The defaults The <syscheck> block in the 4.14.7 manager image's default ossec.conf : <frequency> 43200 </frequency> <scan_on_start> yes </scan_on_start> <alert_new_files> yes </alert_new_files> <directories>…",
  "key_points": [
    "Wazuh FIM typically waits 12 hours for file change detection",
    "Real-time monitoring enables immediate file change detection",
    "Adjust agent.conf to enable realtime= yes for specific directories"
  ],
  "editors_take": "Tweaking Wazuh's configuration to increase scan frequency for specific paths can help reduce detection delays, but applying real-time monitoring broadly may overwhelm the system with excessive alerts.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}