The file limit set for this agent is 100000. Now, 100000 files are being monitored and no more files will be monitored. Change this setting in centralized configuration or locally on the agent.
Description
The file limit set for this agent is 100000. Now, 100000 files are being monitored and no more files will be monitored. Change this setting in centralized configuration or locally on the agent.
No license declared
socfortress/Wazuh-Rules publishes no license, and without an express grant the default is all rights reserved. The rule as written stays upstream, and this one matches no fields of its own to summarize.
Read the full rule at Exclusion Rules/900000-exclusion_rules.xml ↗. Why this rule is treated this way.
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=wazuh -
location=syscheck$ AND match="^wazuh: FIM DB:" -
233The maximum limit of files monitored has been reached. At this moment there are files and the limit is . From this moment some events can be lost. You can modify this setting in the centralized configuration or locally in the agent. · alert_type = full, fim_db_table = file_entry anchor level 12field alert_type="full" AND field fim_db_table="file_entry" -
900053The file limit set for this agent is 100000. Now, 100000 files are being monitored and no more files will be monitored. Change this setting in centralized configuration or locally on the agent. exclusion level 7 this ruleMatches no fields of its own.