Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A successful exit from /var/ossec/bin/wazuh-analysisd -t does not prove that every custom rule dependency loaded. If the rule uses if_sid, look for warnings 7617 and 7619: they can indicate that the parent rule was unavailable and the dependent rule was ignored. A filename-order problem is one possible cause. Confirm it from your own test output and manager log, then use wazuh-logtest to see whether the intended rule ID matches your event.

Why can analysisd -t exit 0 when a rule is missing?

Wazuh documents wazuh-analysisd -t as a configuration test. A zero exit status alone is not a guarantee that a rule referencing another rule is usable. Read the command’s standard output and standard error, and check /var/ossec/logs/ossec.log for dependency warnings. The wazuh-analysisd reference describes the test option; it does not say that exit status 0 validates every dependent rule.

What warnings 7617 and 7619 mean

  • 7617: a referenced signature ID was not found.
  • 7619: the resulting rule has an empty if_sid dependency and is ignored.

These warnings point toward a missing parent rule, rather than proving that the custom rule loaded correctly. Wazuh issue reports document dependent rules being skipped when the referenced signature is unavailable: see Wazuh issue 20146 and Wazuh documentation issue 8719.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How file names can affect dependent rules

Rules are processed in file order. When a child rule refers to a parent using if_sid, a child processed before its parent may encounter an unavailable dependency and be ignored. Check that the parent exists, is enabled, and is loaded before the child. For the reported split-file case, the Wazuh documentation issue recommends keeping related parent and child rules together in dependency order.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

A title-matching article reports 168 stock rule files beginning with digits in Wazuh 4.14.7 and shows how a custom filename can sort before a stock file. Treat that inventory and its filename examples as specific to that release, not as a rule for every Wazuh installation. The underlying diagnosis is plausible when the warnings identify a missing parent, but verify the ordering on your installed version.

Troubleshoot the rule in order

  1. Record your version and rule paths. Identify the Wazuh version and where the parent and child definitions are stored. Do not assume the stock-file ordering reported for 4.14.7 applies to your release.
  2. Run the configuration test and inspect its output. Use /var/ossec/bin/wazuh-analysisd -t. Read both standard output and standard error; do not rely only on $?.
  3. Search the manager log for dependency warnings. On a standard installation, run grep -E '((7617|7619))' /var/ossec/logs/ossec.log. Adapt the path if your deployment uses a different log location.
  4. Trace each missing signature. For every 7617 message, find the referenced parent ID and locate both rule definitions. Check whether the child file is processed first and whether the parent is enabled and loaded. Arrange dependent rules so the parent is available before the child; where practical, keep related definitions together in sequence.
  5. Rerun the test. Confirm that the dependency warnings have disappeared before testing whether the event matches.
  6. Test a representative event. Run /var/ossec/bin/wazuh-logtest and submit the actual one-line log event. Inspect Phase 3 and verify that its final rule ID is the intended custom child rule—not merely a parent or default rule. Wazuh documents wazuh-logtest as its tool for testing rules and decoders in the custom rules guide.
  7. Activate the change for production. After editing rule files, restart wazuh-manager before expecting production alerts. A logtest match validates the test event; it does not by itself show that the running manager has activated the change.

Put custom rules in the supported location

For minor changes, Wazuh recommends /var/ossec/etc/rules/local_rules.xml. For larger custom rule sets, use separate files under /var/ossec/etc/rules/. Avoid putting custom files in /var/ossec/ruleset/, which is managed as part of the ruleset and can be affected by upgrades. See Wazuh’s custom rules instructions and ruleset directory layout.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Check custom rule IDs and overrides

Wazuh recommends IDs in the 100000–120000 range for custom rules. To override an existing rule, copy it into the custom rules directory and set overwrite="yes". An overwrite cannot change certain dependency labels, including if_sid; if the dependency itself needs to change, an overwrite may not achieve that. The custom rules guide documents these ID and overwrite constraints.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Distinguish loading, matching, and alerting

  • Loaded: the rule definition and its dependencies are available without the missing-parent warnings.
  • Matched: wazuh-logtest decodes the representative event as expected and Phase 3 reports the intended rule ID.
  • Alerted: after the manager has been restarted to activate the edit, the live deployment generates the expected alert.

These are separate checks. A rule that is ignored at dependency-loading time cannot match; a loaded rule can still fail its conditions; and a successful logtest does not alone demonstrate that production generated an alert.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Version-specific evidence

The filename-order inventory described above is specific to Wazuh 4.14.7. A separate Wazuh GitHub issue, opened on November 8, 2023, reports missing if_sid references in a v4.5.2 setup; a Wazuh documentation issue dated July 23, 2025, describes dependent rules being skipped when referenced rules are not found. Those reports support checking dependencies, but they do not establish that every release sorts every rules file in the same way. Use your own warnings, paths, and test results to establish the cause on your installation.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.