What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
If an alert appears in /var/ossec/logs/alerts/alerts.json but not in the Wazuh dashboard, it was generated and written locally—but that does not prove the indexer accepted it. Follow the alert past the file, inspect the bulk API response and logs, then test whether the rejected document’s field structure conflicts with the index mapping. An HTTP 400 is a rejection, not a diagnosis.
Where the alert can disappear
Wazuh’s documented flow separates alert generation from indexing. The server analyzes endpoint events and generates alerts when they match detection rules. By default, it writes alert data to /var/ossec/logs/alerts/alerts.json and /var/ossec/logs/alerts/alerts.log, then forwards the JSON alert document from alerts.json to the Wazuh indexer API. The indexer stores accepted alerts in wazuh-alerts-* indices. See Wazuh indexer indices.
That makes the local JSON file a useful boundary in the investigation: finding the event there supports that alert generation and local writing occurred. It does not establish that forwarding or indexing succeeded.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWhat an HTTP 400 tells you—and what it does not
The indexer bulk API handles operations such as indexing, creating, updating, and deleting documents. Its reference classifies HTTP 400 as a bad request, but the status alone does not say why a request failed. Read the complete response body and correlate it with indexer logs and the document that was rejected. The response may identify a field, parsing or mapping issue, request-format problem, or another cause. See the bulk API reference.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Do not conclude that every 400 is a mapping conflict. A field-shape conflict is one testable possibility, not a universal explanation.
Test whether one field path has two shapes
A JSON path can appear as an object in one alert and as a scalar value in another. For example, a path represented as agent: { name: "host-a" } in one document is structurally different from agent: "host-a" in another. If the index mapping already expects one representation, the other may be incompatible. This example illustrates the shape difference; it is not evidence that agent is the field causing a particular failure.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
- Capture the affected alert. Find it in
alerts.jsonand record its timestamp, alert ID, and relevant JSON structure. - Find the failed indexing attempt. Check the Wazuh server/Filebeat or connector logs, as applicable to your installation, and the indexer logs around the same time. Preserve the full error response and identify the rejected document if available.
- Read the response, not just the status. Note any named field path, parser or mapping detail, and request-format information. A 400 by itself does not establish a field conflict.
- Compare documents and mappings. Compare the rejected alert with an accepted alert using the same path. Inspect the current index mapping and the applicable template to determine the intended field type and whether the path is represented consistently. The mapping API reference describes field types and dynamic-mapping choices.
- Make a change that matches the evidence. If the source alternates between object and scalar, correct the upstream data shape or adjust the intended template as appropriate. If the index already has an incompatible mapping, plan for a new index and reindexing rather than expecting an in-place mapping change to rewrite existing data.
- Verify the outcome. Check that new alerts index successfully, then confirm the dashboard’s index pattern and time range include the resulting documents.
A Wazuh community discussion describes mapping conflicts in alert and archive indices, but it is supporting context—not proof that a conflict explains your 400 or a universal repair procedure: Wazuh community discussion.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsWhy changing a mapping may require a new index
Mappings define how indexed fields are represented and typed. The mapping reference explains that mapping updates cannot modify mappings already applied to existing data. If an existing index has the wrong mapping, Wazuh documents creating a new index with the desired mapping and reindexing the old documents. See Wazuh indexer indices and the mapping API reference.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Plan that change against the actual index state and your retention needs. Do not delete old indices as a casual workaround; preserve required data and follow your site’s change and retention procedures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Check connector and queue evidence separately
Wazuh’s connector documentation describes an in-memory queue, retries for selected transient failures, and possible event drops when the queue overflows. The exact behavior depends on version and configuration; it does not establish that a particular HTTP 400 followed this path. Check the connector documentation and logs for the installed release, and look for queue-related evidence rather than assuming retry or drop behavior. The available connector reference is on Wazuh’s main branch: Wazuh indexer connector README.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Use the evidence to choose the next step
| Evidence | What it supports | What to check next |
|---|---|---|
The alert is present in alerts.json. |
Alert generation and local file writing occurred. | Find the corresponding forwarding attempt, response, and indexer log entry. |
| The bulk response identifies a field or mapping error. | The response gives a specific lead; it still needs to be matched against the source document and current mapping. | Compare rejected and accepted JSON for that path, then inspect the mapping and template. |
| The response reports a different request or parsing problem. | The 400 may have a cause other than a mapping conflict. | Follow the named error and examine the full request/response context. |
| Connector logs show retries or queue overflow. | Connector behavior may be relevant to delivery or dropped events. | Check the installed version’s behavior and configuration, and correlate logs with the alert time. |
Wazuh documentation pages and the connector README may not describe behavior identically for every installed release. Confirm your Wazuh version, connector configuration, templates, current index mapping, and the actual error before changing production index state.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

