Skip to main content

Knowledge

Knowledge entries are short notes a team writes about its own estate. A firewall that silently drops everything except the manager ports, a backup job that can fill a disk, a host that must never be restarted during trading hours. The agent reads every matching entry at the start of each run, so it works from what the team already knows instead of rediscovering it, or never discovering it at all. The Knowledge page opens with a searchable table of scopes, one row for the whole organization and one per environment, each with its entry count. Opening a scope shows its entries, searchable by title, and everyone on the team can read what the agent is being told.

What the agent does with an entry​

Entries are handed to the agent as facts about the environment, never as instructions. They inform how it diagnoses and what it recommends, and they cannot widen what a run is allowed to do. A run started as look only still has no way to execute a command, whatever an entry says, and a command in manual mode still waits for an operator's approval.

Writing entries​

Admins create, edit and retire entries. Members read them. Each entry has a title of up to 200 characters and a note of up to 2000, stored and shown as plain text. A workspace can hold up to 100 active entries.

Write an entry the way a new engineer would be briefed. State what is true about the estate that the agent cannot discover on its own, and keep one entry to one fact so it can be retired on its own when it stops being true.

Scope​

Every entry applies either to the whole organization or to one environment.

ScopeThe agent reads it on
OrganizationEvery run, in every environment.
EnvironmentRuns against that environment only.

Scope is chosen when the entry is created and cannot be changed afterwards. To move a note, retire it and write it again in the other scope.

Expiry​

An entry can carry an optional expiry date. From that moment the agent no longer reads it, while the entry stays listed and editable so the team can still see what it said. Extending or clearing the date hands it back to the agent. The date must be in the future. To end an entry immediately, retire it instead.

Retire and restore​

Retiring an entry takes it away from the agent on its next run without deleting what was written. Retired entries stay listed behind the Show retired filter, and an admin can restore one, which counts against the 100-entry limit like creating one. Restoring does not clear an expiry date: a restored entry that has already expired stays out of the agent's runs until the date is extended or cleared.

Knowledge entries and Vesper's procedures​

A knowledge entry is a fact about one estate, written by its team. The troubleshooting procedures the agent follows are a different thing: written and reviewed by Vesper's team, the same for every customer, and about Wazuh rather than about any one deployment. An entry can say which host must not be restarted. A procedure says which checks diagnose a manager that will not start. The agent reads both at the start of a run and treats both as material to reason from, never as permission to act. Procedures are not listed or edited in the console. See the agent.