Reading answers
Vesper's answers are deliberately structured and deliberately sourced. This page explains how to read one critically.
What Vesper answers
Vesper answers questions about Wazuh: installing it, configuring it, and troubleshooting the manager, the indexer, the dashboard, the agents and the ruleset. A question about anything else, such as unrelated code or a general topic, gets a single sentence saying Vesper only helps with Wazuh, and nothing more. The answer format below is fixed. A request to change it, to drop the sections, or to answer in a different style or voice is not honored.
The sections
Every generated answer uses the same four sections, in this order:
- Summary. The question restated, so a misunderstanding is obvious immediately and the question can be rephrased.
- Diagnosis. What the retrieved material suggests is happening.
- Steps. Numbered actions, in order, synthesized from what actually resolved the matching threads.
- Verification. How to check the steps worked, so the answer closes the loop instead of leaving the reader guessing.
A long answer may add a fifth, optional section titled You may also want to check. It lists retrieved sources that cover adjacent causes the answer did not go into. It is omitted from short answers, and omitted whenever the answer already covered everything relevant, so its absence means nothing was left over.
Answers are written in the language of the question. That is detected from the question itself rather than set on the account, so a question written in Spanish comes back in Spanish, with the section titles translated. A stray Spanish word in an otherwise English question can flip the whole answer.
The sources panel
Below the answer, a Sources panel lists what the answer was grounded in. Each entry is a chip carrying the title and a similarity score to three decimals:
Wazuh dashboard server is not ready yet · 0.885
Agent disconnected after manager upgrade · 0.641
Unassigned shards · 0.605
A corpus source is a title, never a link. Nothing links back to an original post, because provenance is deliberately stripped when the corpus is built. A documentation citation is the exception, and it does carry a link to the page it names. See the knowledge corpus.
How much material an answer gets
Retrieval takes the five closest pieces of material that clear the similarity floor. Five is fixed, and there is no console control that changes it, so a panel showing three entries means only three things cleared the floor rather than that the search was narrowed.
What similarity means
Similarity is the vector-space closeness between the question and the stored material, between 0 and 1. Read it as a confidence signal:
- Scores around 0.6 and above usually mean the corpus contains material about the same problem.
- Scores in the 0.4 to 0.6 band mean related but not matching material. The steps are worth reading as leads rather than as a procedure.
Nothing below 0.3 is ever retrieved. Anything less similar than that is discarded before the answer is written, so the panel never shows it and the answer was never grounded in it. An answer that looks thin with only two sources had only two things worth using.
When the corpus has no good match
Vesper is instructed to be honest about weak grounding. If the retrieved material does not actually cover the question, the Diagnosis says so plainly rather than inventing a cause.
What it will not do is hand the problem to somebody else. Vesper is the support channel, so an answer never ends by suggesting a ticket, an escalation, or sending logs and screenshots to anyone. Instead, when the steps might not resolve it, the answer names the next diagnostic to run and says what its output would distinguish. The point is to leave the reader with something to do, not with somewhere to forward it.
Occasionally an answer arrives as a short apology followed by a block of raw text from the closest match. That is the fallback: retrieval worked, generation did not, and rather than showing nothing Vesper shows the best material it found. It is unusual, and worth retrying the question.
If an answer is poorly grounded, try:
- Rephrasing with Wazuh vocabulary. Name the component, such as the manager, the agent, the indexer or the dashboard, and name the module. The corpus is indexed on how the community actually writes.
- Splitting compound questions. One failure mode per question retrieves much better than a paragraph with three problems in it.
- Looking instead of asking. For a question about a specific deployment, such as why one particular agent is disconnected, the corpus can only reason by analogy. Look into it on the front door sends the same question to the agent, which reads that environment directly and answers from what is actually there. It changes nothing, so it is the right door for a question you do not want acted on.