Skip to main content

FAQ

The questions that come up most, grouped by what they are about. Each answer is short on purpose and links to the page that carries the detail, so there is one place where each subject is explained properly and this page never becomes a second version of it.

The platform​

Where do the answers come from?​

From years of resolved community support conversations on the Wazuh Slack, Discord, Google Groups and GitHub. A question is embedded, the closest material is retrieved, and the answer is written using only that material as context. The sources panel under every answer lists exactly what it used.

A question about a documented feature or procedure can also be routed to the official Wazuh documentation. That page is fetched live at the moment of asking, never stored here, and the answer cites it. See Where answers come from.

Can a colleague see a conversation?​

Not unless the owner shares it. Every conversation belongs to whoever started it, and that holds for admins too. Being an administrator of the workspace does not open anybody else's conversation.

Sharing is explicit. The owner opens the conversation, presses Share with, picks colleagues and chooses what each may do. Can view reads the conversation and follows it as it goes. Can participate also asks in it and starts agent runs in it, spending the same workspace credit the owner's own questions do. Only the owner can share, rename or delete it, a grantee cannot pass it on, and nobody sees who else it was shared with. See Conversations.

Is one workspace's data used to answer another?​

No. The corpus has exactly one input, the public community discussions. A customer's own questions, agent conversations, environments and everything the connector reads stay inside their workspace. None of it is ingested, embedded or used to answer anybody else.

Can an answer be wrong?​

Yes. Answers are generated, so they can be wrong. That is why every one carries its sources and a similarity score for each. The score is a confidence signal, and the material is worth checking when a step looks surprising. See Reading an answer.

What is the difference between Look into it and Fix it?​

The same agent on the same environment. A look only run is not given the command tool at all, so it reads what the Wazuh API and the indexer report and touches no shell. Fix lets it act. The choice is made per message, so a later message in the same conversation can be sent as a fix. See The Vesper agent.

Is look only the same as an environment set to Read only?​

No. It is stricter. Read only refuses changes but still runs read and diagnostic shell commands on the host. A look only run runs none at all. There are two ceilings and the lower one always wins, so a look only run on an Auto environment still cannot run a command.

Can an admin widen a conversation while it is running?​

Not a look only one. The environment's mode is re-read on every command, so lowering it stops a run in flight. A run that started look only stays that way, and nobody can change it afterwards.

Who can approve a change the agent proposes?​

An admin of the workspace, on the Runs page. Approving a command runs it as root on a production machine, which is why the decision is an admin's and is taken in the customer's own console. Nobody at Wazuh can approve it on their behalf.

Two other decisions are open to any member of the workspace, because neither reaches a machine. One is a stalled run asking to try harder, the other is a run asking for more working time. Both spend money and nothing else, and both are taken inside the run. See why the agent stops and asks.

Why did the agent stop and ask whether to keep going?​

Because it had worked on that one question for ten minutes without finishing. A long investigation costs real money, so the decision to spend more belongs to the customer. Keep going grants another ten minutes and changes nothing else. The same environment, the same limits, and nothing left waiting to run on the machine. Stopping there ends the run with everything it found so far, which stays in the transcript.

Why does an answer come back in a different language?​

The language is detected from the question itself rather than set on the account, so a question in Spanish comes back in Spanish with its section titles translated. One stray word in another language can flip the whole answer.

Can Vesper be tried without an account?​

Yes. The playground is the real console signed in to a read only demo workspace filled with fictitious data. Every write is refused there, which is what makes it safe to leave open to anyone. See The playground.

The connector​

What does the connector open on the network?​

Nothing. It is strictly outbound. It dials Vesper over mTLS and keeps that session alive, so no inbound rule is needed, and the Wazuh credentials it uses never leave the machine. Behind a proxy it honours the standard HTTPS_PROXY, HTTP_PROXY and NO_PROXY variables. See Installing the connector.

What does it need on the host?​

Linux with systemd, on x86_64 or arm64, and root both to install and to run. It also needs curl. Only the binary download falls back to wget, so an install on a host with wget alone fails partway through.

An environment went Offline and will not come back. Why?​

Most likely its identity expired. Enrollment issues an mTLS certificate valid for 90 days and nothing renews it. There is no reminder and no warning as the date approaches. The connector retries forever and cannot recover on its own, because recovery needs a new certificate, and one is only issued against a fresh enrollment. The console no longer issues install commands, so the node comes back by connecting the environment through Wazuh Fleet. See Connector lifecycle.

What is the difference between Remove node and Revoke all connectors?​

Remove node revokes one node's identity, drops its live session and takes it off the list. Revoke all connectors does the same for every node of the environment at once.

Both act on Vesper's side only. The binary, the service and its config stay on the host, and the service keeps retrying with a credential that is no longer accepted. Removing it from the machine is a separate step.

Where does the connector go on a distributed Wazuh?​

On every server node. The manager master, each worker, each indexer node and the dashboard. Wazuh Fleet installs it on each of them that runs the Wazuh Fleet connector, each node enrolls as its own connector, and the node list under the environment card shows them with what each one runs. A node that Wazuh lists in its cluster and that has no connector is listed too, because the agent can neither read nor fix anything there until one is installed.

Does the agent run shell commands on the host?​

Only when everything allows it. The connector has to have been installed with shell execution enabled, the environment's mode has to permit changes, and the conversation has to have been sent as a fix rather than as a look. Any one of those refusing means no command runs.

Does re-running the installer overwrite existing settings?​

Yes, by default. A re-run rewrites the configuration file from the flags and what the installer discovers on the host, and saves the previous file beside it as connector.yaml.bak. Add --keep-config to preserve settings edited by hand. The node keeps its identity either way, so the console keeps showing the same node. See re-running the installer.

Does the connector upgrade itself?​

Only when asked. Automatic upgrades are off by default and are turned on per environment. Otherwise a new build arrives when somebody presses Upgrade now on the environment card.

Billing​

When does charging start?​

When a billing admin switches Pay as you go on, and not before. The organization's card lives in the Wazuh Hub and is shared with every Wazuh Labs service, so a card added to keep another service running is not a decision about Vesper. Until the switch is on, the workspace runs on its free credit. See Billing.

What happens when the free credit runs out?​

New questions and agent runs pause and say so, with a link to turn Pay as you go on. Nothing is charged by surprise, and nothing belonging to the workspace is deleted or locked away. The Billing page shows what has been used and what is left.

Is there a trial, or a countdown?​

No. There is no trial and no clock running against the workspace. What exists is the credit and the switch, and neither expires on a date.

What exactly is metered?​

Every model call. The retrieval and generation behind each question, the embedding behind a corpus search on the Answers page, and an agent run's accumulated token usage. The Usage page groups the spend by what caused it. A corpus search is a small fraction of what a question costs, and it is still a real call.

Are there seats or plan tiers?​

No. There are no seats and no subscription tiers. The bill is the real model token cost of what was used, at a fixed margin, so adding a teammate costs nothing by itself. See The team.

Why does a long conversation cost more?​

Because recent turns are replayed into follow-up runs so the agent keeps its context, which means it is paid to read them again. That is also why the replay window is bounded rather than unlimited.

How can spending be capped?​

With a monthly budget, set on the Billing page. Reaching it pauses new questions and agent runs instead of charging past it. Any member of the workspace can read the limit, so somebody whose question was paused can see why. A ceiling higher than the page offers is available on request.

Can Pay as you go be turned off again?​

Yes, at any time. Billing stops at the end of the current period, and usage already recorded is still invoiced. Nothing is deleted.