Ask your first question
Vesper answers Wazuh questions from real resolved support threads and from the official documentation, read live. The way in is the Answers page: you ask a question, and an answer comes back.
Where to ask
- Sign in at vesper.wazuh.com. The console opens on the Overview, which shows the state of the registered environments and a summary of the last day of agent runs. The Ask a question panel leads to the Answers page, and so does the Answers entry in the sidebar.
- Type the question the way it would be put to a colleague. Real questions
from the corpus look like:
- "How do I show only active, non-resolved vulnerabilities in the Vulnerability Detection module?"
- "How do I restart the Wazuh manager on Linux?"
- "How to rotate Wazuh logs?"
Answers is about Wazuh in general, and nothing more. A question about one specific deployment goes to the agent instead. Look into it reads a registered environment and answers, changing nothing. Fix it lets the agent act on it. Both are chosen per message on the agent page, both need a connector installed and online, and both are described in The Vesper agent. Until an environment is registered, Answers is the only thing available.
Ask and get an answer
The Answers page opens on a welcome and a single box. Type the question and send it, with the Send button or the Enter key. Vesper reads the support corpus and the official documentation and writes an answer grounded in them. There is no step in between: the ranked threads and pages the answer rested on are a retrieval detail, not something to browse and choose from first.
An answer costs what a question costs, drawn from the organization's service credit. See Quotas and credit below.
Past answers live behind the Conversations button in the top right of the page. See Conversation history.
What comes back
Every answer follows the same shape:
| Section | What it contains |
|---|---|
| Summary | What the question is really about, restated. |
| Diagnosis | What is going on, based on the retrieved material. |
| Steps | Numbered, concrete actions to take. |
| Verification | How to confirm the fix actually worked. |
A long answer may close with an optional fifth section, You may also want to check, listing retrieved sources that cover adjacent causes it did not go into.
Below the answer, the Sources panel lists what the answer was grounded in. A documentation page is a link you can open and read; a verified Vesper procedure carries a badge. See Reading answers for how to read the panel, and the knowledge corpus for where that material comes from.
Quotas and credit
Questions draw on the organization's service credit, metered by the real model-token cost of the retrieval and generation calls. New organizations start with a lifetime credit and no card on file. When it runs out, an admin adds the organization card in the Wazuh Hub. The details live in Billing.