Wazuh 5.0 will not load your custom XML rules. 82% of one public pack depends on what it drops.
If you run Wazuh 4.x with your own rules and decoders, the 5.0 release changes more than the version number. We read the migration guides that ship with the latest 5.0 pre-release (v5.0.0-beta5) and ran the numbers on a
If you run Wazuh 4.x with your own rules and decoders, the 5.0 release changes more than the version number. We read the migration guides that ship with the latest 5.0 pre-release (v5.0.0-beta5) and ran the numbers on a public community ruleset. Here is what applies to custom content, with the source for each point.
What changes
Custom XML files are not loaded at all. From docs/guide/migration/manager-configuration-migration.md at v5.0.0-beta5:
Custom rules and decoders from 4.x cannot be migrated by copying XML files to the manager.
The same table lists <ruleset> as a startup error and says etc/rules/, etc/decoders/ and etc/lists/ "do not exist in 5.0". Decoders become YAML assets run by the new engine; rules become Sigma-style YAML documents stored in the indexer and managed through its content API.
There is no converter. From docs/guide/migration/rules-4x-to-5x.md:
There is no automatic conversion tool. Rules must be manually rewritten following this guide.
The manager migration issue (#39109, closed 28 September) states the scope plainly: "rules, decoders, CDB lists and anything the engine changed structurally" are out of scope, and "the translation is the user's responsibility". The tool merged for it (PR #39197) moves agent keys, groups and API users, not content.
Rules no longer chain. The rules guide marks these as not supported:
| 4.x | 5.0 (per the guide) |
|---|---|
<if_sid>, <if_group>, <if_level>
|
not supported; "rules are self-contained" |
<if_matched_sid>, frequency/timeframe, <same_*>/<different_*>, <if_fts>
|
not supported in rules; "correlation handled separately" |
<list> (CDB lookups) |
not supported in rules; move to KVDBs at the decoder level |
<time>, <weekday>, <check_diff>
|
not supported |
<options> (no_log, no_full_log, …), <var>
|
no direct equivalent |
And <match>/<regex> no longer search the raw log: 5.0 rules match fields of the normalized event, with event.original as the fallback.
Decoders lose some elements. The decoder guide lists <plugin_decoder>, <accumulate/>, <fts>, <json_null_field>, <type>, <use_own_name> and the pcre2/offset options as unsupported: 5.0 parses with its own field-extraction language, not regex.
How much of a real ruleset is affected
We took the public SOCFortress Wazuh-Rules set (75 XML files, 2,211 rules, 105 decoders) and counted, rule by rule, the elements the 5.0 guide marks as unsupported:
| Rules | Share | |
|---|---|---|
Use rule chaining (if_sid, if_group or if_level) |
1,804 | 82% |
Use correlation (frequency, if_matched_*, same_*) |
8 | <1% |
Use CDB lookups or check_diff
|
3 | <1% |
| None of the above (only a rewrite to the new format) | 399 | 18% |
Chaining is how most 4.x content is written: a child rule refines a stock parent. In 5.0 each of those rules has to carry its own full condition, written against normalized field names instead of a parent's decoded fields.
Where things stand
-
v5.0.0-beta5(1 September) is the latest 5.0 tag. The5.0.0branch already reads"stage": "rc1". No GA date has been announced. - There is no in-place upgrade from a 4.x manager; the configuration guide says 5.0 is a fresh install.
- Until you move, 4.x keeps loading XML as before, including its quirks: if you are still writing 4.x rules, check them before restarting (one quirk we measured: wazuh-analysisd shows at most 50 load warnings).
Measure your own
The free checker at https://atkvn.com/wazuh-rule-precheck.html runs in the browser and checks 4.x load problems. The counts above came from the same code with a 5.0 mode that lists, per rule, the elements the 5.0 guide marks as unsupported. If you want that list for your own rules before planning a move, send them and your Wazuh version to the address on the checker page and we will send it back, free.
Limits
Everything about 5.0 here comes from the migration guides at v5.0.0-beta5 and the linked issue and PR, not from running a 5.0 engine. A pre-release can change before GA. The counts are a static reading of the XML.
Dong Nguyen, ATK New Technology. We check and fix Wazuh rules for people who run it.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.