Wcs Management

Maintain and create Wazuh Common Schema (WCS) modules under wcs/ in wazuh-indexer-plugins. Use when asked to add a field to a WCS module, change a module's index/template settings, create a new WCS module, or regenerate WCS index templates. Covers the module anatomy, the ECS-subset + custom-field YAML dialect, the 3-step Docker generator pipeline (update_module_list.sh, generate_schema.sh, count_and_update_total_fields.sh), and the out-of-tree wiring (SetupPlugin.java, module_list). Never hand-edit generated templates.

wazuh 18dda17 2 files · 18.0 KB Updated

File contents

wazuh/wazuh-indexer-plugins/tree/main/.claude/skills/wcs-management commit 18dda17ea5

Frequently asked questions

npx skillmds@latest add wazuh/wcs-management