Wazuh Agent Configuration Result (wresult)
Overview
wresult provides the running configuration of a Wazuh agent by reconstructing how it applies ossec.conf and agent.conf. This tool is designed to support users for compliance reporting and troubleshooting, ensuring that teams can see the actual settings enforced on an agent.
Why Use wresult?
The Problem
Wazuh agents dynamically apply configurations:
- ossec.conf is loaded first (local settings).
- agent.conf is fetched from the Wazuh manager and applied sequentially, overriding or appending settings.
- Conditional configurations, aka Options (e.g., OS-specific, profile-based configurations) determine the final applied settings.
- There are internal options that amends the behaviors in an advanced manner. For agents, it is generally just the debug configuration. Since the original file
internal_options.confis overwritten on every update, there is thelocal_internal_options.conffile for overriding default behaviors. This is crucial on troubleshooting. And user needs to be aware of the deviances from the defaults.
As a result:
🔹 Compliance teams struggle to verify if required security policies are applied.
🔹 Security engineers face difficulties troubleshooting unexpected agent behavior.
🔹 Administrators need a way to see the configuration exactly as the agent applies it.
The Solution
✅ Shows the running configuration—not just raw config files.
✅ Resolves conflicts—newer policies override older ones.
✅ Filters out irrelevant settings—only applicable rules are included.
✅ Saves time—eliminates manual inspection of multiple configuration files.
Features
- Accurate Reconstruction – Mirrors how Wazuh agents process configurations.
- Conflict Resolution – Newer settings take precedence; others are appended.
- JSON Output – Machine-readable, structured for automation and jq processing.
- HTML Report – Interactive, easy-to-read configuration report.
- Supports Linux & Windows – Uses standard Wazuh configuration paths.
Installation
wresult is designed for easy installation and execution via pipx.
pipx install wresult
Usage
usage: wresult [-h] [--output OUTPUT]
Parse the Wazuh agent running configuration, print to stdout as JSON or save to an HTML file.
options:
-h, --help show this help message and exit
--output OUTPUT, -o OUTPUT
Output file path
CLI Output (JSON for Automation)
wresult | jq .
🔹 View the exact applied settings in structured JSON, ideal for automation.
Generate a Human-Readable Report
wresult --output report.html
🔹 Generates an interactive HTML report with expandable sections.
🔹 See the collapsed tree of configuration items.
🔹 Click "Show all" to have a broader view.
Hidden Arguments
In order to support testing, the tool has provided hidden parameters that are not visible on the help menu. The users must provide all 3 of them if needed. Otherwise, the tool will fall back to default locations for the undefined paths. This is designed to test and validate configuration changes without breaking the agent.
These arguments are for testing only. They are subject to change and should be treated as an undocumented API.
--agent_conf_path (-ap): Custom path for agent.conf.
--ossec_conf_path (-op): Custom path for ossec.conf.
--client_keys_path (-ck): Custom path for client.keys file.
--local_internal_options_path (-li): Custom path for local_internal_options.conf file.
License
This project is open-source and licensed under the MIT License.
Thanks
I was considering a remake of the gpresult HTML report, but I came up with a better and easier solution thanks to Maxim Maeder. I took his example, and simplified it for my use case, and it worked brilliantly. Kudos to Maxim!
Release files for wresult 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| wresult-1.1.0.tar.gz | 12.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| wresult-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.2 kB
Release files / wresult-1.1.0.tar.gz
| Download URL | wresult-1.1.0.tar.gz |
|---|---|
| Size | 12.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1638a553128f9b331be79196165a4bc9564561d6af8275b7c230979a1fe8c986
|
|
BLAKE2b-256 checksum How to use checksums |
f8103406febeb9f432414e0c4451743831813a7418fa0f8ff5e51255dcca22a8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency logRelease files / wresult-1.1.0-py3-none-any.whl
| Download URL | wresult-1.1.0-py3-none-any.whl |
|---|---|
| Size | 11.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
771843402b68690782916c4c86c94f944a30ca7a9ab5a8a5f5c199c526ff8ce9
|
|
BLAKE2b-256 checksum How to use checksums |
928faf7bd938667a08e173f3e1ad125c70c5eb98f49588c4128bfd43d7395b05
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency log