Skip to main content

Wazuh Agent Configuration Result (wresult)

Overview

wresult provides the running configuration of a Wazuh agent by reconstructing how it applies ossec.conf and agent.conf. This tool is designed to support users for compliance reporting and troubleshooting, ensuring that teams can see the actual settings enforced on an agent.

Why Use wresult?

The Problem

Wazuh agents dynamically apply configurations:

  • ossec.conf is loaded first (local settings).
  • agent.conf is fetched from the Wazuh manager and applied sequentially, overriding or appending settings.
    • Conditional configurations, aka Options (e.g., OS-specific, profile-based configurations) determine the final applied settings.
  • There are internal options that amends the behaviors in an advanced manner. For agents, it is generally just the debug configuration. Since the original file internal_options.conf is overwritten on every update, there is the local_internal_options.conf file for overriding default behaviors. This is crucial on troubleshooting. And user needs to be aware of the deviances from the defaults.

As a result:

🔹 Compliance teams struggle to verify if required security policies are applied.

🔹 Security engineers face difficulties troubleshooting unexpected agent behavior.

🔹 Administrators need a way to see the configuration exactly as the agent applies it.

The Solution

✅ Shows the running configuration—not just raw config files.

✅ Resolves conflicts—newer policies override older ones.

✅ Filters out irrelevant settings—only applicable rules are included.

✅ Saves time—eliminates manual inspection of multiple configuration files.

Features

  • Accurate Reconstruction – Mirrors how Wazuh agents process configurations.
  • Conflict Resolution – Newer settings take precedence; others are appended.
  • JSON Output – Machine-readable, structured for automation and jq processing.
  • HTML Report – Interactive, easy-to-read configuration report.
  • Supports Linux & Windows – Uses standard Wazuh configuration paths.

Installation

wresult is designed for easy installation and execution via pipx.

pipx install wresult
Install via pipx

Usage

usage: wresult [-h] [--output OUTPUT]

Parse the Wazuh agent running configuration, print to stdout as JSON or save to an HTML file.

options:
  -h, --help            show this help message and exit
  --output OUTPUT, -o OUTPUT
                        Output file path

CLI Output (JSON for Automation)

wresult | jq .

🔹 View the exact applied settings in structured JSON, ideal for automation.

Print to console

Generate a Human-Readable Report

wresult --output report.html

🔹 Generates an interactive HTML report with expandable sections.

Export to HTML file

🔹 See the collapsed tree of configuration items.

HTML report with collapsed items

🔹 Click "Show all" to have a broader view.

HTML report with expanded items

Hidden Arguments

In order to support testing, the tool has provided hidden parameters that are not visible on the help menu. The users must provide all 3 of them if needed. Otherwise, the tool will fall back to default locations for the undefined paths. This is designed to test and validate configuration changes without breaking the agent.

These arguments are for testing only. They are subject to change and should be treated as an undocumented API.

--agent_conf_path (-ap): Custom path for agent.conf.
--ossec_conf_path (-op): Custom path for ossec.conf.
--client_keys_path (-ck): Custom path for client.keys file.
--local_internal_options_path (-li): Custom path for local_internal_options.conf file.

License

This project is open-source and licensed under the MIT License.

Thanks

I was considering a remake of the gpresult HTML report, but I came up with a better and easier solution thanks to Maxim Maeder. I took his example, and simplified it for my use case, and it worked brilliantly. Kudos to Maxim!

Release files for wresult 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for wresult 1.1.0
File Size Uploaded
wresult-1.1.0.tar.gz 12.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for wresult 1.1.0
File Interpreter ABI Platform
wresult-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 24.2 kB

Release files / wresult-1.1.0.tar.gz

Download URL wresult-1.1.0.tar.gz
Size 12.8 kB
Tags Source
SHA-256 checksum
How to use checksums
1638a553128f9b331be79196165a4bc9564561d6af8275b7c230979a1fe8c986
BLAKE2b-256 checksum
How to use checksums
f8103406febeb9f432414e0c4451743831813a7418fa0f8ff5e51255dcca22a8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release files / wresult-1.1.0-py3-none-any.whl

Download URL wresult-1.1.0-py3-none-any.whl
Size 11.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
771843402b68690782916c4c86c94f944a30ca7a9ab5a8a5f5c199c526ff8ce9
BLAKE2b-256 checksum
How to use checksums
928faf7bd938667a08e173f3e1ad125c70c5eb98f49588c4128bfd43d7395b05
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.1.0 This release

2 release files

1.0.1

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page