If you forgot Wazuh password
If you forgot the password used to log in to your Wazuh Dashboard, that is normally the Wazuh Indexer admin password. You can reset it directly on the Wazuh server/indexer. Wazuh’s current documentation recommends using wazuh-passwords-tool.sh. Wazuh Documentation
For a typical all-in-one Wazuh installation, SSH to the server and run:
sudo -i
cd /usr/share/wazuh-indexer/plugins/opensearch-security/tools/
./wazuh-passwords-tool.sh -u admin
If you don’t specify a password, Wazuh will generate a new random password and display it. Then log in to:
https://<WAZUH-SERVER-IP>
with:
Username: admin
Password: <new password>
You can also specify your own password:
./wazuh-passwords-tool.sh \
-u admin \
-p 'MyWazuh2026*'
The password must be 8–64 characters and contain uppercase, lowercase, a number, and an accepted special character such as *, ., +, ?, or -. Wazuh Documentation
Important for your Wazuh server
Because admin is also used for communication between components, changing it may require Filebeat and the Wazuh Manager credentials to be synchronized. On an all-in-one installation, the password tool handles the associated updates; on a distributed installation, additional updates can be necessary. Wazuh Documentation
After resetting it, check:
systemctl status wazuh-indexer
systemctl status wazuh-manager
systemctl status wazuh-dashboard
systemctl status filebeat
If necessary:
systemctl restart wazuh-indexer
systemctl restart wazuh-manager
systemctl restart filebeat
systemctl restart wazuh-dashboard
Given your setup, I recommend resetting only admin, rather than using --change-all. Changing all passwords also changes kibanaserver, wazuh-wui, API credentials, etc., which creates more synchronization work. Wazuh Documentation
If your command returns wazuh-passwords-tool.sh: No such file or directory, send me:
dpkg -l | grep wazuh
and
ls -la /usr/share/wazuh-indexer/plugins/opensearch-security/tools/
and I can give you the exact reset command for your installed Wazuh version.