Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
VTI Academy - Yen Nguyen VTI Academy - Yen Nguyen VTI Academy - Yen Nguyen
VTI Academy - Yen Nguyen VTI Academy - Yen Nguyen VTI Academy - Yen Nguyen
  • Home
  • Tất cả bài giảng
  • Home
  • Tất cả bài giảng
Close

Search

  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Subscribe
Cybersecurity

If you forgot Wazuh password

By yennhc
October 7, 2026 2 Min Read
0

If you forgot the password used to log in to your Wazuh Dashboard, that is normally the Wazuh Indexer admin password. You can reset it directly on the Wazuh server/indexer. Wazuh’s current documentation recommends using wazuh-passwords-tool.sh. Wazuh Documentation

For a typical all-in-one Wazuh installation, SSH to the server and run:

sudo -i

cd /usr/share/wazuh-indexer/plugins/opensearch-security/tools/

./wazuh-passwords-tool.sh -u admin

If you don’t specify a password, Wazuh will generate a new random password and display it. Then log in to:

https://<WAZUH-SERVER-IP>

with:

Username: admin
Password: <new password>

You can also specify your own password:

./wazuh-passwords-tool.sh \
-u admin \
-p 'MyWazuh2026*'

The password must be 8–64 characters and contain uppercase, lowercase, a number, and an accepted special character such as *, ., +, ?, or -. Wazuh Documentation

Important for your Wazuh server

Because admin is also used for communication between components, changing it may require Filebeat and the Wazuh Manager credentials to be synchronized. On an all-in-one installation, the password tool handles the associated updates; on a distributed installation, additional updates can be necessary. Wazuh Documentation

After resetting it, check:

systemctl status wazuh-indexer
systemctl status wazuh-manager
systemctl status wazuh-dashboard
systemctl status filebeat

If necessary:

systemctl restart wazuh-indexer
systemctl restart wazuh-manager
systemctl restart filebeat
systemctl restart wazuh-dashboard

Given your setup, I recommend resetting only admin, rather than using --change-all. Changing all passwords also changes kibanaserver, wazuh-wui, API credentials, etc., which creates more synchronization work. Wazuh Documentation

If your command returns wazuh-passwords-tool.sh: No such file or directory, send me:

dpkg -l | grep wazuh

and

ls -la /usr/share/wazuh-indexer/plugins/opensearch-security/tools/

and I can give you the exact reset command for your installed Wazuh version.

Author

yennhc

Follow Me
Other Articles
Previous

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • If you forgot Wazuh password
  • Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
  • Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Recent Comments

No comments to show.

Archives

  • October 2026

Categories

  • Cybersecurity
  • News
Copyright 2026 — VTI Academy - Yen Nguyen. All rights reserved.