Skip to main content

Troubleshooting

Most things that go wrong in Argus surface as one of a small number of states: a sign-in that lands nowhere, a connection that never settles, a scan that does not start, or a report that is not ready yet. This page maps each state to what causes it and to the next step.

An invitation does not open the workspace​

An invited member joins automatically on the first sign-in, so there is no invitation to accept by hand. When the invitation is no longer live, the sign-in still succeeds and Argus shows the Almost there screen instead of the workspace, offering to start a new workspace rather than reporting a problem with the invitation.

Two things put a member on that screen:

  • The invitation expired. Invitations are live for 14 days. Ask an admin to send a new one.
  • The invitation was already used. An invitation joins one account. A second person using the same link needs an invitation of their own.

Starting a workspace from that screen is a different action from joining an existing one. A member who is meant to join a colleague's workspace should wait for a fresh invitation rather than start one. See Team & roles.

Start here does not create a workspace​

The Almost there screen offers Start here to anyone who signs in without a workspace. That action can be refused, and the screen reports the reason in place instead of failing silently. Each refusal names a different party as the one who can act.

NoticeMeaning
Argus is in closed beta and isn't enabled for your organization yet.Argus has not been enabled for the organization. A workspace can be started once the Wazuh team grants the organization access. Invitations into an existing workspace are unaffected
Your organization uses Argus, but you haven't been given access to it.The organization already runs Argus, and this person is not among those allowed into it. An owner or a billing admin adds them to Argus on the Members page of the Wazuh Hub
Your organization hasn't activated Argus yet, and only an owner or a billing admin can activate it.Nobody has activated Argus for the organization, and this person's role cannot do it. An owner or a billing admin activates it from the Wazuh Hub
Activation is temporarily unavailable. Please try again in a few minutes.Argus reached no verdict on whether activation is allowed. Nothing is created and nothing is lost, so the action is worth repeating a few minutes later

Owner and billing admin are roles in the Wazuh Hub organization, not Argus roles. An Argus workspace admin cannot grant them, and the person who holds them may never have opened Argus.

A refusal creates nothing and leaves the sign-in valid. Once the grant is in place, Start here opens the workspace with no further step and no second sign-in.

A connection test does not pass​

The connect wizard registers the account first and runs the connection test afterwards, so the account exists even when the test fails. On a failed verdict the wizard reports The provider rejected the credentials. Review them and try again.

That message is the same for every cause. Argus does not identify which part of the setup is wrong, so check the role against the four things an assumed-role connection needs, in this order:

  1. The role name. It must start with argus-scan-. Argus can only assume roles carrying that prefix, so a role named anything else never connects, however correct the rest of the setup is.
  2. The role ARN. It has to match the role exactly, and the account id inside it has to be the account that owns the role.
  3. The External ID. The value in the role's trust policy must equal the External ID the wizard showed. It is authored per workspace and cannot be edited.
  4. The trust policy principal. It names the Argus scanner principal as the party allowed to assume the role. See Connect an AWS account for the policy template and the two read-only managed policies the checks rely on.

A failed test leaves the account registered rather than discarding it. It appears on Accounts in the Failed state and it occupies a slot against the plan's account limit. Repair the role and re-test, or delete the account.

The wizard stops waiting for a verdict​

The connection test runs in the background, and the wizard follows it for about a minute and a half. If no verdict has arrived by then, the wizard reports that verification is still running and stops following it. The test itself carries on. Close the wizard and read the outcome on the account card.

An account still reads Failed after the role is fixed​

Test connection starts a fresh check in the background instead of waiting for it. It reports neither success nor failure, so the card still carries the previous verdict when the action returns. Give the check a few seconds and reload the Accounts page.

An account whose state is not Connected cannot be scanned. It is absent from the account list in the Launch scan dialog until a test passes.

A scan does not start​

What is seenCause
Launch scan is disabledScans are a Pro capability. See Billing & plans
Connect a cloud account first, then launch a scan.No account has passed a connection test yet
The account is not in the Launch scan dialogIts connection state is not Connected
The run appears under In progress and stays at the same percentageEither it is waiting its turn, or it has stopped. See below
A Free workspace's weekly scan has not run for weeksNobody has signed in for 45 days, so the weekly scans are paused. Signing in resumes them. See Billing & plans

A launched run does not always begin straight away. Runs are processed one at a time, so a run launched while another is still going waits for it, and the first run after a quiet period takes a few minutes to get going.

The Scans page does not refresh on a timer either, so a run that looks frozen is often a stale page. Reload it before reading anything into the progress bar.

A run stays in progress after a reload​

A run that has sat under In progress far longer than that account's scans normally take has stopped rather than slowed down. It stays open, and no further scan of the same account starts while it is open. Other accounts in the workspace keep scanning normally.

Argus offers no action to cancel a run, so this is the one failure on this page that cannot be cleared from the console. Report it from the console's Contact page and it can be cleared without losing anything. Deleting the account and connecting it again also releases the block, at the cost of that account's entire scan history. See Accounts & provider groups.

A run that ended in failure is listed under the Completed tab, not under In progress, with the status failed and no fail or pass counts.

A report will not download​

Reports are built on demand, when Download report is used, so the first attempt on a scan that has just finished can arrive before the file exists. The action is offered on completed runs only.

NoticeMeaning
The report is being generated. Try again in a moment.Generation is under way. Argus does not retry by itself, so use Download report again
No report is available for this scan yet.No file is ready. This notice also covers a request that failed outright, so it is worth one more attempt before treating it as final

Findings are missing from a list​

Three defaults and one limit account for most findings that seem to have gone missing:

  • The page opens on failures. The Findings page starts with Status set to fail, so passing and manual results stay out of the list until that filter changes.
  • Muted findings are hidden. The mute filter starts on Active, which leaves muted findings out of the list. Switch it to Muted + active to see everything. See Mute rules.
  • Manual results are not failures. A check that cannot be verified automatically is recorded as manual, not as fail. A low failure count is therefore not by itself a clean account.
  • The read window is seven days. The Findings and Resources lists read the most recent seven days of scan results. An account whose last scan is older than that has nothing to show in them. Run a new scan, or read the older run through the scan selector on Compliance.