Skip to main content

Settings

The Settings page holds the few controls that are neither intelligence nor fleet: how the console looks, what the workspace is, and where its data comes from. Notification destinations and routing have their own page, linked from here and covered in Notifications.

Appearance​

The theme is system, dark or light. It is stored locally in the browser, so it is a per-browser preference rather than a workspace setting, and choosing it on one machine does not change it on another or for anyone else on the team.

Workspace​

The Workspace card is the read-only identity of the workspace: the organization it belongs to, its own identifier in the row the console labels Tenant, the signed-in member's role, and its billing state. Nothing here is edited on this page. The role is set when a member is invited, billing is changed on the Signals page, and organization membership belongs to the Wazuh Hub.

The upstream feed​

Pharos keeps a live mirror of the Wazuh CTI corpus, and it reaches Wazuh CTI through its public surfaces only. The Upstream feed card reports the state of that mirror: the context and consumer it reads as, the offset it has reached in the upstream change stream, when the last snapshot was taken, and whether the consumer is public.

Filling the mirror is Pharos's own work, done server-side on a schedule. There is nothing for a customer to run and no feed to configure. The card is there to show that the mirror is current, not to ask for anything.