Telegram and Wazuh - Integrate Wazuh and Telegram to Receive Alerts in Real Time!

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 พ.ย. 2024

ความคิดเห็น • 42

  • @ueukxvj
    @ueukxvj ปีที่แล้ว +5

    not working for current wazuh version(
    now found just WAZUH group, not OSSEC when CHOWN

    • @hansaja5594
      @hansaja5594 6 หลายเดือนก่อน +1

      chown root:wazuh /var/ossec/integrations/custom-telegram*
      chmod 750 /var/ossec/integrations/custom-telegram*

    • @leonardoacostacoden5060
      @leonardoacostacoden5060 5 หลายเดือนก่อน

      @@hansaja5594 genio!

  • @carrot5063
    @carrot5063 2 ปีที่แล้ว +2

    Clean and very cool session.

  • @reginaldo5200
    @reginaldo5200 4 หลายเดือนก่อน

    its working! thank you
    version 4.8

  • @kevinmedeiros6
    @kevinmedeiros6 หลายเดือนก่อน

    Seu video me ajudou, muito bem explicado e simples

  • @hlanr
    @hlanr หลายเดือนก่อน

    If my Wazuh manager is set up as a cluster and my agent is registered on the worker, should I place the Telegram configuration file on the master or on the worker?

  • @ИльяДжермакян
    @ИльяДжермакян 7 หลายเดือนก่อน

    Worked fine, thank you very much!

    • @canyoufindm3
      @canyoufindm3 5 หลายเดือนก่อน

      still worked? I don't why my telegram and slack didn't work

  • @user-fg8lh5nx5r
    @user-fg8lh5nx5r หลายเดือนก่อน

    Hi! How do I add the output in the message field: timestamp?

  • @TVTV-f9b
    @TVTV-f9b 3 หลายเดือนก่อน

    my bot in telegram only sending to private, not send to the group. How can i Fix?

  • @JohnDoe-hc8gi
    @JohnDoe-hc8gi 2 ปีที่แล้ว

    Hi, I'm able to receive the alert but the problem is. The alert is being send to my telegram bot not inside the group chat I created.

  • @tinobattistutti964
    @tinobattistutti964 ปีที่แล้ว

    Gracias totales!!

  • @numanmaavia8575
    @numanmaavia8575 3 ปีที่แล้ว

    Great session

  • @SupermotoSM
    @SupermotoSM 2 ปีที่แล้ว

    Hello. Many thanks for this video, highly appreciated :) ..would it be possible to trigger an active response only after confirmation by telegram for example? Best regards

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      I do not believe you can do that with the Telegram app explicitly, but you could create a Shuffle workflow that takes advantage of a text message or email trigger. shuffler.io/docs/triggers#user_input

  • @danielfeitosa3205
    @danielfeitosa3205 2 ปีที่แล้ว

    its working for me, but only in windows server. Linux os is not working.

  • @Thit-Rang-Chay-Canh
    @Thit-Rang-Chay-Canh 2 ปีที่แล้ว

    How can i send to multiple CHAT_ID with Condition?

  • @serzh3078
    @serzh3078 3 ปีที่แล้ว

    Very cool!!!

  • @tbaror
    @tbaror 3 ปีที่แล้ว

    Thanks very nice, is it possible to do video integrating Pfsense firewall logs, and Suricata logs on it? Thanks again

  • @danielfeitosa3205
    @danielfeitosa3205 2 ปีที่แล้ว

    Its working all good, but the text isnt in UTF 8. how can i fix it ? thanks for the tutorial

    • @danielfeitosa3205
      @danielfeitosa3205 2 ปีที่แล้ว +1

      fix it. this switch to # Send the request
      requests.post(hook_url, headers=headers, data=json.dumps(msg_data , ensure_ascii=False).encode('utf8'))

  • @AlexanderJMarsh
    @AlexanderJMarsh ปีที่แล้ว

    Is Python3 a requirement?

  • @virtual-riot
    @virtual-riot ปีที่แล้ว

    Hello a question help meee!!! i need this but that only alert events with name “start with” as i do??????

  • @dheanova9008
    @dheanova9008 2 ปีที่แล้ว

    Cool! I've tried this tutorial, but why the notification that appears only when restarting Wazuh Manager? please answer, thank you😊

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      What does your integration block look like?

    • @dheanova9008
      @dheanova9008 2 ปีที่แล้ว

      @@taylorwalton_socfortress same with this tutorial😞

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      @@dheanova9008 Do you have an agent connected to the manager that would be triggering more level 3 and above alerts? You can also take a look at the /var/ossec/log/integrations.log file to see if there are any errors.

  • @serzh3078
    @serzh3078 2 ปีที่แล้ว

    Hi. It doesn't work for me. Tell me, should additional packages be installed on the system? I am using the ova wazuh image, it contains python 2.7.5, maybe this is the reason? Or install pip of a specific version?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      Yes try installing python3 and pip3 then install the request package with “pip3 install requests”

    • @serzh3078
      @serzh3078 2 ปีที่แล้ว

      @@taylorwalton_socfortress tell me how to add the use of a proxy to the script?

    • @muhamadridwansyah3580
      @muhamadridwansyah3580 2 ปีที่แล้ว

      @@taylorwalton_socfortress hi, i have installed python3, pip3, and requests package as well. But I still can't get the notification in my Telegram, do you have any solution for this?

  • @anomouswarrior8492
    @anomouswarrior8492 6 หลายเดือนก่อน

    Hi thanks for the video
    i am facing one issue with integration you set the alert value of 3
    me also set same value so i will get all alerts but when i chage it to value 10,12 or 15 i didnt get any ssh attacks alerts on telegram
    how to fix this issue

  • @LuckyAce1
    @LuckyAce1 2 ปีที่แล้ว

    Please make the gain much lower next time ,
    My ears are bleeding 😵

  • @miguerattox
    @miguerattox ปีที่แล้ว

    chown root:ossec /var/ossec/integrations/custom-telegram* I cannot execute this command the output gives me this: "chown: invalid group: ‘root:ossec’"

  • @rikur4543
    @rikur4543 ปีที่แล้ว

    chown root:ossec /var/ossec/integrations/custom-telegram*
    chown: invalid group: 'root:ossec'
    I failed in this section, can anyone help me?

    • @the_acheelies505
      @the_acheelies505 ปีที่แล้ว

      Same Boat seeing what i can find

    • @harras07
      @harras07 ปีที่แล้ว +2

      try: chown root:wazuh /var/ossec/integrations/custom-telegram*

    • @Stordom24
      @Stordom24 10 หลายเดือนก่อน

      This is the solution, very thx@@harras07