Wazuh Alerts in Slack!

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ก.ย. 2024

ความคิดเห็น • 14

  • @JamesHart-s1m
    @JamesHart-s1m ปีที่แล้ว +1

    Great video. Thanks

  • @karnafelfamily7590
    @karnafelfamily7590 2 ปีที่แล้ว +1

    Awesome video! Have you had the ability to expand the slack alerts by adding additional information about the alert using the json information data that is on wazuh alerts dashboard? Like Agent IP, TargetUserName, Source IP and etc, windows Event ID, and etc

    • @jowerstechsolutions
      @jowerstechsolutions  2 ปีที่แล้ว

      I have not yet done a deep dive on getting additional log details but that may certainly be in a future video. Thanks!

    • @karnafelfamily7590
      @karnafelfamily7590 2 ปีที่แล้ว

      @@jowerstechsolutions Thanks Appreciate it. I'll be the first to watch it.

  • @aniketg09
    @aniketg09 2 ปีที่แล้ว +1

    Nice Video. I am able to get the alerts in slack channel. But not sure how I can modify the template of the alert. So far I am just getting below details:
    Monitor Successful sudo to ROOT executed. just entered alert status. Please investigate the issue.
    - Trigger: Sudo command executed
    - Severity: 1
    - Period start: 2022-07-25T11:16:19.208Z
    - Period end: 2022-07-25T11:31:19.208Z
    How I can add more fields like Agent Name, user details etc?

    • @jowerstechsolutions
      @jowerstechsolutions  2 ปีที่แล้ว

      Modifying the template is beyond the scope at the moment but it may be something we can do in the future. Thanks!

  • @federicolozan9509
    @federicolozan9509 ปีที่แล้ว +1

    Hola buenas se puede personalizar el nivel? para que solo alerte por ejemplo por el nivel 10?

    • @jowerstechsolutions
      @jowerstechsolutions  ปีที่แล้ว

      You can set alerts at certain levels within Wazuh, not sure about specific levels going to Slack alerts.

  • @akshanshshrivastava3761
    @akshanshshrivastava3761 2 ปีที่แล้ว

    I am doing the same but I am not receiving any alerts

  • @lautarorojas1396
    @lautarorojas1396 3 ปีที่แล้ว

    hey cool channel, I have a question that may seem silly but I don't want to break anything, I want to configure the manager for email alerts but i dont know what i have to put in mail.test.com .. I don't know what to put, the server's ip? with: 5601?

    • @christianborla
      @christianborla 3 ปีที่แล้ว

      Hi Lautaro!
      An SMTP server is an application that's primary purpose is to send, receive, and/or relay outgoing mail between email senders and receivers.
      ie: Gmail's SMTP server address is smtp.gmail.com
      if your destination account is a gmail account, you can try
      smtp.gmail.com
      And after changed it restart the server.
      For Systemd:
      # systemctl restart wazuh-manager
      For SysV Init:
      # service wazuh-manager restart
      also you can find extra information in following link:
      documentation.wazuh.com/current/user-manual/manager/manual-email-report/index.html?highlight=email
      Let me know if that works! Regards!

    • @jowerstechsolutions
      @jowerstechsolutions  3 ปีที่แล้ว +1

      Thank you for the reference Christian!