Integrating Suricata With Wazuh For Log Processing

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ม.ค. 2025

ความคิดเห็น •

  • @passaronegro349
    @passaronegro349 2 ปีที่แล้ว +4

    I'm following your work here in Brazil!!!! your channel is very good.

  • @Fz3r0_OPs
    @Fz3r0_OPs 2 ปีที่แล้ว +4

    Thank you very much for this blue team series. I really appreciate it. Thank for sharing with us that knowledge, you explain very well I love your videos. Cheers from Mexico my friend, much respect.

  • @mauriciob3334
    @mauriciob3334 ปีที่แล้ว +2

    thanks it did work very well in my configuration, we tested with the wazuh cloud, the only difference was in the client configuration, the log format was: json

  • @ehsanumer2596
    @ehsanumer2596 2 ปีที่แล้ว +1

    always Best and very helpful for everyone

  • @xboxplayer4230
    @xboxplayer4230 2 ปีที่แล้ว +3

    Thank you so much for the explication

  • @0xr1kk07
    @0xr1kk07 2 ปีที่แล้ว +1

    Nailed it! Can I ask for the link for Blue Team Series part 1?

  • @darkaura4949
    @darkaura4949 2 ปีที่แล้ว +1

    I have a query, why are you using this wazuh? and how to connect a Suricata on "switch/router" to collect all logs connected to my network?

  • @musicmodi5686
    @musicmodi5686 2 ปีที่แล้ว +1

    i like you man good luck

  • @jackiechan3539
    @jackiechan3539 2 ปีที่แล้ว

    thanks for the session. It's good for beginners like me. However, I cannot figure out what is the difference between snort and Suricata. What is the use cases that we must use snort instead of Suricata?. thanks.

  • @Rc28300
    @Rc28300 ปีที่แล้ว

    Very nice video !!

  • @angelnavarro476
    @angelnavarro476 2 ปีที่แล้ว

    Great video!

  • @chisomokavina107
    @chisomokavina107 2 ปีที่แล้ว +3

    brilliant, and am following

  • @0x_hacks
    @0x_hacks ปีที่แล้ว

    If we use wazuh for logs analysis,ids and ips then why we learn about snort and suricata and why we use these tools?

  • @8080VB
    @8080VB 2 ปีที่แล้ว

    12:13 wasn't that you were looking? It's there!

  • @domiflichi
    @domiflichi ปีที่แล้ว

    How would I get the logs from Suricata into Wazuh if Suricata is running on a separate PC?

    • @domiflichi
      @domiflichi ปีที่แล้ว

      Nevermind. I somehow missed the fact that you used the Wazuh agent on the Suricata PC. Thanks for the video!

  • @Damielsestrem
    @Damielsestrem ปีที่แล้ว

    is it possible to forward suricata logs to graylog too?

  • @megherbifatminoureddine2148
    @megherbifatminoureddine2148 หลายเดือนก่อน

    Could you please show us how to install Suricata on Windows? Thanks

  • @taimurahmed5617
    @taimurahmed5617 2 ปีที่แล้ว

    Thanks alot for such an informative session. I have a query is it possible that I can send my suricata alerts to a newly created indice rather than sending it to wazuh_alerts*? can you please guide me in this regard

  • @tanaypatil4949
    @tanaypatil4949 2 ปีที่แล้ว

    How to use Suricata as inline IPS and forward logs to any SIEM(Wazuh/splunk/Alienfualt)

  • @josebaezc.7709
    @josebaezc.7709 2 ปีที่แล้ว

    Muy bien. Te voy siguiendo.

  • @pedrodiaz5338
    @pedrodiaz5338 2 ปีที่แล้ว

    Wazuh detect ssh brutte force attacks?

  • @JoaoSilva-ny1tl
    @JoaoSilva-ny1tl 2 ปีที่แล้ว

    can you connect the suricata windows logs to Wazuh?
    If so can anyone explain how?

  • @cartercharbonneau1028
    @cartercharbonneau1028 ปีที่แล้ว

    Can this be done with Windows?

  • @azrilwaiz2495
    @azrilwaiz2495 2 ปีที่แล้ว

    Thanks

  • @h4cklearning547
    @h4cklearning547 2 ปีที่แล้ว

    Nice

  • @ashifkhan16909
    @ashifkhan16909 2 ปีที่แล้ว

    Bro i challenge can you hack Awaken monster battle adventure it is not available in playstore

  • @christiankhairallah397
    @christiankhairallah397 ปีที่แล้ว

    quick remark for me it didn't work on ubuntu in ossec.conf syslog but when i change it to json i started receiving the logs in wazuh manager