Integration with Wazuh
I have followed the blog (https://www.zenarmor.com/docs/guides/integrating-zenarmor-with-wazuh) to integrate Zenarmor with Wazuh but alerts are not appearing in index.
I can see alters in archive.log and sample alerts pass rule test but nothing in open search indices.
Any ideas?
-
Its pretty tricky to pinpoint exactly where it is going wrong with the limited info, but if I were to guess, I would start by checking that Zenarmor is pointed to the correct IP address and Port that Wazuh is listening on and in the Wazuh configs, make sure the port and protocol matches, and that the IP of the Zenarmor instance is in the allowed list, to start
Please sign in to leave a comment.
Comments
1 comment