Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[🔌 Provider]: Wazuh cyber related alerts can be very helpful #2702

Open
Greatz08 opened this issue Nov 29, 2024 · 11 comments · May be fixed by #3065
Open

[🔌 Provider]: Wazuh cyber related alerts can be very helpful #2702

Greatz08 opened this issue Nov 29, 2024 · 11 comments · May be fixed by #3065
Assignees
Labels
Good First Issue Good for newcomers Provider Providers related issues

Comments

@Greatz08
Copy link

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
It is cybersec tool which can generate alot of alerts based on how we setup and those can be very helpful for those who are using it and i would like to check its alerts from this project so because of this reason i am sharing this provider

Thankyou very much for this great project :-))

@Greatz08 Greatz08 added the Provider Providers related issues label Nov 29, 2024
@shahargl
Copy link
Member

hey @Greatz08 , thanks for opening this issue :) are you using Keep?

@Motii1
Copy link

Motii1 commented Nov 29, 2024

@Greatz08 It would be nice to have out of the box support for Wazuh, but have you tried to integrate Wazuh with Keep using wazuh custom integration and adding a custom keep provider. I am also interested in this feature

@shahargl
Copy link
Member

hey @Motii1, are you from the wazuh team?

@Motii1
Copy link

Motii1 commented Nov 29, 2024

@shahargl No, but I use Wazuh as a security scanner on my servers.
Wazuh alerts generate a lot of noise so Keep seems perfect for alerting, automation, and noise reduction.

I’d be happy to contribute by submitting a PR for a Wazuh provider. However, as I’m relatively new to KeepHQ, I would greatly appreciate any guidance or resources to help me get started.

@shahargl
Copy link
Member

shahargl commented Nov 29, 2024

@Motii1 let's write it together! how are you about joining our Slack (https://slack.keephq.dev) and we will collaborate on that?

@Greatz08
Copy link
Author

@shahargl right now i haven't installed keep but will surely test very soon :-))

@Greatz08
Copy link
Author

@Motii1 i havent tested this one out as i am recently trying to setup wazuh again in my system due to some mess i created by mistake :-)

@shahargl
Copy link
Member

You can join our slack we already start to collaborate on developing it 💪

@Matvey-Kuk Matvey-Kuk added the Good First Issue Good for newcomers label Jan 12, 2025
@Matvey-Kuk
Copy link
Contributor

Labeling this one as a Good First Issue.

Use https://docs.keephq.dev/providers/adding-a-new-provider as a starting point :)

If you want to work on this, join Slack and we will help: https://slack.keephq.dev/ !

@Motii1
Copy link

Motii1 commented Jan 12, 2025

Labeling this one as a Good First Issue.

Use https://docs.keephq.dev/providers/adding-a-new-provider as a starting point :)

If you want to work on this, join Slack and we will help: https://slack.keephq.dev/ !

Already prepared most of the implementation locally. I will submit PR as soon as possibile 😄

@Matvey-Kuk
Copy link
Contributor

@Motii1 great! I'll assign to you, thank you!

@traceroute42 traceroute42 linked a pull request Jan 19, 2025 that will close this issue
4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Good First Issue Good for newcomers Provider Providers related issues
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants