Hello there!

Need Help? We are right here!

Support Icon
miniOrange Email Support
success

Thanks for your Enquiry. Our team will soon reach out to you.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to info@xecurify.com

Search Results:

×

Wazuh SIEM Integration Setup


Wazuh is an open-source platform for threat detection, analysis log data, and compliance that integrates with SIEM. miniOrange provides secure access and full control to Wazuh for enterprises and applications. With the help of the given guide you can configure Wazuh easily.


Get Free Installation Help


miniOrange offers free help through a consultation call with our System Engineers to Install or Setup Strapi SSO solution in your environment with 30-day free trial.

For this, you need to just send us an email at idpsupport@xecurify.com to book a slot and we'll help you in no time.



1. Create a user account for API authentication

  • Log into your Wazuh dashboard as an admin.
  • Click on the hamburger menu icon present on the left top section.
  • Navigate to Server Management > Security.
  • Click on the Create User button under the User tab.
  • Provide any username and password.
  • You can keep the Allow run as option disabled.
  • Select the user role as administrator and click on the Apply button.
  • miniOrange Audits in Wazuh Create new user

  • Configure the above username and password in miniOrange to sync the audit logs.

2. Add a rule to use JSON decoder

  • From your Wazuh admin dashboard, open the left menu option.
  • Navigate to Server Management > Rules.
  • Click on the Add new Rules file button.
  • miniOrange Audits in Wazuh Click to Add new rule file

  • Provide any file name and add the following rules in the provided area:
                  
                    <group name="audit">
                      <rule id="222001" level="4">
                        <decoded_as>json</decoded_as>
                        <description>miniOrange Audit messages</description>
                      </rule>
                    </group>
                  
                

    Note: If the rule id 222001 is already assigned to a different rule in your Wazuh instance, you can set any other rule id above. You can also change the log level as per your requirement.


  • miniOrange Audits Rules Click Save

  • Finally click on the Save button.
  • After saving, click on the Restart button when prompted on your Wazuh dashboard.

3. Enabling Event Forwarding

  • Share the following information with us and we will enable the event forwarding to your Wazuh instance:
    • Username and Password of the newly created user.
    • Server IP and Port to forward the events.


Want To Schedule A Demo?

Request a Demo
  



Our Other Identity & Access Management Products