Hello there!

Need Help? We are right here!

Support Icon
miniOrange Email Support
success

Thanks for your Enquiry. Our team will soon reach out to you.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to info@xecurify.com

Search Results:

×

Wazuh SIEM Integration Setup


Wazuh is an open-source platform for threat detection, analysis log data, and compliance that integrates with SIEM. miniOrange provides secure access and full control to Wazuh for enterprises and applications. With the help of the given guide you can configure Wazuh easily.


Get Free Installation Help


miniOrange offers free help through a consultation call with our System Engineers to setup SIEM integration with your Wazuh Instance in your environment with 30-day free trial.

For this, you need to just send us an email at idpsupport@xecurify.com to book a slot and we'll help you in no time.



1. Create a user account for API authentication

  • Log into your Wazuh dashboard as an admin.
  • Click on the hamburger menu icon present on the left top section.
  • Navigate to Server Management > Security.
  • Click on the Create User button under the User tab.
  • Provide any username and password.
  • You can keep the Allow run as option disabled.
  • Select the user role as administrator and click on the Apply button.
  • miniOrange Audits in Wazuh Create new user

  • Configure the above username and password in miniOrange to sync the audit logs.

2. Add a rule to use JSON decoder

  • From your Wazuh admin dashboard, open the left menu option.
  • Navigate to Server Management > Rules.
  • Click on the Add new Rules file button.
  • miniOrange Audits in Wazuh Click to Add new rule file

  • Provide any file name and add the following rules in the provided area:
                  
                    <group name="audit">
                      <rule id="222001" level="4">
                        <decoded_as>json</decoded_as>
                        <description>miniOrange Audit messages</description>
                      </rule>
                    </group>
                  
                

    Note: If the rule id 222001 is already assigned to a different rule in your Wazuh instance, you can set any other rule id above. You can also change the log level as per your requirement.


  • miniOrange Audits Rules Click Save

  • Finally click on the Save button.
  • After saving, click on the Restart button when prompted on your Wazuh dashboard.

3. Configure Wazuh API Endpoint in miniOrange

  • Login into miniOrange Admin Console.
  • Go to SIEM Management and click on Configure button.
  • miniOrange Audits in Wazuh SIEM Management Configure Tab in miniOrange Admin Console

  • Select Wazuh siem tool and click on next.
  • Select Wazuh tab

  • Provide the name for the SIEM tool.
  • Make sure to enter the Endpoint URL.

  • Make sure to add Username and Password created using WAZUH Dashboard.
  • In order to save the Wazuh SIEM configuration click on save.
  •  miniOrange Audits in Wazuh ADD SIEM Configuration

  • Click on activate toggle button in oder to active the SIEM Tool.
  •  miniOrange Audits in Wazuh Activate SIEM Configuration

    miniOrange Audits in Wazuh Configuration Activated Successfully

    Note:

    Superadmin can also activate the SIEM tool for customers using the Manage activation options. Admin can either activate the SIEM tool for all the customers using Activate For all customers option or can activate for individual customers using manage activation option available under the actions menu by clicking on 3 dots.
    Please follow this guide to know more.



  • Select Activate For All Customers :
    • Superadmin can toggle Activate For All Customers to enable the SIEM tool for all tenants in one action.
    miniOrange Audits in Wazuh Select Activate For All Customers

  • Select Manage Activation :
    • Superadmin can use Manage Activation to selectively enable the SIEM tool for individual customer accounts.
    miniOrange Audits in Wazuh Select Manage Activation

4. Monitor Logs in the Wazuh Dashboard

  • Now login to Wazuh dashboard to monitor all the logs.
  • In Wazuh Dashboards Discover logs you should be able to see the logs captured.

    miniOrange Audits in Wazuh Wazuh Dashboards Discover logs

Want To Schedule A Demo?

Request a Demo
  



Our Other Identity & Access Management Products