Wazuh Custom Decoders - Ingest Any Log Into Wazuh By Building Your Own Decoders!

Поділитися
Вставка
  • Опубліковано 27 жов 2024

КОМЕНТАРІ • 20

  • @MeKaliLin-wq8zy
    @MeKaliLin-wq8zy 11 місяців тому +2

    Hey Taylor this is the most important video I have seen on Wazuh. Clearly that you are a very good hearted person. I hope everyone that is in a position to buy you a cup of coffee is doing that right now.

  • @domiflichi
    @domiflichi Рік тому +1

    Awesome video, thank you! I was really having a hard time understanding decoders in Wazuh, but this really clears things up for me. Thank you again!

  • @seb1190
    @seb1190 3 місяці тому +2

    Great explanation, thanks a lot Taylor!

  • @quank32
    @quank32 Місяць тому

    This is solid content. Please keep it up.

  • @Roman-m3u4h
    @Roman-m3u4h 11 місяців тому +1

    Have you tried Enhance Speech from Adobe to improve the sound?

  • @andrijaradicevic3472
    @andrijaradicevic3472 Рік тому

    HI Taylor, thank you for the great video. I have tried to write a decoder for a Wildfly log, however it didn't work out. It is interesting that the pre-deconding phase extracts the timestamp from the full event. In my decoder I have tried to match the timestamp, even just one digit at the start of the line but it never matches the decoder. What am I missing?

  • @dwieztro6748
    @dwieztro6748 23 дні тому

    Soo we don't need setup local file location on wazuh agent?

  • @vugiang2836
    @vugiang2836 9 місяців тому

    Thank bro, you help me solution problem stuck one day

  • @issamzgybi9761
    @issamzgybi9761 Рік тому

    My Man 👍

  • @alejandrojaramillo8590
    @alejandrojaramillo8590 2 роки тому +1

    Great video!
    Do you know the max EPS that wazuh (through syslog) can ingest and correlate?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 роки тому

      Really depends on the specs (cpu and memory) dedicated to your wazuh manger....but if you start to run into issues, i recommend clustering the wazuh managers to enable more throughput

  • @miguelsaiz8151
    @miguelsaiz8151 Рік тому

    Great video

  • @linktel7694
    @linktel7694 2 роки тому

    Very nice video, thank you very much !!!!

  • @ElleDriver
    @ElleDriver 2 роки тому

    I have been waiting for this video for months, thank you!! It is necessary to activate/change something somewhere to use custom decoders? the parent decoder is not working for me (I have tested with your code and log sample. I have tested with just a few numbers in Decoders Tool with same result: No result found for:...)

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 роки тому +1

      Only thing you should need to do is restart the wazuh-manager service. Let me know if that still gives you issues.

    • @ElleDriver
      @ElleDriver 2 роки тому

      @@taylorwalton_socfortress Well, I tried with logs from a Synology NAS. Every step was ok but, in Kibana I see the generated alert but is not showing the log content from NAS alert, instead I have: decoder.name-> synology-nas, full_log > lun 02 may 2022 10[:]11[:]20 CEST active-response/bin/restart[.]sh manager, location -> /var/ossec/logs/active-responses.log, why is that? The alert fields are showing other log content but with NAS decoder and rule fired, how it is possible? :( Thank you!

  • @bakhtiyaramirshin6720
    @bakhtiyaramirshin6720 2 роки тому

    Hey Bro! You know how to automatization restart incidents in wazuh?