Triage overnight alerts in 10 minutes instead of 2 hours
Cuándo usarlo: Shift start. Hundreds of alerts overnight. You need to find the real ones without reading every row.
Requisitos previos
- Wazuh Manager API creds — Wazuh UI > API credentials
Flujo
-
SummarizeFor last 12 hours: group alerts by rule group, count severity 10+ per group, top 5 agents with most high-sev alerts.✓ Copiado→ Ranked summary
-
InvestigateFor top agent, pull the 10 most recent high-sev alerts with full details.✓ Copiado→ Detailed events
-
Determine actionBased on these events, is this a true positive? If yes, propose response: isolate agent / disable account / create ticket.✓ Copiado→ Verdict + action plan
Resultado: Faster MTTD/MTTR without more eyeballs.
Errores comunes
- Auto-triggering active response before confirming — Keep active response tools behind a confirmation gate