Triage overnight alerts in 10 minutes instead of 2 hours
Когда использовать: Shift start. Hundreds of alerts overnight. You need to find the real ones without reading every row.
Предварительные требования
- Wazuh Manager API creds — Wazuh UI > API credentials
Поток
-
SummarizeFor last 12 hours: group alerts by rule group, count severity 10+ per group, top 5 agents with most high-sev alerts.✓ Скопировано→ Ranked summary
-
InvestigateFor top agent, pull the 10 most recent high-sev alerts with full details.✓ Скопировано→ Detailed events
-
Determine actionBased on these events, is this a true positive? If yes, propose response: isolate agent / disable account / create ticket.✓ Скопировано→ Verdict + action plan
Итог: Faster MTTD/MTTR without more eyeballs.
Подводные камни
- Auto-triggering active response before confirming — Keep active response tools behind a confirmation gate