Triage overnight alerts in 10 minutes instead of 2 hours
何時使用: Shift start. Hundreds of alerts overnight. You need to find the real ones without reading every row.
前置條件
- Wazuh Manager API creds — Wazuh UI > API credentials
步驟
-
SummarizeFor last 12 hours: group alerts by rule group, count severity 10+ per group, top 5 agents with most high-sev alerts.✓ 已複製→ Ranked summary
-
InvestigateFor top agent, pull the 10 most recent high-sev alerts with full details.✓ 已複製→ Detailed events
-
Determine actionBased on these events, is this a true positive? If yes, propose response: isolate agent / disable account / create ticket.✓ 已複製→ Verdict + action plan
結果: Faster MTTD/MTTR without more eyeballs.
注意事項
- Auto-triggering active response before confirming — Keep active response tools behind a confirmation gate