Triage overnight alerts in 10 minutes instead of 2 hours
When to use: Shift start. Hundreds of alerts overnight. You need to find the real ones without reading every row.
Prerequisites
- Wazuh Manager API creds — Wazuh UI > API credentials
Flow
-
SummarizeFor last 12 hours: group alerts by rule group, count severity 10+ per group, top 5 agents with most high-sev alerts.✓ Copied→ Ranked summary
-
InvestigateFor top agent, pull the 10 most recent high-sev alerts with full details.✓ Copied→ Detailed events
-
Determine actionBased on these events, is this a true positive? If yes, propose response: isolate agent / disable account / create ticket.✓ Copied→ Verdict + action plan
Outcome: Faster MTTD/MTTR without more eyeballs.
Pitfalls
- Auto-triggering active response before confirming — Keep active response tools behind a confirmation gate