Welcome to the Wazuh app for Splunk
Wazuh Splunk plugin provides management and monitoring capabilities, giving users control over the Wazuh infrastructure. Using this plugin you can monitor the status of your agents and configuration, query and visualize your alert data and manage your Wazuh configuration and configuration.
Community
Enjoy your Wazuh experience and please don't hesitate to give us your feedback.
Wazuh API configuration Use Wazuh API settings to connect the Splunk app to your Wazuh manager or cluster
Please wait
Kv Store is being initialized please wait some seconds and try again later.

API alias

Cluster

Manager

API URL

API Port

User

Run as

Actions

{{entry.alias}} This is the default Manager

{{ (entry.filterType === 'cluster.name') ? entry.filterName : 'Disabled'}}

{{entry.managerName}}

{{entry.url}}

{{entry.portapi}}

{{entry.userapi}}

'Run as' is {{ getIconAndTooltip(entry).tooltip }}

WARNING
Run_as permissions can only be obtained with the wazuh-wui user.

{{messageError}}

  • {{ err }}
WARNING
Run_as permissions can only be obtained with the wazuh-wui user.

{{messageError}}

  • {{ err }}

Oops, it looks like there is nothing to show here

No Wazuh Manager (API) has been added to this installation yet. Only the Splunk administrators can add, modify or delete Wazuh Managers, as write permissions are required. Please, get in contact with the administrator or log in with an administrator user.

WARNING
Run_as permissions can only be obtained with the wazuh-wui user.

{{messageError}}

  • {{ err }}