API Extensions Pattern About
Welcome to the Wazuh App for Kibana 6
The Wazuh App brings together a new and useful web interface for managing and monitoring your Wazuh infrastructure. You can check agent status, alert evolution, most recent events, popular alerts, top alert groups, etc. You can also display configuration and logs of the manager.
In addition, make use of any or all of these extensions:
  • Linux Audit system integration
  • PCI DSS Compliance
  • GDPR Compliance
  • OpenSCAP security compliance and vulnerability assessments
  • Amazon Web Services (AWS) integration
  • VirusTotal integration
The app joins Wazuh features like:  Log management and analysis,  file integrity monitoring,  intrusion and anomaly detection  and  policy and compliance monitoring.
Help us to improve this app. We would appreciate your feedback. Collaborate with us on the  mailing lists  and/or the Wazuh App  Github repository.
Wazuh API seems to be down
Please, check if Wazuh RESTful API is running with one of the commands below:
  • For Systemd:
  • # systemctl status wazuh-api
  • For SysV Init:
  • # service wazuh-api status
If the API is active (running) please check its configuration below.
Wazuh App: API configuration

Cluster

Manager

API URL

API Port

User

Actions

{{entry._source.cluster_info.cluster}}

{{entry._source.cluster_info.manager}}

{{entry._source.url}}

{{entry._source.api_port}}

{{entry._source.api_user}}

{{messageErrorUpdate}}

Update API
Add new API

{{messageError}}

Save API
Wazuh App: Extensions
Enable or disable extensions according to your needs. The extension includes: Panels and Discover, for Overview / Agents tabs.
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit cards from the major card schemes including Visa, MasterCard, American Express, Discover, and JCB. The PCI Standard is mandated by the card brands and administered by the Payment Card Industry Security Standards Council. The standard was created to increase controls around cardholder data to reduce credit card fraud.
GDPR
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union. It also addresses the export of personal data outside the EU. The GDPR aims primarily to give control to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.
OpenSCAP
OVAL (Open Vulnerability Assessment Language) interpreter used to check system configuration and detect vulnerable applications.
It is recognized as a standardized compliance and hardening checking solution for enterprise-level infrastructure.
Audit
The Linux Audit system provides a way to track security-relevant information on your system.
Based on pre-configured rules, Audit generates log entries to record as much information about the events that are happening on your system as possible.
Amazon Web Services (AWS)
Wazuh provides a way to collect alerts from your AWS machines and store them to an agent. Once the agent reads the message, it sends it to the Wazuh manager which analyses it with decoders and rules.
When a rule matches, an alert is triggered if the rule severity is high enough. Wazuh can be used to alert on specific events from IAM, EC2 and VPC.
VirusTotal
VirusTotal is an online service that analyzes files and URLs enabling the detection of viruses, worms, trojans and other kinds of malicious content using antivirus engines and website scanners.
It also can be used to detect false positives.
Wazuh App: Index pattern selection
Select the index pattern to run search and analytics against.
Beware: the new index-pattern structure must be compatible with Wazuh alerts, otherwise the visualizations will load erroneous data, or no data at all.
Wazuh App: About
The Wazuh App brings together a new and useful web interface for managing and monitoring your Wazuh infrastructure. You can check agent status, alert evolution, most recent events, popular alerts, top alert groups, etc. You can also display configuration and logs of the manager.
In addition, make use of any or all of these extensions:
  • Linux Audit system integration
  • PCI DSS Compliance
  • GDPR Compliance
  • OpenSCAP security compliance and vulnerability assessments
  • Amazon Web Services (AWS) integration
  • VirusTotal integration
The app joins Wazuh features like:  Log management and analysis,  file integrity monitoring,  intrusion and anomaly detection  and  policy and compliance monitoring.
Help us to improve this app. We would appreciate your feedback. Collaborate with us on the  mailing lists  and/or the Wazuh App  Github repository.
Wazuh App: Version
App version {{appInfo["app-version"]}}
Install date {{appInfo["installationDate"]}}
Revision {{appInfo["revision"]}}