Wazuh integration crowdsec

I am having some trouble to create alert rules for CrowdSec in Wazuh. The logs come correctly to wazuh-manager, please I need some help. Thanks in advance.
No description
8 Replies
CrowdSec
CrowdSec3w ago
Important Information
Thank you for getting in touch with your support request. To expedite a swift resolution, could you kindly provide the following information? Rest assured, we will respond promptly, and we greatly appreciate your patience. While you wait, please check the links below to see if this issue has been previously addressed. If you have managed to resolve it, please use run the command /resolve or press the green resolve button below.
Log Files
If you possess any log files that you believe could be beneficial, please include them at this time. By default, CrowdSec logs to /var/log/, where you will discover a corresponding log file for each component.
Guide Followed (CrowdSec Official)
If you have diligently followed one of our guides and hit a roadblock, please share the guide with us. This will help us assess if any adjustments are necessary to assist you further.
Screenshots
Please forward any screenshots depicting errors you encounter. Your visuals will provide us with a clear view of the issues you are facing.
© Created By WhyAydan for CrowdSec ❤️
Loz
Loz3w ago
The logs come correctly to wazuh-manager
Okay so what is the problem?
yanhost
yanhostOP3w ago
Hello, I've no alert in dashboard with these rules : <group name="crowdsec,"> <!-- We consider that all CrowdSec alerts are important. --> <rule id="100002" level="12"> <decoded_as>json</decoded_as> <field name="crowdsec.program">crowdsec</field> <description>CrowdSec alert: $(crowdsec.alert.message)</description> </rule> <rule id="100003" level="3"> <if_sid>100002</if_sid> <field name="crowdsec.alert.message">test alert</field> <description>Test alert for CrowdSec.</description> </rule> </group>
yanhost
yanhostOP3w ago
This is result of command "cscli notifications test file_default" in wazuh-manager. A Python script is necessary to truly integrate CrowdSec with Wazuh ?
No description
yanhost
yanhostOP3w ago
Or not ?
yanhost
yanhostOP3w ago
Because I've just this in Wazuh-dashboard about Crowdsec
No description
yanhost
yanhostOP3w ago
Hello I solved the problem alone, thanks:
No description
yanhost
yanhostOP3w ago
I read directly /var/log/crowdsec.log ++ use aws decoder as template 🙂

Did you find this page helpful?