OPNsense Forum

English Forums => Zenarmor (Sensei) => Topic started by: beki on August 28, 2023, 04:56:18 PM

Title: Integrating Zenarmor with Wazuh - A guide to SIEM integration using Syslog
Post by: beki on August 28, 2023, 04:56:18 PM
Dear valued Zenarmor user,

In the world of cybersecurity, having a robust and efficient Security Information and Event Management (SIEM) system is crucial. SIEM systems provide real-time analysis of security alerts generated by applications and network hardware.

In the following guide, you can explore how to integrate Zenarmor, a powerful network security solution, with Wazuh, a free and open-source SIEM and XDR solution, using the easy-to-configure Syslog event messages automatically generated by Zenarmor, for seamless and efficient security incident management.

https://www.zenarmor.com/post/integrating-zenarmor-with-wazuh-a-guide-to-siem-integration-using-syslog

Have a good read...

zenarmor Team
Title: Re: Integrating Zenarmor with Wazuh - A guide to SIEM integration using Syslog
Post by: athurdent on August 28, 2023, 06:00:00 PM
Thank you for the nice write up!
As Zenamor is already sending daily mails to my inbox, I'd love to see this kind of alerting directly from Zenamor. Would be great if it had a notification functionality for threads in general, so we could act on them quickly.
Title: Re: Integrating Zenarmor with Wazuh - A guide to SIEM integration using Syslog
Post by: mokaz on February 28, 2024, 02:28:29 PM
Hi there team,

Is this "still" supposed to work with current versions of either Wazuh or OPNsense?
I can't get this to trigger any alerts in Wazuh, syslogs are coming through though.

Let me know,
Thanks & regards,
m.
Title: Re: Integrating Zenarmor with Wazuh - A guide to SIEM integration using Syslog
Post by: sy on February 29, 2024, 04:07:37 PM
Hi @athurdent,

It is in our roadmap that sending a notification for the threats.