All automations

Wazuh + Splunk + Gemini + n8n

Wazuh + Splunk AI Log Analyzer

A portable investigation workflow for Wazuh and Splunk exports. It normalizes uploaded events, applies deterministic detection logic, uses Gemini to build a structured incident narrative, and saves a professional PDF report while preserving human approval for every response action.

2Supported SIEMs
PDFReport output
100Max risk score

SYSTEM ARCHITECTURE

From raw signal to accountable decision.

01 / Input

An analyst uploads a supported SIEM export or pastes events into a protected n8n form.

02 / Detect

Normalization and deterministic rules identify attack patterns, entities, and risk.

03 / Explain

Gemini creates a validated narrative, investigation plan, and containment guidance.

04 / Export

The complete case report is rendered as a PDF and saved with a unique case ID.

PROCESS

01Upload02Normalize03Score04AI Analyze05Validate06PDF

CAPABILITIES

What the automation delivers.

Wazuh and Splunk parsing

Deterministic risk scoring

Gemini investigation narrative

MITRE ATT&CK mapping

IOC extraction

PDF report generation

SAMPLE OUTPUT

Credential access and encoded PowerShell

SEVERITYCritical

RISK SCORE80 / 100

RECOMMENDATIONEscalate

Webhook endpoint: /form/{workflow-form-id}