An analyst uploads a supported SIEM export or pastes events into a protected n8n form.
Wazuh + Splunk + Gemini + n8n
Wazuh + Splunk AI Log Analyzer
A portable investigation workflow for Wazuh and Splunk exports. It normalizes uploaded events, applies deterministic detection logic, uses Gemini to build a structured incident narrative, and saves a professional PDF report while preserving human approval for every response action.
SYSTEM ARCHITECTURE
From raw signal to accountable decision.
Normalization and deterministic rules identify attack patterns, entities, and risk.
Gemini creates a validated narrative, investigation plan, and containment guidance.
The complete case report is rendered as a PDF and saved with a unique case ID.
PROCESS
CAPABILITIES
What the automation delivers.
Wazuh and Splunk parsing
Deterministic risk scoring
Gemini investigation narrative
MITRE ATT&CK mapping
IOC extraction
PDF report generation
SAMPLE OUTPUT
Credential access and encoded PowerShell
SEVERITYCritical
RISK SCORE80 / 100
RECOMMENDATIONEscalate
Webhook endpoint: /form/{workflow-form-id}