Wazuh forwards an alert to a protected n8n webhook.
Wazuh + n8n
Wazuh SOC L1 Alert Triage
A production-shaped SOC L1 pipeline that turns raw Wazuh events into consistent, explainable triage packages. Analysts receive the evidence, severity, score, and next action without manually rebuilding context for every alert.
3Connected workflows
100Max risk score
L1Analyst ready
SYSTEM ARCHITECTURE
From raw signal to accountable decision.
Rules normalize fields, extract entities, and calculate risk.
A structured L1 report is generated and stored for review.
Analyst decisions feed false-positive and metrics tables.
PROCESS
01Ingest02Normalize03Score04Report05Decide06Measure
CAPABILITIES
What the automation delivers.
Wazuh JSON normalization
Explainable risk scoring
Entity extraction
Decision API
False-positive tracking
Daily SOC metrics
SAMPLE OUTPUT
Suspicious PowerShell execution
SEVERITYCritical
RISK SCORE100 / 100
RECOMMENDATIONEscalate to L2
Webhook endpoint: /webhook/wazuh-alert