All automations

Wazuh + n8n

Wazuh SOC L1 Alert Triage

A production-shaped SOC L1 pipeline that turns raw Wazuh events into consistent, explainable triage packages. Analysts receive the evidence, severity, score, and next action without manually rebuilding context for every alert.

3Connected workflows
100Max risk score
L1Analyst ready

SYSTEM ARCHITECTURE

From raw signal to accountable decision.

01 / Ingest

Wazuh forwards an alert to a protected n8n webhook.

02 / Analyze

Rules normalize fields, extract entities, and calculate risk.

03 / Report

A structured L1 report is generated and stored for review.

04 / Learn

Analyst decisions feed false-positive and metrics tables.

PROCESS

01Ingest02Normalize03Score04Report05Decide06Measure

CAPABILITIES

What the automation delivers.

Wazuh JSON normalization

Explainable risk scoring

Entity extraction

Decision API

False-positive tracking

Daily SOC metrics

SAMPLE OUTPUT

Suspicious PowerShell execution

SEVERITYCritical

RISK SCORE100 / 100

RECOMMENDATIONEscalate to L2

Webhook endpoint: /webhook/wazuh-alert