AI SOC Analyst for Wazuh - Multi-Host Log Pull over SSH
automation · $49.99
Your Wazuh alert arrives with the actual log lines already pulled off the server
One n8n workflow does the tier-1 job for you. It works out which OS the host runs, logs in over SSH, pulls the real log lines around the event, checks the IP against VirusTotal and AbuseIPDB, and has a local AI write the incident report. Linux, Windows and macOS. Nothing leaves your network.
The problem
Wazuh is good at telling you something happened. It does not tell you what it means.
So a person has to do the same six steps on every alert:
Look up the source IP.
SSH into the host.
tailthe logs and read around the timestamp.Decide if it is real or a false positive.
Write it up.
Paste it in a channel.
Step 2 and 3 are the slow ones. You need the right host, the right log file, the right command for that OS - and on Windows it isn't tail at all. It takes ten minutes. You do it fifty times a day.
And when one brute force fires 200 alerts, you do it 200 times for the same attacker.
What makes this one different
Most alert-automation workflows only forward what Wazuh already told you. This one goes and gets the evidence.
It opens a real SSH session on the host that raised the alert and pulls the log lines around the event - journalctl or tail on Linux, Get-WinEvent on Windows, log show on macOS. It picks the right one by working out the OS from the agent, the decoder, the program name, the log content and the rule groups.
That means the report you read is written from the actual logs, not from a one-line alert summary.
If SSH into every host is not an option for you, we make an API-only edition too - see the bottom of this page.
What it does
Cleans the input first. An alert carrying
srcip: "1.2.3.4; rm -rf /"never reaches an SSH command. The IP is validated as real IPv4/IPv6 and shell characters are stripped at the very first node.Kills the duplicates. Same IP, same rule, same agent inside your window? One report, one VirusTotal lookup, one AI pass - not two hundred.
Finds the OS, then pulls the logs. Linux, Windows or macOS, with the right command for each.
Checks the IP. VirusTotal and AbuseIPDB, combined into one 0–100 threat score: CRITICAL, HIGH, MEDIUM or LOW.
Thinks twice, on purpose. Two AI passes: first the raw logs are turned into structured findings, then the incident report is written from those findings plus the threat intel. One pass over raw logs gives you vague reports - this gives you specifics.
Writes the report. Verdict, false-positive call, MITRE technique, and the actions to take right now.
Handles CVE alerts separately. Wazuh vulnerability-detector alerts take their own path and come back as a plain-language CVE summary instead of an incident report.
Sends it everywhere at once. Discord, Slack, Telegram, email - any combination, in parallel. A dead Slack webhook cannot stop the Discord message.
Blocks the attacker (only if you say so).
sudo ufw deny from <ip>, behind four gates.
The AI runs on Ollama, on your own hardware. Alert contents, log excerpts and hostnames never go to a cloud model.
Where the safety rails are
This workflow holds SSH credentials and can write firewall rules. So it is built to be careful.
Input is sanitised before the first SSH session, not after. This is the single most important line of code in the product.
Turn blocking off for your first run. The setup guide has you set
BLOCK_ENABLED: falseon step 2, so you can watch it report for a week before it touches a firewall.Four things must agree before a real block. Blocking on, IP not whitelisted, VirusTotal over your threshold, and rule level over your floor.
The whitelist ships pre-filled with private ranges and the common public DNS resolvers - so you cannot lock yourself out of your own network on day one.
It catches its own failures. Any node that breaks reports itself to Discord instead of dying quietly.
How it works
Import the workflow into n8n.
Open one ⚙️ CONFIGURATION node and set your preferences. Every setting lives here.
Map your hosts. Rename the agent names in the two
Route to VM by Agentswitches and attach your SSH credentials. This is the real work - the setup guide walks it click by click.Attach the rest: VirusTotal, AbuseIPDB, Ollama, and one delivery channel.
Point Wazuh at the webhook and fire one of the included test alerts.
About 30 minutes to your first live report.
Be straight with yourself about step 3. This edition needs SSH from n8n to every host you want logs from. If that is a fight with your network team, buy the API edition instead - link at the bottom.
Requirements
n8n v1.x or newer
Wazuh 4.x sending level 12+ alerts to an n8n webhook
SSH from n8n to every host you want to pull logs from - OpenSSH on Linux/macOS, OpenSSH Server on Windows
An Ollama endpoint (or swap in a cloud model - the guide shows you how)
VirusTotal and AbuseIPDB API keys - the free tiers are enough
One place to send reports: Discord, Slack, Telegram or SMTP
For auto-blocking only:
ufwon the targets and passwordlesssudofor it
$49.99 - one time.
No subscription. No per-alert fee. No seat count. You buy the workflow, you own it.
Your analyst spends about ten minutes writing up one alert. This costs less than one afternoon of that.
And there is no vendor in the middle. It runs in your n8n, against your hosts, with an AI model on your hardware. Nothing to renew, nothing that can be switched off from the outside.
Who it is for
SOC engineers, MSPs and one-person security teams running Wazuh across a handful of servers they already have SSH on - and who want the report written from real log lines, not from an alert summary.
7-day guarantee
If it doesn't work as described, or it isn't what you needed, contact us within 7 days of purchase and we'll refund you in full. If you'd rather have it working, say so and we'll help you get it running. Your call. Full terms.
Questions? Reach out on the contact section