AI SOC Analyst L1 for Wazuh - Triage and Incident Reports

automation · $49.99

Your Wazuh alerts get investigated and written up before you open your laptop

One n8n workflow does the tier-1 job for you: it pulls the context from your Indexer, checks the IP against VirusTotal and AbuseIPDB, has a local AI write the incident report, and drops it in Discord, Slack, Telegram or your inbox. No SSH. Nothing leaves your network.

The problem

Wazuh is good at telling you something happened. It does not tell you what it means.

So a person has to do the same six steps on every alert:

1. Look up the source IP.

2. Search the Indexer to see what else that host did.

3. Decide if it is real or a false positive.

4. Guess the MITRE technique.

5. Write it up.

6. Paste it in a channel.

It takes ten minutes. You do it 50 times a day. And when one brute-force burst fires 200 alerts, you do it 200 times for the same attacker.

That is not analysis. That is copy and paste. Real threats hide in the middle of it.

The AI SOC Analyst L1 workflow canvas in n8n, grouped into configuration, input validation, deduplication, Wazuh context, multi-source threat intelligence, AI incident analysis on a local Ollama model, dry-run-safe auto-block, notification and response, and error handling

What it does

An alert hits the webhook and the workflow:

  • Cleans the input first. The source IP is checked as a real IPv4/IPv6 address and stripped of shell characters before anything else touches it.

  • Kills the duplicates. Same IP, same rule, same agent inside your time window? Counted once, reported once. A 200-alert brute force costs you one report instead of two hundred.

  • Gets the context. It searches your Wazuh Indexer for what else happened around that alert - the same thing an analyst would go looking for.

  • Checks the IP. VirusTotal and AbuseIPDB, combined into one 0–100 threat score: CRITICAL, HIGH, MEDIUM or LOW.

  • Writes the report. A local AI model gives you a verdict, a false-positive call, the MITRE technique, and the actions to take right now.

  • Sends it everywhere at once. Discord, Slack, Telegram, email - pick any combination. They fire in parallel, and a dead Slack webhook cannot stop the Discord message.

  • Blocks the attacker (only if you say so). Wazuh active-response, behind five separate gates.

The AI runs on Ollama, on your own hardware. Your alerts, hostnames and log lines never go to a cloud model.

Why it is safe to install today

This workflow can block IPs on your firewall. So it ships locked down.

  1. Dry-run is on by default. The block path runs end to end, then stops and tells you what it would have blocked. Watch it for a week before you let it act.

  2. Five things must agree before a real block. Dry-run off, blocking on, IP not whitelisted, VirusTotal over your threshold, and rule level over your floor.

  3. The whitelist ships pre-filled with private ranges and the common public DNS resolvers, and it does proper CIDR maths - 10.0.0.0/8 really does cover 10.20.0.31.

  4. No SSH anywhere. It talks to Wazuh over the API only. You are not handing a workflow root on your servers.

  5. It catches its own failures. Any node that breaks reports itself to Discord instead of dying quietly.

How it works

  1. Import the workflow into n8n.

  2. Open one CONFIGURATION node and set your two Wazuh URLs. Every setting lives here - nothing else to hunt for.

  3. Attach your credentials: Wazuh Indexer, Wazuh Manager, VirusTotal, AbuseIPDB, Ollama, and one delivery channel.

  4. Point Wazuh at the webhook.

  5. Fire one of the included test alerts and read the report.

About 15 minutes to your first live report.

Requirements

  • n8n v1.x or newer

  • Wazuh 4.x - Manager and Indexer reachable from n8n

  • An Ollama endpoint (or swap in a cloud model - the guide shows you how)

  • VirusTotal and AbuseIPDB API keys - the free tiers are enough

  • One place to send reports: Discord, Slack, Telegram, SMTP or Gmail

Who it is for

SOC engineers, MSPs and one-person security teams running Wazuh who are tired of hand-writing the same alert summary and who want the AI in a box they control, not in someone else's cloud.

Run it tonight

Import the JSON, fill in the CONFIGURATION node, point your Wazuh integrator at the webhook. Watch your first AI-triaged report land in your channel.

7-day guarantee

If it doesn't work as described, or it isn't what you needed, contact us within 7 days of purchase and we'll refund you in full. If you'd rather have it working, say so and we'll help you get it running. Your call. Full terms.

← Browse all products