SIEM integration
Automate Wazuh SIEM with plain language
Read Wazuh agents, alerts and rule definitions, and restart or reconfigure an agent group when VernacSecure SuperBot™ finds drift.
What you can do
Wazuh — Manager REST API v4
- List enrolled agents and their status
- Read rules and decoders
- Read agent group configuration
- Restart an agent
Connection: basic authentication against https://wazuh.example.com:55000. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in Wazuh”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
Read actions
- Fetch agents — Lists enrolled agents.
- Fetch rules — Lists detection rules.
- Fetch agent groups — Lists agent groups.
Write actions
- Restart agent — Restarts the named agent id.
Related siem automation pages
Armor Point · Datadog Cloud SIEM · Devo Platform · Elastic Security · Exabeam Security Operations · Fortinet FortiSIEM