SIEM integration

Automate Wazuh SIEM with plain language

Read Wazuh agents, alerts and rule definitions, and restart or reconfigure an agent group when VernacSecure SuperBot™ finds drift.

What you can do

Wazuh — Manager REST API v4

  • List enrolled agents and their status
  • Read rules and decoders
  • Read agent group configuration
  • Restart an agent

Connection: basic authentication against https://wazuh.example.com:55000. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Show the last 24 hours of high severity alerts in Wazuh”

Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.

Get started free

Read actions
  • Fetch agents — Lists enrolled agents.
  • Fetch rules — Lists detection rules.
  • Fetch agent groups — Lists agent groups.
Write actions
  • Restart agent — Restarts the named agent id.