Anthony,
I have CVE-2023-27522, CVE-2022-37436 for example, but i don't want to be mail/alert on those existing CVE number because they exist now but i want to be alerted when new CVE relative to apache/ssh are imported/active in wazuh for my agents.
The goal is to be sure in case of a CVE alert on this packages/services (apache and ssh globally) concerning my agents that i have an alert mail from wazuh (not a daily /weekly global report with a lot of different alerts in it )
I'm registered on an external service (
https://www.opencve.io/) to be notified in case of new cve related to apache/apache2 and ssh/openssh, but i'll would prefer to have a real alert from wazuh for those specific services if a new CVE appear/is active for my machines/agents.
For my tests => screenshot visualization for apache, apache* not possible.
Regards,