Packetbeat and Wazuh

574 views
Skip to first unread message

Peter Santiago

unread,
Jun 1, 2021, 9:57:10 PM6/1/21
to Wazuh mailing list

Can I integrate Packetbeat inputs into wazuh with any needed templates or modifications?

Alberto Rodriguez

unread,
Jun 2, 2021, 4:18:21 AM6/2/21
to Wazuh mailing list
Hello 

  Did you consider using Owlh? The Owlh project has a tested integration with Wazuh and I think that maybe can suit your use case. Packetbeat is an Elastic beat that directly sends information to Elasticsearch and both template's schemas are not compatible yet. Please take a look and let me know if this could work for you: https://documentation.owlh.net/en/0.17.0/main/OwlHScenarios.html#wazuh-integration

Regards, 

Peter Santiago

unread,
Jun 2, 2021, 9:41:00 PM6/2/21
to Wazuh mailing list
Thank you for your suggestion. I will take a closer look at Owlh integration
Reply all
Reply to author
Forward
0 new messages