Hello,
thanks for using wazuh!
The guide of our documentation is quite objective with the process to be carried out, but there are points to take into account where you could delve into the topic, such as the custom rules that are created, in this section you could create more child rules to be able to generate personalized alerts according to your requirements. You can read more about creating custom rules in the following documentation:
Custom rules and decodersIt is also important to note the use of Suricata, Suricata is a NIDS solution, which is open source and can be quickly deployed on existing Unix-like hosts to monitor just their own network traffic. You can follow our linked documentation to be able to configure Suricata as NIDS:
SuricataI hope this is helpful, let me know if you need anything else.
Regards,
Luis Avendaño