I know, I'm not the first to ask such question but yeah, my attempt to recompile Wazuh and have the GeoIP pre-processing (before alert and rule assignment) met with a dead end.
As mentioned in this Reddit thread and some other places, it told me to recompile wazuh. Cool, and then what am I supposed to do after it which is the best to have GeoIP enabled?
Copying the compiled rule wont do anything (unless I copied the wrong stuff) and I'll be greeted with the usual invalid syntax error. The thing in question is "wazuh-analysisd".
Trying to reinstall Wazuh will be greeted with API issue after I finished installing it due to credential mismatch. And I have no idea where do I obtain the new credential for the API.
If anyone successfully implemented GeoIP pre-processing, please enlighten me.