hello, I recommend installing suricata on the client and within ossec.conf insert the configuration:
<localfile>
<log_format>json</log_format>
<location>/var/log/suricata/eve.json</location>
</localfile>
On wazuh server customize your rules to block what you need.
Hi,
How to set Suricata in IPS mode and block these requests , wanted to do smth about that blocks SQL injection or XSS in real time not just alert them using wazuh. If u have any idea please send me
thanks--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2a76720a-f472-4581-af0d-96e4dbce9d1en%40googlegroups.com.
Hi.
Did you implement the active response?
I think Allan is suggesting you use that with the firewall drop
rule like this:
Geoff
Hi i did add this before and i did it again
still suricata wont prevent anything . even that it alerts those that need. but it doesnt prevent it .
Thanks
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/d1f2c0c0-a9f8-4274-99e5-0765d6d690afn%40googlegroups.com.
I recommend evaluating the additional protection modules:
mod_security and its rules
https://github.com/SpiderLabs/ModSecurity
mod_evasive
cloudflare waf for example
and pen-test scanner for application vulnerabilities.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/0339da2a-c8f2-3e91-0d94-946216fe7326%40gnaa.net.