Modify Full log

32 views
Skip to first unread message

Riccardo Olivetto

unread,
Oct 3, 2025, 2:11:24 PM (7 days ago) Oct 3
to Wazuh | Mailing List
Hi, i've created a custom active response script that use ChatGPT.
The active response script is called correctly, but the alert is generated without it's response. How can I add an additional field to see chatgpt response?

Federico Ramos

unread,
Oct 3, 2025, 2:49:55 PM (7 days ago) Oct 3
to Wazuh | Mailing List
Hello, Active Response doesn't create new alerts; it's a script that runs based on certain alerts you've configured.

If you want to save the CHATGPT response, you should add a way to persist this data to your script.

Riccardo Olivetto

unread,
5:21 AM (6 hours ago) 5:21 AM
to Wazuh | Mailing List
I refer to this article: https://documentation.wazuh.com/current/proof-of-concept-guide/leveraging-llms-for-alert-enrichment.html
The script itself doesn't add the field chatgpt responde, but from the visulization of alerts by GUI there is this additional field.

If i share with you my script can you help me?
Reply all
Reply to author
Forward
0 new messages