Add Visualization

378 views
Skip to first unread message

MH

unread,
Nov 13, 2022, 6:07:10 PM11/13/22
to Wazuh mailing list
Hello

I was reading this document and it shows a  Visualization  towards the bottom https://wazuh.com/blog/using-wazuh-to-monitor-sysmon-events/


Just wondering how/where I add this to my Wazuh setup to be able to use it.

Julio Gasco

unread,
Nov 13, 2022, 8:42:00 PM11/13/22
to Wazuh mailing list
Hi Michael,
That visualization is outdated and it´s not supported anymore in actual versions. I have reproduced a similar dashboard which you can import that is attached to this message (Powershell_Dashboard.ndjson)

The new dashboard has 4 visualizations: 
Agent IDs: Agent IDs that have sysmon alerts
Users: Users that triggered sysmon alerts
Parent Process: Parent Process of the sysmon alerts triggered.
Evolution of powershell events: Area map with powershell alerts triggered.

This is how it looks on my lab
Dashboard.JPG

To import the dashboard follow the next steps:
  • Log into your wazuh instance and in the left menu go to Management -> Stack Management
Step1.JPG
  • Under the stack management menu go to saved objects 
Step2.JPG
  • On the saved objects menu at the left press Import
Step3.JPG

  • In the import menu that open press the Import icon
Step4.JPG
  • Browse through your files and select the ndjson attached to this message and then press below Import
Step5.JPG

Once the dashboard and the visualizations is imported you can access it in the left menu on the Dashboard menu.
Step6.JPG

You can edit the dashboard and the visualizations if desired to better fit your requirements. The basic filter for all the visualizations is data.win.system.channel is Microsoft-Windows-Sysmon/Operational which captures incoming sysmon alerts.

Let me know if this helps-
Regards!
Powershell_Dashboard.ndjson
Reply all
Reply to author
Forward
0 new messages