Monitor alert from alerting to a webhook

100 views
Skip to first unread message

Julian Jorge

unread,
Apr 23, 2024, 10:43:28 AM4/23/24
to Wazuh | Mailing List

Hi, 

We are trying to send a monitor alert from alerting to a webhook of shuffle.

Is there a way to send the complete json just as we can do using the shuffle integration? We need it to be a json to see the different fields from the alert and use it on shuffle.

Marcos Javier Bonacci

unread,
Apr 23, 2024, 1:06:35 PM4/23/24
to Wazuh | Mailing List
Hi Julian,
Here is a blog post with a detailed explanation of how to integrate Wazuh>Shuffle. Additionally, in the Wazuh docs section, you can check Wazuh integrations.
Could you share the json that you received via shuffle to check it?

Julian Jorge

unread,
Apr 24, 2024, 2:56:41 AM4/24/24
to Wazuh | Mailing List
Hello Marcos,

 I don't think I've explained myself properl. I am using the section of "Alert monitor" from wazuh:Alert monitor.png
With this tool I can send message from wazuh to Shuffle when there is a conexion outside of spain for example.

But I need to add more fields for the generated aler. How can I do it?

Marcos Javier Bonacci

unread,
Apr 24, 2024, 10:13:02 AM4/24/24
to Wazuh | Mailing List
Hi Julian,
In the Actions Section/Message, did you configure a variable with Results?

imagen_2024-04-24_111108062.png

Julian Jorge

unread,
Apr 24, 2024, 10:37:56 AM4/24/24
to Wazuh | Mailing List
Hello,

No, I didn´t configure that. I just do it but the result have not much information.

Is some way to have information from the real alert log?
Message has been deleted

Marcos Javier Bonacci

unread,
Apr 25, 2024, 9:32:50 AM4/25/24
to Wazuh | Mailing List

Hello,
The full alert JSON should be included in a field named all_fields, as the blogspot shows in the image: 
imagen_2024-04-25_102936236.png

You could set this field to be overwritten if you include {"all_fields": "<whatever>"} as options.
Reply all
Reply to author
Forward
0 new messages