Hello Wazuh Community,
I am currently working with Wazuh version 4.13 and would like to set up GeoIP-based map visualization in the Wazuh Dashboard (OpenSearch Dashboards). I understand that this requires configuring GeoIP databases and enabling certain settings, but I would appreciate if someone could kindly provide the full, detailed steps required to:
Properly install and configure the GeoIP database (e.g., GeoLite2-City.mmdb)
Configure Wazuh manager to enable GeoIP lookup and include GeoIP data in alerts
Verify that GeoIP data is correctly added to alerts
Configure or access the map visualization in the Wazuh/OpenSearch Dashboard
Any additional tips or common pitfalls to avoid during this setup
Thanks in advance for your help!
Hello Chukwudalu,
Thank you for the detailed steps. I will try this on our Wazuh Indexer and follow up once it’s done.
Thanks again for your guidance!