Good Day Everyone,
I am just new to the new the team and the company I am working is young as well which I wanted to help - I am also new using Wazuh.
Is there any way to or even possible to:
1. Send all valid/known alerts to Viber? valid/known alerts would be like:
(I don't think email would do just to avoid it being swamped)
- agent disconnection
- log sources that are down or aren't sending logs after x number of minutes
- RDP/SSH connection has an accept data action outside of business hours and over the weekends
- successful sudo to root and sshd
- successful login outside of the country on 0365
- and the like
2. Set a color coding script to all valid/known alerts on wazuh for easy alert detection say:
- Low severity is Green
- Medium severity is Orange
- High severity is Light Red
- Critical is Red
Any links, references, suggestions are welcome team :)