Using CDB lists for Active Response

229 views
Skip to first unread message

Childe Robertson

unread,
Aug 13, 2023, 5:03:53 PM8/13/23
to Wazuh mailing list
Hello, I'm curious if it is possible to use a CDB list for Active Response. I am making an active response to block IP addresses (firewall-drop) that trigger off from a set of rule IDs by specifying them on <rules_id> </rules_id>.

It got me thinking it would be easier to manage this if instead of explicitly editing the field in the config file whenever I need to add or remove a rule ID is if I could instead state said rule IDs in a CDB list where the active response script could automatically update or read from.



Daniel Sappa

unread,
Aug 13, 2023, 6:28:55 PM8/13/23
to Wazuh mailing list
Hi Childe Robertson!

Yes, it is possible to use a CDB (Constant DataBase) list for Active Response in Wazuh. CDB lists are useful for maintaining a dynamic list of items that can be read by various components of Wazuh, including Active Responses, here is a link that may be useful.


I hope I help you.
Reply all
Reply to author
Forward
0 new messages