I NEED HELP FOR INTEGRATE ALIENVAULT WITH WAZUH

1,012 views
Skip to first unread message

Lorenzo Putignano

unread,
Jan 26, 2024, 11:37:39 AM1/26/24
to Wazuh | Mailing List
Hi everyone! 
I'm following this two tutorials for integrate Alienvault OTX with wazuh (Not with the CDB List) 


And how you can see this work.... (Photo1)

Photo 1.PNG

so i do the dnsquery on   webdatatrace.com -> DNS Stats respond me and start a custo script otx.cmd situated on Programs Files (x86)\ossec-agent\active-response\bin\ that run another script otx.ps1 (i have installed Phowershell 7 as the guide says)
but don't trigger "AlienVault OTX -Indicator(s) Found" on wazuh, can anyone help me?


Lorenzo Putignano

unread,
Jan 29, 2024, 8:33:59 AM1/29/24
to Wazuh | Mailing List

Guys solved ! 
Here you can find a simple step by step guide. Write to me for improvements (obviously)

Manuel Alejandro Roldan Mella

unread,
Jan 29, 2024, 11:29:39 PM1/29/24
to Wazuh | Mailing List
Hi Lorenzo,

Thanks for the step-by-step guide!

If you have any other questions or need further assistance, please feel free to reach out at any time. I'm here to help and would be happy to provide additional information or clarification as needed.

Regards

kushagra varshney

unread,
Oct 27, 2025, 7:33:41 AM10/27/25
to Wazuh | Mailing List
Hi Lorenzo,

I used the same integration steps as given by you for integration wazuh and otx  but i am facing errors in basic ioc matching when ossec is trying to run the script provided in walkthrough.

2025/10/27 11:13:51 wazuh-integratord: ERROR: Unable to run integration for custom-alienvault -> integrations
2025/10/27 11:13:51 wazuh-integratord: ERROR: While running custom-alienvault -> integrations. Output: KeyError: 'win'

i want to use it as, it should verify any ip, domain, or hash coming in my wazuh alerts with the public ioc's in otx and enrich my logs.

Thanks & Regards
Kushagra Varshney
Reply all
Reply to author
Forward
0 new messages