How to use Opensearch Machine Learning in Wazuh

2,297 views
Skip to first unread message

Utkarsh Bhargava

unread,
Jun 6, 2022, 1:39:50 AM6/6/22
to 'Utkarsh Bhargava' via Wazuh mailing list
Hi Community,

I am new to machine learning and trying to figure out how we can use OpenSearch's Machine Learning capabilities in Wazuh.

regards
Utkarsh
Sent from Mailspring

antonio....@wazuh.com

unread,
Jun 6, 2022, 4:48:13 AM6/6/22
to Wazuh mailing list
Hello Uktarsh

Wazuh doesn't come with OpenSearch ML engine enabled by default, as Wazuh only OpenSearch to index the data once it's processed by the Wazuh manager, searching for specific patterns in logs and files and triggering the alerts based on those patterns that are specified in the Wazuh ruleset.  So the data that OpenSearch stores are already processed by the Wazuh manager.

I have been looking at the OpenSearch documentation and it seems that it has some algorithms to perform anomaly detection and forecasting. These kinds of capabilities may help you detect outliers in the data (for example ssh connection from outside your network), but in most cases, you can set up a rule that will trigger an alert in that use case.

Anyway, if you want to try, I will leave some of the documents that I have been reading:
- https://www.elastic.co/blog/improve-security-analytics-with-the-elastic-stack-wazuh-and-ids
Reply all
Reply to author
Forward
0 new messages