USE GEO LOCATION COUNTRY NAME IN RULE

54 views
Skip to first unread message

Mohammad Awais Javaid

unread,
Apr 24, 2025, 6:50:19 AM4/24/25
to Wazuh | Mailing List
I have tried to use geo location country name in rules in sid but that never happens. No rule is triggered using the geo location country name field. it appears in the document but not be used by new rules which I am trying to write. 

Is there any solution to this, I dont want to go with work around to build manager from sources since I need to do this in my production servers, but I need a proper method  to handle this situation. 

Can any one help me with this?

Regards 

Awais

Emiliano Zorn

unread,
May 7, 2025, 5:37:14 AM5/7/25
to Wazuh | Mailing List
Hi!

The GeoIP data is added to the events in a higher level of the stack, that's why you can see it in the final events but it can't be used to trigger alerts.

If you want to make the Wazuh manager capable of using the GeoIP data for alerts, it's necessary to compile the manager with the USE_GEOIP  flag enabled (Available flags). Also, you have to download the GeoLite2 legacy database and convert it with the geolite2legacy tool. 

The whole process is already described in this previous answer, don't hesitate in making any question you have:

Reply all
Reply to author
Forward
0 new messages