Hello,
I'm creating alerts with Wazuh and have successfully been getting email alerts on basic things so far (ie eventid-4720 new user added). I created this with the GUI.
However, all I get in the alert is that the alert trigger happened. No details other than the alert time , severity, and monitor name that triggered the alert.
What I WANT is: the entire details of the Windows event, which is data that is in the event in Wazuh. These are being pulled by the Windows Wazuh agent.
Help is appreciated, I'm pretty new to Wazuh but so far so good ... I'm just not getting anywhere with the details here.
If there is a json template that someone could point me to for Windows events where I could just paste and enter the event-id I'm looking for, that would help a LOT.
I also have only read that there is a json rule list somewhere, I have not found where it is yet, so I can only create alerts / monitors / triggers in the webGUI ... so a link to the how-to would also help.
Thanks everyone!