SIEM & Log Sources
Live todayAI alert triage for Wazuh
Open-source security monitoring and threat detection.
Visit Wazuh ↗How Jutsu works with Wazuh
Wazuh feeds host, file-integrity, and threat-detection events straight into Jutsu so agents triage them the moment they fire.
What you can do
- Ingest Wazuh alerts in real time
- Auto-enrich and correlate events with threat intel
- Trigger response playbooks on high-severity detections
How it connects
Connect in minutes
Authenticate with your existing credentials: no agents to deploy, no data to migrate.
Jutsu investigates
AI SOC agents triage, enrich, and correlate every signal automatically, around the clock.
Act with confidence
Get analyst-grade verdicts and one-click response, with humans always in control.
What Jutsu reads from each Wazuh alert
Wazuh alerts arrive through Jutsu's Ingest API with the fields an analyst would otherwise copy out by hand. Every event stays searchable on the Events page, with the raw JSON one tab away.
Source. Wazuh agent name and ID, manager, hostname, program, decoder, and the log file the event came from.
Rule. Rule ID, level, how many times it has fired, its description, and its rule groups.
MITRE ATT&CK. Technique IDs, tactics, and technique names mapped to the Wazuh rule.
Network and identity. Source IP and port, plus the user tied to the activity.
How a Wazuh alert gets triaged
Every Wazuh alert runs through the same chain of AI agents before it reaches your queue, so analysts open a finished analysis instead of a bare rule hit.
- 1
Normalize. The event is reshaped into one internal format, so a failed SSH login from Wazuh and a failed Gmail login from Google Workspace can be correlated.
- 2
Enrich. IPs, file hashes, and domains are checked against nine threat-intel providers, including VirusTotal, AbuseIPDB, GreyNoise, and CISA KEV, and against your asset inventory.
- 3
Score. Jutsu assigns a 0–100 risk score, a verdict (true positive, false positive, or not sure), and a confidence level, computed the same way every time from the evidence. Wazuh's own severity stays visible as the SIEM severity.
- 4
Correlate. Alerts that share an attacker, target, or technique in the same time window are grouped into one incident, so a brute-force run across many hosts reads as one campaign.
- 5
Respond. Clearly benign alerts close on their own, confident detections can run an AgentSOAR playbook, and anything uncertain becomes a case for your analysts.
Test your Wazuh detections
Two other Jutsu products are built around Wazuh. Firehose fires synthetic attack traffic at a Wazuh manager over TCP syslog and reads detections back through alerts.json or the Wazuh Indexer to measure time to detect. Red Team runs MITRE ATT&CK-mapped attack scenarios against scoped targets and shows which ones your detections caught.
Wazuh integration FAQ
Subscribe to our newsletter
Get the latest security tips, product updates, and news delivered to your inbox.