← All integrations
Jutsu×Wazuh logo

SIEM & Log Sources

Live today

AI alert triage for Wazuh

Open-source security monitoring and threat detection.

Visit Wazuh ↗

How Jutsu works with Wazuh

Wazuh feeds host, file-integrity, and threat-detection events straight into Jutsu so agents triage them the moment they fire.

What you can do

  • Ingest Wazuh alerts in real time
  • Auto-enrich and correlate events with threat intel
  • Trigger response playbooks on high-severity detections

How it connects

1

Connect in minutes

Authenticate with your existing credentials: no agents to deploy, no data to migrate.

2

Jutsu investigates

AI SOC agents triage, enrich, and correlate every signal automatically, around the clock.

3

Act with confidence

Get analyst-grade verdicts and one-click response, with humans always in control.

What Jutsu reads from each Wazuh alert

Wazuh alerts arrive through Jutsu's Ingest API with the fields an analyst would otherwise copy out by hand. Every event stays searchable on the Events page, with the raw JSON one tab away.

  • Source. Wazuh agent name and ID, manager, hostname, program, decoder, and the log file the event came from.

  • Rule. Rule ID, level, how many times it has fired, its description, and its rule groups.

  • MITRE ATT&CK. Technique IDs, tactics, and technique names mapped to the Wazuh rule.

  • Network and identity. Source IP and port, plus the user tied to the activity.

How a Wazuh alert gets triaged

Every Wazuh alert runs through the same chain of AI agents before it reaches your queue, so analysts open a finished analysis instead of a bare rule hit.

  1. 1

    Normalize. The event is reshaped into one internal format, so a failed SSH login from Wazuh and a failed Gmail login from Google Workspace can be correlated.

  2. 2

    Enrich. IPs, file hashes, and domains are checked against nine threat-intel providers, including VirusTotal, AbuseIPDB, GreyNoise, and CISA KEV, and against your asset inventory.

  3. 3

    Score. Jutsu assigns a 0–100 risk score, a verdict (true positive, false positive, or not sure), and a confidence level, computed the same way every time from the evidence. Wazuh's own severity stays visible as the SIEM severity.

  4. 4

    Correlate. Alerts that share an attacker, target, or technique in the same time window are grouped into one incident, so a brute-force run across many hosts reads as one campaign.

  5. 5

    Respond. Clearly benign alerts close on their own, confident detections can run an AgentSOAR playbook, and anything uncertain becomes a case for your analysts.

Test your Wazuh detections

Two other Jutsu products are built around Wazuh. Firehose fires synthetic attack traffic at a Wazuh manager over TCP syslog and reads detections back through alerts.json or the Wazuh Indexer to measure time to detect. Red Team runs MITRE ATT&CK-mapped attack scenarios against scoped targets and shows which ones your detections caught.

Wazuh integration FAQ

Subscribe to our newsletter

Get the latest security tips, product updates, and news delivered to your inbox.