September 22, 2026
Wazuh SOC Investigation
Provides investigation workflows and dashboards for analyzing Wazuh endpoint security alerts, with a modular input for ingesting vulnerability data from Wazuh Indexer.Built by Kaled AljeburSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 8.x, 6.x, 5.x, 4.x, 3.x
Log in to rate this app
The Wazuh SOC Investigation app provides security operations workflows and analytical dashboards for investigating endpoint security alerts generated by Wazuh. The app includes a modular input that retrieves vulnerability assessment findings from the Wazuh Indexer API and brings them into Splunk for correlation and analysis. Alert data is normalized to the CIM Intrusion Detection data model, enabling integration with other security tools and Enterprise Security. The app supports investigation of file integrity events, authentication activities, and MITRE ATT&CK-mapped threat behaviors across monitored endpoints. For details: https://github.com/kaledaljebur/wazuh-soc-investigation
Log in to report this app listing.