Skip to main content
Wazuh SOC Investigation app icon

Wazuh SOC Investigation

Provides investigation workflows and dashboards for analyzing Wazuh endpoint security alerts, with a modular input for ingesting vulnerability data from Wazuh Indexer.Built by Kaled Aljebur
splunk product badge

Default Version 1.2.2

September 22, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x, 6.x, 5.x, 4.x, 3.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Wazuh SOC Investigation app provides security operations workflows and analytical dashboards for investigating endpoint security alerts generated by Wazuh. The app includes a modular input that retrieves vulnerability assessment findings from the Wazuh Indexer API and brings them into Splunk for correlation and analysis. Alert data is normalized to the CIM Intrusion Detection data model, enabling integration with other security tools and Enterprise Security. The app supports investigation of file integrity events, authentication activities, and MITRE ATT&CK-mapped threat behaviors across monitored endpoints. For details: https://github.com/kaledaljebur/wazuh-soc-investigation