DFIR IRIS Module Wazuh Indexer - socarium/makarasoc GitHub Wiki
DFIR-IRIS Module Wazuh Indexer
Use the Wazuh-Indexer
module to quickly search your logs with Wazuh-Indexer module to spot IoCs. This module is designed to help SOC analysts quickly spot any other endpoints that have the same IoCs associated with their ingested events.
- Select
DFIR IRIS Module Wazuh Indexer
.
- Once deployment finish, Access DFIR-IRIS from your Browser App.
Note: ignore error messages.
-
Open the DFIR-IRIS via Browser App.
-
Navigate to
Advanced -> Modules
.
- Add a new module.
- Input the Module name:
iris_wazuhindexer_module
- Select
Validate module
.
- Configure the module with
Wazuh index
environment.
- You can check the credential from Wazuh docker file.
nano wazuh-docker/single-node/docker-compose.yml
- Select
enable module
.