DFIR IRIS Module Wazuh Indexer - socarium/makarasoc GitHub Wiki
DFIR-IRIS Module Wazuh Indexer
Use the Wazuh-Indexer module to quickly search your logs with Wazuh-Indexer module to spot IoCs. This module is designed to help SOC analysts quickly spot any other endpoints that have the same IoCs associated with their ingested events.
- Select DFIR IRIS Module Wazuh Indexer.

- Once deployment finish, Access DFIR-IRIS from your Browser App.

Note: ignore error messages.

- 
Open the DFIR-IRIS via Browser App. 
- 
Navigate to Advanced -> Modules.

- Add a new module.

- Input the Module name: iris_wazuhindexer_module

- Select Validate module.

- Configure the module with Wazuh indexenvironment.

- You can check the credential from Wazuh docker file.
nano wazuh-docker/single-node/docker-compose.yml

- Select enable module.
