Wazuh Agent Health & Disconnection Auto-Alerter
Know when a Wazuh agent goes offline before your client does.
A free n8n workflow for MSPs and SOC teams running Wazuh. It checks agent health every 15 minutes and alerts your team when an endpoint disconnects or stops reporting.
Simple, lightweight, and ready to use.
Why use it?
A disconnected endpoint can mean lost visibility.
Instead of checking the Wazuh dashboard manually, this workflow monitors your agents and sends alerts automatically through Slack, Discord, Email, or Jira.
Key features
- 15-minute heartbeat — Checks agents through the Wazuh Manager API.
- Business-hours monitoring — Workstations can be ignored outside working hours while servers stay monitored 24/7.
- Maintenance windows — Silence planned outages without disabling monitoring.
- Two alert levels — Alert after 15 minutes and escalate after 2 hours.
- Multi-channel alerts — Slack, Discord, Email, and Jira.
- Safe by default — All notification channels start disabled.
- Stateless — No database required. Runs anywhere n8n runs.
What's included
- Import-ready n8n workflow
- Setup guide
- Configuration guide
- README
- License
Requirements
- n8n, self-hosted
- Wazuh 4.x
- Wazuh Manager API access
- Wazuh API user with agent read access
- At least one alert channel: Slack, Discord, Email, or Jira
Get it free
Import the workflow, connect your Wazuh credentials, enable your notification channel, and start monitoring.
Want the production version?
For stateful alerting, SLA/MTTR tracking, and multi-tenant client dashboards, check out NeetroX.
Free to use and modify. Not for resale. No warranty. Test before production.