Pack Automating Wazuh
Automate Your Wazuh SIEM with n8n
Automate Your Wazuh SIEM with n8n
Running Wazuh is only the first step. The real work starts after the alerts arrive.
This bundle gives you 7 practical Wazuh automation workflows for alert investigation, threat hunting, vulnerability reporting, agent monitoring, rule tuning, and security reporting.
Instead of building everything from scratch, import the workflows into n8n and start automating your SOC.
Build 30-day behavioral baselines and detect unusual activity across users and hosts.
Automatically create technical and executive security reports from your Wazuh data.
Know when an agent disconnects or stops reporting, with automatic alerts and escalation.
Safely test and approve rule changes with an approval-based n8n workflow.
Turn Wazuh vulnerability data into clear weekly reports with risk-based prioritization and patch recommendations.
Automatically investigate Wazuh alerts, enrich indicators, analyze them with AI, and create incident reports.
Run 59 MITRE ATT&CK-mapped threat hunts automatically and receive analyst-ready findings.
SOC teams ยท MSSPs ยท MSPs ยท Security consultants ยท Wazuh administrators ยท Security homelabs
Want help deploying or customizing it? Get deployment & customization
Here are all the products that are included in your bundle