For more information about integrations, check the Integration with external APIs section of the documentation.
Configure your environment as follows to test the PoC.
Create a Slack webhook. This is a unique URL to which Wazuh will send messages with the alerts.
YOUR_SLACK_WEBHOOKin the below configuration with the URL obtained in the previous step. Set this Slack integration configuration in
/var/ossec/etc/ossec.confat the Wazuh manager.
<integration> <name>slack</name> <hook_url>YOUR_SLACK_WEBHOOK</hook_url> <!-- Replace with your Slack Webhook --> <level>10</level> <alert_format>json</alert_format> </integration>
Restart the Wazuh manager to apply the configuration changes.
# systemctl restart wazuh-manager
No action is required. Wazuh automatically forwards alerts level 10 or higher to the provided Slack webhook.