configure Suricata with Wazuh
-
hello all!
I am attempting to incorporate Wazuh into my network security. The Wazuh site states
"There are several ways to integrate pfSense with Wazuh. The easiest method is syslog, but you can also use the Wazuh agent. Wazuh agent (native package for pfSense) is already pre-installed In pfSense which is available in Yandex Cloud Marketplace/VK Cloud Marketplace. Therefore, you can start setting up immediately, bypassing the installation process."
I do not see one. It then explains how to use by configuring Suricata, and finally, it explains how to import the syslog itself. But all reference restarting the "Agent".
Several sites show how to 'fix' pfsense to get packages directly from FreeBSD repositories, but that seems to be fairly dangerous.
So does anyone have a reference on how to send syslogs from PfSense to Wazuh without "backdoor tinkering"?
Thanks