Skip to content

Engine - Research Feasibility of Using OpenSearch SQL Plugin for Event Correlation and Frequency Rules #23332

Closed
@JcabreraC

Description

@JcabreraC
Wazuh version Component Install type Install method Platform
5.0.0 Engine Manager Packages/Sources OS version

Description

This issue is focused on exploring the potential integration of the OpenSearch SQL plugin to enhance Wazuh's event correlation and frequency rule capabilities. The goal is to determine if this plugin can be effectively utilized to correlate events processed by the wazuh-engine and stored in OpenSearch indices.

Objective

  • Research and PoC Development: Investigate the capabilities of the OpenSearch SQL plugin for writing complex correlation and frequency rules and develop a proof of concept (PoC) if feasible.

Tasks

  • Review the existing documentation and capabilities of the OpenSearch SQL plugin to assess its suitability for event correlation.
  • Identify potential challenges and limitations in using the SQL plugin for event correlation within the Wazuh context.
  • Develop a small-scale PoC demonstrating the use of the SQL plugin to correlate events based on predefined criteria.

Expected Outcomes

  • A clear understanding of the OpenSearch SQL plugin's applicability for enhancing Wazuh's event correlation.
  • Documentation of findings, including possible benefits, drawbacks, and any technical challenges identified.
  • A decision on whether to proceed with further development based on the PoC results.

Notes

This research is crucial for advancing Wazuh's capabilities in handling complex event correlations efficiently and could lead to significant improvements in how security events are processed and analyzed.

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions