Closed
Description
Wazuh version | Component | Install type | Install method | Platform |
---|---|---|---|---|
5.0.0 | Engine | Manager | Packages/Sources | OS version |
Description
This issue is focused on exploring the potential integration of the OpenSearch SQL plugin to enhance Wazuh's event correlation and frequency rule capabilities. The goal is to determine if this plugin can be effectively utilized to correlate events processed by the wazuh-engine and stored in OpenSearch indices.
Objective
- Research and PoC Development: Investigate the capabilities of the OpenSearch SQL plugin for writing complex correlation and frequency rules and develop a proof of concept (PoC) if feasible.
Tasks
- Review the existing documentation and capabilities of the OpenSearch SQL plugin to assess its suitability for event correlation.
- Identify potential challenges and limitations in using the SQL plugin for event correlation within the Wazuh context.
- Develop a small-scale PoC demonstrating the use of the SQL plugin to correlate events based on predefined criteria.
Expected Outcomes
- A clear understanding of the OpenSearch SQL plugin's applicability for enhancing Wazuh's event correlation.
- Documentation of findings, including possible benefits, drawbacks, and any technical challenges identified.
- A decision on whether to proceed with further development based on the PoC results.
Notes
This research is crucial for advancing Wazuh's capabilities in handling complex event correlations efficiently and could lead to significant improvements in how security events are processed and analyzed.