SYNOTI / Wazuh Security Events
Wazuh Security Events
Correlated security event explorer · 6,842 alerts / 24h.
Alerts / 24h
6,842
312 critical · 412 high
Level 12+
12
critical severity
Level 7+
147
high severity
Active Responses
1,289
auto-triggered
Rule Groups
22
matched
Event Stream
| Time | Agent | Rule | Level | Description | Group |
|---|---|---|---|---|---|
| 18:42:11 | www-03 | 86605 | 12 | Critical CVE-2026-4432 — RCE in www-03 | vulnerability-detector |
| 18:41:58 | www-03 | 1002 | 3 | File added: /var/www/backdoor.php | syscheck |
| 18:40:44 | ws-05 | 5503 | 7 | Rootkit detected — /dev/sda1 hidden | rootcheck |
| 18:39:21 | ws-05 | 5900 | 3 | Active response started: firewall-drop | active-response |
| 18:38:07 | proxy-02 | 577 | 5 | sshd: 5 failed auth from 203.0.113.45 | syslog |
| 18:35:52 | mysql-02 | 807 | 6 | gpgcheck disabled in yum.conf | audit |
| 18:33:40 | mail-01 | 87103 | 10 | Suspicious SMB share access — ADMIN$ | windows |
| 18:31:18 | k8s-02 | 60116 | 7 | Docker: privileged container started | docker |
| 18:28:55 | app-06 | 86604 | 9 | CVE-2026-1122 — kernel exploit attempt | vulnerability-detector |
| 18:26:33 | app-06 | 514 | 4 | Group added: adm / dev-ssh-users | syscheck |
Event Volume / 24h
Top Modules (24h)
View allFIM
1204%
Syslog
3412%
Active Response
1289%
Cloud
318%
Vuln Detector
412%
Recent Activity
View allRansomware behavior blocked on mail-01 CRITICAL
Playbook PB-041 auto-contained host · Ryuk TTPs matched
SSH brute force from 203.0.113.42 HIGH
42 failed logins in 60s · source IP blocked
Threat hunt matched T1059.001 on www-02
PowerShell obfuscation · confidence 0.91
SCA scan completed on 128 hosts
98.2% compliance · 11 benchmarks passed
Firewall rule 'BLK-3321' propagated to 14 nodes
0.4s propagation · geo-blocked 12 CIDRs
Sandbox verdict — 'invoice_9921.exe' malicious
Heuristic score 96 · family 'Emotet'
