Creating a Custom Wazuh Dashboard

Source

Why Customize Your Dashboard?

An effectively designed dashboard does more than just present data; it enhances decision-making processes. By utilizing custom visualizations, security teams can:

  • Prioritize Critical Alerts: Emphasize high-priority threats and anomalies for immediate action.
  • Enhance Response Time: Facilitate quick access to actionable intelligence.
  • Optimize Workflows: Minimize unnecessary noise and provide clear insights into specific security metrics.

Prerequisites

Before proceeding with dashboard customization, ensure that you have:

  • A fully operational Wazuh environment.
  • Logs being collected from multiple sources, including Linux, macOS, Windows, or network monitoring tools such as Suricata.

Planning Your Dashboard

Before creating visualizations, define your key performance indicators (KPIs). Some essential metrics include:

  • Agent Status: Monitoring the number of connected and disconnected agents.
  • Threat Trends: Tracking alert frequency and types over time.
  • Source-Specific Insights: Creating custom views for logs from O365, SSH, or Suricata.

Below are three custom dashboards

1. High & Critical Alerts Dashboard

High & Critical Alerts Dashboard 1
High & Critical Alerts Dashboard 2

This dashboard highlights alerts of high and critical severity that require immediate action. The following visualizations ensure thorough monitoring:

  • EPS Count (Gauge): Displays the average Events Per Second (EPS), providing a real-time snapshot of log activity to identify anomalies.
  • Top 3 Agents by Log Count (Pie Chart): Highlights the three agents generating the most logs, helping pinpoint unusual activity during EPS spikes.
  • Event Location (Stacked Bar Chart): Categorizes events by location, offering context for analyzing EPS spikes and tracking region-specific activity.
  • Disconnected & Active Agents (Metric): Provides a quick count of disconnected and active agents for operational monitoring.
  • High Alerts and Critical Alerts (Data Table): Lists alerts with rule levels categorized as high (10–12) and critical (13–15), ensuring that no critical alerts go unnoticed.
  • Successful Login: Non-Native (Critical) & O365 Successful Login: Non-Native (Critical) (Data Table): Identifies critical non-native logins to detect unauthorized access attempts via SSH and O365.
  • Discover Tab: Enables deeper investigation into specific alerts by applying precise filtering for detailed analysis.

2. SSH Events Dashboard

SSH Events Dashboard

This dashboard is dedicated to monitoring SSH-related events to bolster security and detect unauthorized access attempts. The following visualizations provide comprehensive oversight:

  • Login Attempts: Non-Native GeoLocation (Pie Chart): Detects login attempts from non-native geolocations, indicating potential threats.
  • Successful Login: Non-Native (Critical) (Data Table): Lists critical successful logins from non-native locations, assisting in the rapid identification of account compromises.
  • Login Attempts: Top 10 Usernames (Pie Chart): Displays the most frequently targeted usernames, helping detect brute force attacks.
  • Top IPs of Successful Logins (Bar Chart): Highlights the IP addresses responsible for successful logins, identifying potentially suspicious sources.
  • SSH Alerts (Data Table): Centralizes all alerts related to SSH activities for streamlined monitoring and incident response.

3. O365 Compromise Detection Dashboard

O365 Compromise Detection 1
O365 Compromise Detection 2

Designed for detecting and investigating potential compromises in O365 environments, this dashboard includes visualizations to provide clear insights into activities and alerts:

  • Event Timeline (Vertical Bar): Maps key O365 operations, such as UserLoggedIn, ModifyFolderPermissions, and FileAccessed, on a timeline for post-compromise analysis.
  • O365 Triggered Alerts (Data Table): Lists all triggered alerts for centralized and efficient monitoring of suspicious activities.
  • Failed & Successful Logon Details (Data Table): Captures failed and successful logon attempts, aiding in the identification of unauthorized access.
  • Discover Tab: Highlights crucial fields like DeviceProperties.Value and ExtendedProperties.Value, essential for investigating unauthorized access facilitated by malicious agents like Raccoon and Axios.

You can build tailored dashboards according to your specific use cases. By leveraging Wazuh’s flexible visualization capabilities, security teams can enhance monitoring efficiency, improve incident response times, and gain better insights into potential security threats.

Subscribe to news