Skip to content
Discussion options

You must be logged in to vote

I can read from here that Active Response on Wazuh seems supported already. Is it fully supported? I can read things that confuse me on the forum. Can the developers give a more precise reply, especially on where to configure it? Must the configuration be done locally (endpoint side) or does it propagate if I do it on the manager-node side?

Each Security Onion installation has its own Wazuh server. That means that if you have a Security Onion distributed deployment with manager, search nodes, and forward nodes, each one of those nodes has their own Wazuh server and those Wazuh servers are independent.

If you install a Wazuh agent on a non-Security-Onion endpoint and connect that agent t…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@vanh20
Comment options

@vanh20
Comment options

Answer selected by vanh20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants