Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Wazuh Common Schema

The Wazuh Common Schema (WCS) is a standardized structure for organizing and categorizing security event data collected by Wazuh. It is designed to facilitate data analysis, correlation, and reporting across different data sources and types.

Categorization

The Wazuh Common Schema categorizes events into several key areas to streamline data management and analysis.

The index mappings and settings for subcategories take precedence over those from the main category. In OpenSearch, index templates are applied in order of their "priority" value: templates with a lower priority are applied first, and those with a higher priority are applied afterward, allowing them to override previous settings. This means the index template for the main category is applied first (priority=1), and then the subcategory template (priority=10) is applied on top of it, so subcategory-specific settings override the main category defaults.

Access Management

None yet.

Applications and Web Servers

Integration NameSubcategoryCategory
Apache integrationApacheApplications
NGINX integration-Applications
IIS integration-Applications
Apache Tomcat integrationApacheApplications
WebSphere Application Server integration-Applications
Oracle WebLogic Server integration-Applications
Spring Boot integration-Applications
squid-Applications

Cloud Services

Integration NameSubcategoryCategory
Amazon Security LakeAWSCloud Services
AWSAWSCloud Services
AWS BedrockAWSCloud Services
AWS LogsAWSCloud Services
AWS FargateAWSCloud Services
AWS FirehoseAWSCloud Services
AzureAzureCloud Services
Azure Blob StorageAzureCloud Services
Azure App ServiceAzureCloud Services
Azure FunctionsAzureCloud Services
Azure MetricsAzureCloud Services
Azure OpenAIAzureCloud Services
Cisco Umbrella-Cloud Services
GCPGCPCloud Services
Google SCCGCPCloud Services

Network Activity

Integration NameSubcategoryCategory
iptables-Network Activity
Cisco ASACiscoNetwork Activity
Cisco IOSCiscoNetwork Activity
Cisco MerakiCiscoNetwork Activity
Cisco AironetCiscoNetwork Activity
Fortinet FortigateFortinetNetwork Activity
CheckPoint-Network Activity
SonicWall-Network Activity
F5 BIG-IP-Network Activity
pfSense-Network Activity
Fortinet FortiproxyFortinetNetwork Activity

Security

Integration NameSubcategoryCategory
Snort-Security
Suricata-Security
ModSecurity-Security
Zeek-Security

System Activity

Integration NameSubcategoryCategory
AuditdLinuxSystem Activity
Sysmon LinuxLinuxSystem Activity
WindowsWindowsSystem Activity
Windows DHCPWindowsSystem Activity
Windows DNS serverWindowsSystem Activity
Windows Exchange serverWindowsSystem Activity
ULSmacOSSystem Activity

Other

None yet.

Indices

wazuh-events-v5-access-management-000001
wazuh-events-v5-applications-000001
wazuh-events-v5-cloud-services-000001
wazuh-events-v5-cloud-services-aws-000001
wazuh-events-v5-cloud-services-azure-000001
wazuh-events-v5-cloud-services-gcp-000001
wazuh-events-v5-network-activity-000001
wazuh-events-v5-other-000001
wazuh-events-v5-security-000001
wazuh-events-v5-system-activity-000001

Aliases

wazuh-events-v5-access-management
wazuh-events-v5-applications
wazuh-events-v5-cloud-services
wazuh-events-v5-cloud-services-aws
wazuh-events-v5-cloud-services-azure
wazuh-events-v5-cloud-services-gcp
wazuh-events-v5-network-activity
wazuh-events-v5-other
wazuh-events-v5-security
wazuh-events-v5-system-activity