2024-05-08 01:56:48 +02:00
|
|
|
---
|
|
|
|
|
#start of yaml
|
|
|
|
|
|
|
|
|
|
# This is the yaml config file for both the wazuh-ntfy-notifier.py and wazuh-discord-notifier.py.
|
|
|
|
|
# The yaml needs to be in the same folder as the wazuh-ntfy-notifier.py and wazuh-discord-notifier.py
|
|
|
|
|
|
|
|
|
|
targets: "discord,ntfy"
|
2024-05-10 13:23:28 +02:00
|
|
|
full_message: "discord,ntfy"
|
2024-05-08 01:56:48 +02:00
|
|
|
|
|
|
|
|
# Exclude rules that are listed in the ossec.conf active response definition.
|
|
|
|
|
|
2024-05-10 14:23:54 +02:00
|
|
|
excluded_rules: "5401,5403"
|
2024-05-08 01:56:48 +02:00
|
|
|
excluded_agents: "999"
|
|
|
|
|
|
|
|
|
|
# Priority mapping from 1-12 (Wazuh events) to 1-5 (Discord and ntfy notification)
|
|
|
|
|
|
2024-05-10 14:23:54 +02:00
|
|
|
priority_5: [15,14,13,12]
|
|
|
|
|
priority_4: [11,10,9]
|
|
|
|
|
priority_3: [8,7,6]
|
|
|
|
|
priority_2: [5,4]
|
|
|
|
|
priority_1: [3,2,1,0]
|
2024-05-08 01:56:48 +02:00
|
|
|
|
2024-05-08 15:09:35 +02:00
|
|
|
sender: "Wazuh (IDS)"
|
|
|
|
|
click: "https://google.com"
|
2024-05-08 01:56:48 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
#end of yaml
|
|
|
|
|
...
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|