Wazuh × Tines

Integrating Tines and Wazuh empowers security teams to automate incident detection and response workflows, enhancing operational efficiency and threat management capabilities.

Pre-built templates

With Tines, you can easily take any action that has a defined API. We've already pre-built some of the most popular ones for you, so you can build quickly.

Update rules file in Wazuh
Update group configuration in Wazuh
Update decoders file in Wazuh
Update agents in Wazuh
Update agents custom in Wazuh
Trigger restart agents in Wazuh
Trigger restart agents in node in Wazuh
Trigger restart agents in group in Wazuh
Trigger restart agent in Wazuh
Trigger force reconnect agents in Wazuh
Run syscheck scan in Wazuh
Run rootcheck scan in Wazuh
Run command in Wazuh
List tasks in Wazuh
List rules in Wazuh
List outdated agents in Wazuh
List decoders in Wazuh
List agents without group in Wazuh
List agents in Wazuh
List agents distinct in Wazuh

Build your own connections

With Tines, you can easily take any action that has a defined API using an HTTP request. To build even more quickly, copy a cURL command and paste it into the storyboard.

cURL request

curl -v -X GET --location "https://api.nasa.gov/neo/rest/v1/neo/browse?api_key=DEMO_KEY" -H 'Content-Type: application/json'

Paste in your Tines story

Full workflow examples

Explore pre-built workflows for Wazuh. Use them for inspiration or as a starting point to build your custom automation solution.

Retrieve logs from the Wazuh Indexer

Retrieve Cowrie honeypot logs from Wazuh Indexer. Enrich the source IP and record the event in Tines records alongside the used username and password.

Created by

Conor Dunne

Trusted by industry innovators

CanvaCode42CoinbaseDropboxElasticGitLab
IntercomMarsMcKessonOpenTableSnowflakeReddit

Built by you,
powered by Tines

Already have an account? Log in.