|
|
1 mese fa | |
|---|---|---|
| .. | ||
| README.md | 1 mese fa | |
| send-wazuh-test-events.sh | 1 mese fa | |
Use this to inject synthetic SOC events via syslog UDP into Wazuh manager.
scripts/send-wazuh-test-events.sh [scenario] [count] [delay_seconds]
Scenarios:
ioc_dnsioc_ipsvpn_outside_thwindows_auth_failallExamples:
scripts/send-wazuh-test-events.sh all
scripts/send-wazuh-test-events.sh vpn_outside_th 5 0.2
WAZUH_SYSLOG_HOST=127.0.0.1 WAZUH_SYSLOG_PORT=514 scripts/send-wazuh-test-events.sh ioc_ips
Environment overrides:
WAZUH_SYSLOG_HOST (default 127.0.0.1)WAZUH_SYSLOG_PORT (default 514)WAZUH_TEST_SRC_IPWAZUH_TEST_DOMAINWAZUH_TEST_USER