Skip to content
All projects & labs

SOC Automation

Wazuh alert routing with n8n

A documented workflow that forwards Wazuh alerts into n8n, creates Jira issues, notifies Slack, and sends severity-based email.

Wazuhn8nJiraSlackEmail

Why this matters to a team

When alerts land in the right ticket queue and chat channel automatically, analysts spend less effort copying details between tools.

Example workflowillustrative
  1. 01

    Security event ingestion

    Endpoint & log sources

  2. 02

    Wazuh analysis

    Rules, decoders, severity

  3. 03

    n8n orchestration

    Parse, enrich, branch

Jira issue
Slack message
Email (high severity)

Problem

Security alerts generated in Wazuh often need to be manually copied into a ticketing system and shared with the right people, which is repetitive and easy to miss.

Documented approach

  1. 01Configure Wazuh to forward selected alerts to an n8n webhook.
  2. 02Parse the alert payload in n8n and extract the fields a responder needs.
  3. 03Branch by severity: create a Jira issue, post a Slack notification, and send email for higher-severity events.
  4. 04Document the setup step by step so it can be reproduced.

My contribution

Designed and built the workflow, published the repository, and wrote the step-by-step integration walkthrough.

Evidence

Limitations

This is a documented lab workflow. It does not represent a specific client deployment, and no response-time measurements are claimed.