SOC Automation
Wazuh alert routing with n8n
A documented workflow that forwards Wazuh alerts into n8n, creates Jira issues, notifies Slack, and sends severity-based email.
Why this matters to a team
When alerts land in the right ticket queue and chat channel automatically, analysts spend less effort copying details between tools.
- 01
Security event ingestion
Endpoint & log sources
- 02
Wazuh analysis
Rules, decoders, severity
- 03
n8n orchestration
Parse, enrich, branch
Problem
Security alerts generated in Wazuh often need to be manually copied into a ticketing system and shared with the right people, which is repetitive and easy to miss.
Documented approach
- 01Configure Wazuh to forward selected alerts to an n8n webhook.
- 02Parse the alert payload in n8n and extract the fields a responder needs.
- 03Branch by severity: create a Jira issue, post a Slack notification, and send email for higher-severity events.
- 04Document the setup step by step so it can be reproduced.
My contribution
Designed and built the workflow, published the repository, and wrote the step-by-step integration walkthrough.
Evidence
Limitations
This is a documented lab workflow. It does not represent a specific client deployment, and no response-time measurements are claimed.