Adds real-time alert notifications by push, text and voice calls to your Wazuh
Integrated on-call duty and shift scheduling allows for automated routing of ticket alerts to the right people at the right time
User-friendly mobile app for Android and iPhone provides incident management on-the-go
Integrates with a few mouse-clicks into Wazuh
Why SIGNL4
Wazuh is an open-source security platform offering unified XDR and SIEM protection for endpoints and cloud workloads. It is used to collect, aggregate, index and analyze security data, helping organizations detect intrusions, threats and behavioral anomalies.
SIGNL4 adds app-based alerting and incident response. This includes alerts app-push, text and voice call and strategic escalations when needed. The integration of Wazuh and SIGNL4 introduces an advanced duty scheduling system, ensuring that on-call responsibilities are efficiently allocated and allows you to see who is on duty at any given time.
How it Works
Wazuh uses webhooks to submit alert information to SIGNL4. You can simply configure it by entering your SIGNL4 webhook URL including team secret / integration secret. Specifically the integration helps you with the following.
Benefits and Value-Add
Scenarios
Integration Type
Alerts in Wazuh are sent to SIGNL4 via HTTP request
Event categorization, routing and automated delivery based on availability, duty schedules, etc.
Persistent Notifications by push, text and voice call with Tracking, Escalation and Confirmation to Staff on Duty
In the Wazuh web portal log in as a admin to configure SIGNL4 alerting.
Under Notifications create a new channel of the type Custom webhook. The Webhook URL is your SIGNL4 webhook URL including team or integration secret.
https://connect.signl4.com/webhook/{team-secret}
Here, {team-secret} is your SIGNL4 team secret.
The header value Content-Type is application/json.
You can also send a test alert here.
Under Alerting -> Monitors create a new monitor that triggers when you would like to send an alert. You need to configure the Trigger accordingly.
The Action will trigger the SIGNL4 alert. You select the SIGNL4 notification channel that you have created in the previous step. The message is in JSON format and might look like follows.
{
"AlertMonitor": "{{ctx.monitor.name}} just entered alert status. Please investigate the issue.",
"Trigger": "{{ctx.trigger.name}}",
"Severity": "{{ctx.trigger.severity}}",
"PeriodStart": "{{ctx.periodStart}}",
"PeriodEnd": "{{ctx.periodEnd}}",
"X-S4-SourceSystem": "Wazuh",
"X-S4-ExternalID": "Wazuh: {{ctx.trigger.name}}",
"X-S4-Status": "new"
}
You can also automatically close alerts is the status in Wazuh is OK again. In this case you specify a Trigger for the OK condition and the message in the SIGNL4 action might look like this.
{
"X-S4-ExternalID": "Wazuh: {{ctx.trigger.name}}",
"X-S4-Status": "resolved"
}
The value for X-S4-ExternalID is the same as for the previously opened alert.
Alert Optimization
SIGNL4 can further increase the visibility of alerts through its Signals and Services categories. Augmenting the color and icon of alerts will provide more relevant information at a glance without having to open the alert. You can also augment alerts with maps or change the subject or message to a more comprehensible content.
Alert categories in SIGNL4 also allow to group alerts and even to route those ticket notifications to your staff based on skills or other criteria. Screenshots show how to override text, colors and titles are triggered by keywords set within the mobile app.
Duty Scheduling
SIGNL4’s duty scheduling feature streamlines Wazuh alert management by directing notifications to on-call staff. By pre-defining shifts and on-call schedules, Wazuh alerts are routed to available and relevant team members, reducing response times. This eliminates the chaos of alert floods during off-hours and ensures that critical incidents get immediate attention.
With SIGNL4, on-call scheduling is done with just a few mouse clicks and in no time at all. Instead of Excel spreadsheets, planning is done conveniently and transparently in the web browser. It offers a real-time “Who is on duty” dashboard with real-time, digital information. It facilitates shift handovers with mobile reminders, automated punch-ins/outs and handover assistants. Additionally, it provides post-shift email reports, audit trails and downloadable duty records. Read more about On-call Management here.