---
title: Docs - Wazuh SIEM Integration
description: Integrate ChallengeWord with Wazuh SIEM for enhanced social engineering threat detection and response. Follow steps to seamlessly set up API access and configuration.
---

[Skip to content](https://challengeword.com/docs/wazuh-siem-integration#main-content)

[![ChallengeWord](https://challengeword.com/hubfs/ChallengeWord_Horizontal_Color_Trim_SVG.svg "ChallengeWord")](https://challengeword.com)

- [Home](https://challengeword.com)
- [Solution](https://challengeword.com/solution) 
    - [For Business](https://challengeword.com/solution/business) 
          - [Business App](https://challengeword.com/mobile/business)
    - [For Personal](https://challengeword.com/solution/personal)
    - [Case Studies](https://challengeword.com/case-studies)
- [Pricing](https://challengeword.com/pricing)
- [Articles](https://challengeword.com/articles)
- [Support](https://challengeword.com/support)
- [Contact](https://challengeword.com/contact)
- [Login](https://my.challengeword.com)

Search

- There are no suggestions because the search field is empty.

Documentation

# Wazuh SIEM Integration

#### Overview

In the rapidly evolving world of cybersecurity, it's crucial to harness every tool in our arsenal to guard against threats, particularly social engineering attacks. This document details how to integrate Wazuh, a powerful Security Information and Event Management (SIEM) system, with ChallengeWord, the leader in social engineering protection.

#### Requirements

- Wazuh server (latest version recommended)
- ChallengeWord Business account with administrative access

### Step 1: Create a Rules File in Wazuh

- Navigate to your Wazuh manager’s rules directory.

![Greenshot 2024-04-28 14.45.49](https://challengeword.com/hs-fs/hubfs/Greenshot%202024-04-28%2014.45.49.png?width=867&height=448&name=Greenshot%202024-04-28%2014.45.49.png)

- Create a new rules file

![Greenshot 2024-04-28 14.46.42](https://challengeword.com/hs-fs/hubfs/Greenshot%202024-04-28%2014.46.42.png?width=806&height=225&name=Greenshot%202024-04-28%2014.46.42.png)

- Use the following template and customize if needed.
- Take note of the "integration" field value. We'll need that later.

|   | Filename: `challengeword.xml` `<group name="challengeword,">     <rule id="99999" level="10">         <decoded_as>json</decoded_as>         <field name="integration">ChallengeWord</field>         <description>ChallengeWord alert.</description>     </rule> </group>` |
| --- | --- |

### ![Greenshot 2024-04-28 14.47.28](https://challengeword.com/hs-fs/hubfs/Greenshot%202024-04-28%2014.47.28.png?width=562&height=293&name=Greenshot%202024-04-28%2014.47.28.png)

### Step 2: Establish API Access in Wazuh

- Create a new API user specifically for ChallengeWord integration, ensuring proper permissions are set for event submission.

 ![Greenshot 2024-04-28 15.14.49](https://challengeword.com/hs-fs/hubfs/Greenshot%202024-04-28%2015.14.49.png?width=718&height=450&name=Greenshot%202024-04-28%2015.14.49.png)

### Step 3: Configure ChallengeWord

- Log into your ChallengeWord portal.
- Navigate to: 
    - Settings
    - Incident Management
    - SIEM Integrations
- Click the "Add SIEM Integration" and select "Wazuh"
- Enter your Host (IP or FQDN) and update your Username & Password

![Greenshot 2024-04-28 15.27.51](https://challengeword.com/hs-fs/hubfs/Greenshot%202024-04-28%2015.27.51.png?width=866&height=599&name=Greenshot%202024-04-28%2015.27.51.png) 

- The first field of Event Data, "integration = ChallengeWord" must match the field from "challengeword.xml" created in Wazuh:

`<field name="integration">ChallengeWord</field>`

![Greenshot 2024-04-28 15.49.49](https://challengeword.com/hs-fs/hubfs/Greenshot%202024-04-28%2015.49.49.png?width=866&height=413&name=Greenshot%202024-04-28%2015.49.49.png)

- Wazuh receives event information as a Json object containing an "events" array of Json string data. ChallengeWord's Wazuh template is pre-configured and no changes to the section should be necessary.

|   | `{` `  "events": [` `    "{eventDataAsJsonString}"` `  ]` `}` |
| --- | --- |

![Greenshot 2024-04-28 15.50.18](https://challengeword.com/hs-fs/hubfs/Greenshot%202024-04-28%2015.50.18.png?width=865&height=407&name=Greenshot%202024-04-28%2015.50.18.png)

### Step 4: Test and Validate

- After setting up the integration, perform a test to ensure that the events from ChallengeWord are correctly being sent to and processed by Wazuh.
- ChallengeWord provides a "Test Pre-Auth" button and a "Test Event Submission" button for testing purposes.
- Verify that the events appear in the Wazuh dashboard and that alerts are generated according to the configured rules.

## Troubleshooting

- Ensure that the Wazuh's API port is accessible from the internet.
- Verify API credentials and permissions if ChallengeWord is unable to connect to the Wazuh server.
- Check the rules file for syntax errors if events are not triggering alerts as expected.

By following these steps, you can effectively integrate ChallengeWord with Wazuh, enhancing your ability to detect and respond to social engineering threats.

![ChallengeWord_Main_Dark_Trim_SVG](https://challengeword.com/hubfs/ChallengeWord_Main_Dark_Trim_SVG.svg "ChallengeWord_Main_Dark_Trim_SVG")

![Patent Pending](https://challengeword.com/hubfs/Patent%20Pending.svg "Patent Pending")

# 19/195,512

##### #MFA4IRL

The only human driven cybersecurity solution to Social Engineering attacks. 

#### About Us

[Security & Compliance](https://challengeword.com/security-and-compliance)

##### Our Office

800 N King Street   
Suite 304-1013  
Wilmington, DE 19801  
United States

###### *[support@challengeword.com](mailto:support@challengeword.com)*

##### Follow Us

[Follow us on Instagram](https://www.instagram.com/mfa4irl/) [Follow us on LinkedIn](https://www.linkedin.com/company/challengeword) [Follow us on Facebook](https://www.youtube.com/@ChallengeWord)

##### [Press Room](https://challengeword.com/press)

[challengeword.com/press](https://challengeword.com/press)

| © 2023-2025 ChallengeWord LLC - All rights reserved - [Disclaimer](https://challengeword.com/disclaimer) - [Credits](https://challengeword.com/credits) - [Status](http://status.challengeword.com/)<https://challengeword.com/disclaimer><https://challengeword.com/acceptable-use-policy> | [Privacy Policy](https://challengeword.com/privacy-policy) - [Cookie Policy](https://challengeword.com/cookie-policy) - [AUP](https://challengeword.com/acceptable-use-policy) - [Terms of Service](https://challengeword.com/terms-of-service) |
| --- | --- |

 