Write a custom Wazuh decoder and matching detection rule to parse and alert on a proprietary application log format

domain: documentation.wazuh.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Add a custom decoder definition in the manager's local decoder file, using decoder, prematch (or a parent decoder reference), regex, and order elements to extract fields from the raw log line.
  2. Add a corresponding rule in the manager's local rules file that references the decoder's extracted fields, sets a rule id, level, and group, and matches on the decoded field values.
  3. Point the log source at the manager — either via the agent's local log-collection configuration or direct manager-side log collection — so events actually reach the manager for decoding.
  4. Restart the Wazuh manager to load the new decoder and rule definitions, since changes are not applied live.
  5. Validate the new decoder/rule pair against sample log lines using the manager's log-testing utility before deploying broadly, confirming both the expected decoder and rule fire.

Known gotchas

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans