Skip to content

[Bug] Wazuh responder problem with analyzer #1243

@romarito90

Description

@romarito90

Hello everyone I'm trying to get fix the problem in the wazuh responder

How can I get the data from an artifact or observable in a case ?

I created one new observable "agent_id" this is visible in my list of observables in the case in Thehive

imagen

How can I get the data from that field and pass to the payload to run the command firewalldrop

imagen

imagen

If I run the command like above this It works
imagen

When I change the code to the following the analyzer failed

imagen

imagen

what command or code I need to get that data from that field "agent_id " in this case 12079 ??

Work environment

  • Client OS: Windows 11
  • Browse type and version: Firefox
  • Cortex version: 3.1.7
  • Cortex Analyzer/Responder name: Wazuh 1.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions