Wazuh decoders and detection rules for MikroTik RouterOS syslog output. Covers firewall drops, DHCP leases, system events, login failures, and brute force detection. Tested on RouterOS 7.x and Wazuh 4.12–4.14.
H2FSpawn/wazuh-mikrotik-decoder is carrying a momentum pulse of 0/100 with no cross-source channels firing yet — GitHub-stars-only signal so far.
It sits at 9 stars without a fresh weekly delta on record — the trending placement here is steady-state interest in the other category rather than a 7-day breakout.
Watch-outs: no tagged release on record (treat as pre-stable).
git clone https://github.com/H2FSpawn/wazuh-mikrotik-decoder.gitThen follow the README in the cloned directory.
//COMMENTS · 0
Sign in to join the discussion