wazuh_alert_summary
Generate a high-level summary of recent alerts including severity distribution, top attacking IPs, most triggered rules, and MITRE technique coverage. Ideal for security posture assessment or shift handoff.
Instructions
Get a high-level summary of recent alerts: severity distribution, top attacking IPs, most triggered rules, and MITRE technique coverage. Use this as the first step in security posture assessment or shift handoff.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| hours_back | No | Number of hours to look back for the summary (default: 24) | |
| min_level | No | Minimum alert level to include (default: 7, moderate and above) |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |