wazuh-documentation icon indicating copy to clipboard operation
wazuh-documentation copied to clipboard

Suggestion: First steps after installation

Open Selutario opened this issue 2 years ago • 0 comments

Description

I think that users can feel lost or overwhelmed with Wazuh after the installation of the manager and their first agent is complete. This is because the documentation is so large that it's not easy to know where to start once everything is installed. I think it would be really useful to add a new section at the end of the installation guides (of the manager, agent or both) or a link to a section that explains what are the most common next steps the user might need. This could include, among other things:

  • The state of Wazuh right after the installation or, in other words, what is being monitored by default and what is not (a very frequent question in the community). This should be different depending on which agent was installed.
  • How to monitor new log files.
  • How alerts are generated and how to create new decoders and custom rules.
  • How to monitor changes in folders or files (FIM) and what files might be useful to monitor.
  • Vulnerability detection.
  • Most frequent and useful integrations (Virustotal, AWS, etc).
  • Most frequent and useful manager's configurations (alerts by email, deletion of old rotated logs and indices, generation of automatic reports, etc).

Each of those points could include a short description of what it is useful for and a link to the corresponding section of the documentation. In summary, the goal is to guide the users through their first steps so that they do not feel lost.

Note: Original issue:

  • https://github.com/wazuh/wazuh/issues/15555#issuecomment-1333804323

Selutario avatar Dec 02 '22 16:12 Selutario