Wazuh alert processing workflow

★ 6.6 · n8n · medium · 7 nodes

Wazuh alert processing workflow is an n8n automation template that receives Wazuh SIEM alerts via webhook and routes them through a SOC pipeline automatically. Reach for it when analysts are overwhelmed by manual alert triage, when Wazuh notifications pile up without clear routing, or when the team needs incident emails sent automatically without investing in a full SOAR platform. Trigger: Webhook. Integrations: Gmail. The workflow accepts incoming Wazuh events at a webhook endpoint and delivers processed notifications via Gmail; it deploys by importing a JSON template into any n8n instance, self-hosted or cloud. The direction is inbound alert handling and notification routing — not infrastructure monitoring or alert generation (those happen on the Wazuh side). Use only on systems you are authorized to monitor and within your SOC team's sanctioned scope. Suits small to mid-sized security teams already running Wazuh with access to n8n; not the right fit if you need bidirectional ticketing integration or threat-intelligence enrichment, which require additional nodes beyond this template.