Wazuh: writing custom rules and decoders so your SIEM doesn't drown in noise (part 3/6)
Part 3 of the Wazuh series: the anatomy of rules and decoders, a custom SSH brute-force detection with a threshold you own, a decoder for your application's JSON logs, overriding default rules instead of editing them, and testing everything with wazuh-logtest without restarting the manager.