MYTHOSAI

Monitoring / PRACTICAL GUIDE

Create a small Wazuh file-integrity monitoring lab

Monitor a dedicated test directory and explain a file-change alert without touching business data.

Before you start

An enrolled Linux Wazuh agent, manager access and permission to edit agent configuration.

Monitor something you can safely change

File-integrity monitoring records changes to selected files and metadata. A change is not automatically malicious: an update, administrator or application can cause it. Begin with a dedicated lab directory so your test does not involve patient records, real credentials or system configuration.

Prepare the test directory

On the enrolled Linux endpoint:

bash
sudo mkdir -p /opt/mythosai-fim-lab
printf 'baseline\n' | sudo tee /opt/mythosai-fim-lab/example.txt > /dev/null

Confirm the directory is exclusively for this exercise. Do not put sensitive content into a demonstration file.

Add a narrow monitoring entry

Back up the existing agent configuration through your normal administrative process. In the existing syscheck section, add an entry following the documentation for your installed Wazuh version:

xml
<directories realtime="yes">/opt/mythosai-fim-lab</directories>

Do not replace the entire syscheck block or paste a second full configuration over the file. Central group configuration can also affect agent behaviour, so review the effective design rather than editing two competing locations.

Restart the agent through its supported service process after validating your configuration. Wait for the initial scan and baseline according to the configured schedule.

Generate one harmless change

bash
printf 'changed during an authorised lab exercise\n' |
  sudo tee -a /opt/mythosai-fim-lab/example.txt > /dev/null

Search the manager's file-integrity view or security events using the correct agent and time window. Match the path and time to your intentional change. Changes made before monitoring was active may appear only as baseline data, not a later modification alert.

Verify the meaning

Explain whether the event describes creation, modification or deletion and which attributes changed. A checksum difference proves contents differ; it does not identify the person or intent unless other collected evidence supports that conclusion.

Common mistakes

Monitoring a large frequently changing directory in real time can generate excessive events and load. Reporting file differences can disclose contents, so do not enable that capability broadly for confidential files. A dashboard with no alert might indicate timing, configuration or transport issues rather than no change.

Clean up

Remove the lab monitoring entry through the same configuration route, restart as documented and remove only your test files when no longer needed. Keep the event as a harmless teaching example if your retention policy allows it.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.