diff --git "a/datasets/service2_dataset_v3_1500.jsonl" "b/datasets/service2_dataset_v3_1500.jsonl" new file mode 100644--- /dev/null +++ "b/datasets/service2_dataset_v3_1500.jsonl" @@ -0,0 +1,1500 @@ +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 99, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "high", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "CORE-R1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "CORE-R1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "corp.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "corp.local", "reachable_dns": ["10.1.0.53", "10.1.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name corp.local", "ip name-server 10.1.0.53", "ip name-server 10.1.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 20, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 20, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 20", "ip arp inspection vlan 20"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "high", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "EDGE-FW1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "EDGE-FW1", "vlan": 30, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 40, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "BRANCH-RTR1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "BRANCH-RTR1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 40, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 40, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 40", "ip arp inspection vlan 40"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "medium", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 99, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 99, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 99", "ip arp inspection vlan 99"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 30, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 30, "attacker_ip": "10.10.10.5"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 30", "ip arp inspection vlan 30"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "CORE-R1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "CORE-R1", "vlan": 10, "attacker_ip": "198.51.100.77"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "arp_spoofing", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "ARP spoofing suspected", "device": "BRANCH-RTR1", "severity": "high", "vlan": 10, "description": "Duplicate ARP replies detected."}, "devices": [{"name": "BRANCH-RTR1", "vlan": 10, "attacker_ip": "203.0.113.45"}], "cli_fix": ["ip dhcp snooping", "ip dhcp snooping vlan 10", "ip arp inspection vlan 10"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "CORE-R1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "CORE-R1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "EDGE-FW1", "severity": "medium", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "EDGE-FW1", "ntp_servers": ["10.0.0.123", "10.0.1.123"], "source_interface": "Loopback0"}], "cli_fix": ["ntp server 10.0.0.123", "ntp server 10.0.1.123", "ntp source Loopback0", "ntp update-calendar"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "medium", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "dns_issues", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "DNS resolution issues detected", "device": "EDGE-FW1", "severity": "high", "domain": "safe.local", "description": "DNS resolution failures observed."}, "devices": [{"name": "EDGE-FW1", "failed_domain": "safe.local", "reachable_dns": ["10.0.0.53", "10.0.1.53"]}], "cli_fix": ["ip domain-lookup", "ip domain-name safe.local", "ip name-server 10.0.0.53", "ip name-server 10.0.1.53"]} +{"incident_type": "ntp_unsynchronize", "instruction": "Analyze network services incidents (DNS/NTP/ARP security) and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "NTP unsynchronized", "device": "BRANCH-RTR1", "severity": "high", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "description": "NTP stratum 16 / unsynchronized."}, "devices": [{"name": "BRANCH-RTR1", "ntp_servers": ["10.2.0.123", "10.2.1.123"], "source_interface": "Vlan99"}], "cli_fix": ["ntp server 10.2.0.123", "ntp server 10.2.1.123", "ntp source Vlan99", "ntp update-calendar"]}