Monitoring
wazuh
- Open-source security platform (SIEM + XDR) built on the Elastic stack.
- Use cases: log analysis, threat detection, file integrity monitoring (FIM), vulnerability detection, and compliance.
- Core pieces: Wazuh agent (endpoints), Wazuh manager (analysis/rules), and Elastic/OpenSearch for indexing + dashboards.
- Typical homelab setup: one manager + indexer + dashboard VM/container; agents on servers, desktops, and network appliances where possible.
- Notes to capture: alert noise tuning (rules/decoders), retention/storage sizing, and update/backup plan for the index.