Monitoring

wazuh

  • Open-source security platform (SIEM + XDR) built on the Elastic stack.
  • Use cases: log analysis, threat detection, file integrity monitoring (FIM), vulnerability detection, and compliance.
  • Core pieces: Wazuh agent (endpoints), Wazuh manager (analysis/rules), and Elastic/OpenSearch for indexing + dashboards.
  • Typical homelab setup: one manager + indexer + dashboard VM/container; agents on servers, desktops, and network appliances where possible.
  • Notes to capture: alert noise tuning (rules/decoders), retention/storage sizing, and update/backup plan for the index.
Last updated: September 3, 2026