Technology pageSIEM · DETECTIONTier 2

Wazuh

Detection on the servers themselves: what changed, who got in, and what shouldn't have.

The topicWhat we're talking about

Wazuh is an open-source detection platform: an agent installed on each server reports system events, watches file integrity, flags configurations drifting from a baseline, and raises readable alerts in a single console. Where a firewall and an IP blocker stop people getting in, Wazuh answers the other question — the one always asked too late: has someone already got in, and what did they touch?

My opinionMy owned point of view

My take on Wazuh: it's what I propose once prevention is in place and what's missing is the eyes.

Stopping intrusions is necessary; being able to say, three months later, which file was modified and by which account is what separates an incident handled from an incident endured. I deploy it with one reservation I state up front: a detection platform produces alerts, and alerts nobody reads protect nobody.

So I tune it to speak rarely and speak accurately — a handful of signals someone can actually act on, rather than a daily stream that ends up ignored.

Relevant when
  • Several production servers whose history must be reconstructable after an incident
  • Compliance or insurance requirement calling for traceability of access and changes
  • File integrity monitoring: knowing an application file changed outside a deployment
  • Need to centralise logs from heterogeneous machines behind one console
Skip it when
  • ×Nobody to read the alerts: a detection platform with no recipient is a cost, not a protection
  • ×One or two simple servers: log monitoring and an IP blocker already cover the essentials
  • ×Fully managed hosting with no system access: there's no agent to install
My approachHow I tackle it concretely
  1. 01

    Scope first: which servers, which logs, and above all which alerts should wake someone up

  2. 02

    Agents deployed through automation, never machine by machine by hand

  3. 03

    Noise tuning from the first week: without that pass, the console becomes a wall of ignored alerts

  4. 04

    Integrity monitoring limited to the directories that matter, aligned with the deployment rhythm

  5. 05

    Written incident procedure: who is notified, what they look at first, what they isolate

Frequently asked questionsAbout this technology specifically
  • How is this different from an IP blocker like CrowdSec?
    They answer different questions. CrowdSec stops people getting in: it spots attack behaviour and blocks the address. Wazuh watches what happens on the machine: modified files, created accounts, privilege escalations, drifting configuration. One is a door, the other is a camera. On serious infrastructure, both coexist.
  • Wazuh and the ELK stack — isn't that redundant?
    No, they stack. Wazuh builds on an indexing engine from the same family and can forward its alerts into an existing stack. The difference is what sits on top: ELK is a search engine over your logs, Wazuh adds detection rules, compliance baselines and integrity monitoring. If you already run ELK, Wazuh brings the intelligence, not the storage.
  • What does it cost to run?
    The software is open source, with no licence fee. The running cost is the server that receives and indexes: memory and disk grow with the number of agents and the log retention period. A managed offering from the vendor exists if you'd rather not operate that machine yourself.
  • What does a Wazuh deployment cost?
    The weight isn't in the install, it's in the tuning: the number of servers and how heterogeneous they are, the compliance baselines to apply, the retention required, and how many rules need adjusting to keep alerts readable. The amount is set in the quote, after a free initial scoping session that puts the scope in writing before any commitment.
  • Do I need a dedicated security team to run it?
    No, but you need a named recipient. On an SMB estate, a few well-tuned rules produce a handful of genuinely actionable alerts, and that can fit inside existing operations. What doesn't work is plugging the platform in without deciding in advance who looks, how often, and what they do with what they see.
SIEM · DETECTION

A project involving Wazuh?

Describe your context: I'll suggest the right level of investment.

First call
07 /Contact

Let's talk aboutyour project.

Describe your need in a few lines. Reply within 24h to plan next steps, detailed quote within 48h.

  • 24h response
  • NDA on request

By sending this form, you agree that your information will be used to respond to your request. Stored for 3 years, never shared with third-party advertisers. Learn more

Bordeaux & Nouvelle-Aquitaine