SIEM / Blue Team

Wazuh SIEM

From raw log to an alert you can keep or close.

developmentYEAR: 2026

PROBLEM

SIEM is installed and the analyst cannot say where the alert came from or how to replay it.

PODEJŚCIE

Document the path: endpoint → agent → parser → rule → alert.

ARCHITECTURE

  • Wazuh manager in the lab
  • agents on Windows and Linux
  • a few rules with an explicit test

IMPLEMENTATION

  • lab install
  • first endpoint logs
  • one rule with a true test and a decoy

RESULT

  • pipeline described in docs and a blog post
  • a rule-review template as a resource
  • no invented client MTTD

LESSONS

  • a rule without a test is decoration
  • alert ≠ incident

Goal

Wazuh in this portfolio is a SIEM lab: it shows how an alert is born, not that “I deployed Wazuh at company X”.

Status

development. Manager, agents and a few scenarios are in progress. No screenshots from other people’s estates, no fake KPI.

See also: Wazuh as a starting point and the rule review template.

Want a similar setup?

This is a lab / concrete loop, not a slide. Tell me what you have on the table.

The inquiry is stored on the server. The operator is notified on Telegram. There is no email autoresponder.