PROBLEM
SIEM is installed and the analyst cannot say where the alert came from or how to replay it.
PODEJŚCIE
Document the path: endpoint → agent → parser → rule → alert.
ARCHITECTURE
- Wazuh manager in the lab
- agents on Windows and Linux
- a few rules with an explicit test
IMPLEMENTATION
- lab install
- first endpoint logs
- one rule with a true test and a decoy
RESULT
- pipeline described in docs and a blog post
- a rule-review template as a resource
- no invented client MTTD
LESSONS
- a rule without a test is decoration
- alert ≠ incident
Goal
Wazuh in this portfolio is a SIEM lab: it shows how an alert is born, not that “I deployed Wazuh at company X”.
Status
development. Manager, agents and a few scenarios are in progress. No screenshots from other people’s estates, no fake KPI.
See also: Wazuh as a starting point and the rule review template.