Wazuh
Open-Source Security Monitoring & SIEM
Threat detection, log analysis, vulnerability management and compliance monitoring — unified in a single platform.
What is Wazuh?
Wazuh is a free, open-source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualised, containerised and cloud-based environments, providing enterprise-grade security capabilities without the hefty licensing fees of proprietary alternatives.
Think of it as a central security command centre for your infrastructure. It combines Host-based Intrusion Detection (HIDS) and Security Information and Event Management (SIEM) into a single tool, with over 10 million downloads per year and one of the largest open-source security communities worldwide.
Core Capabilities
Threat Detection
Monitor endpoints for malware, rootkits, suspicious behaviour and unauthorised file modifications
Log Data Analysis
Collect, aggregate and parse logs from OS, applications, firewalls and cloud environments
Vulnerability Detection
Scan systems for missing patches and known CVEs in installed software
Configuration Assessment
Audit systems against security benchmarks (CIS) to ensure hardened, secure configurations
File Integrity Monitoring
Track changes to critical files and directories for compliance and intrusion detection
Active Response
Automated actions on threat detection: block IPs, isolate hosts, execute remediation scripts
How It Works
Wazuh uses a classic Agent-Server architecture for comprehensive security monitoring.
Wazuh Agents
Lightweight agents installed on endpoints (Linux, Windows, macOS) monitor the local system and feed data to the manager
Wazuh Server (Manager)
The brain of the operation — receives data from agents, analyses against thousands of security rules and triggers alerts
Indexer & Dashboard
Powerful search engine and web UI (forked from OpenSearch) for visual tracking, filtering and analysis
Why Use Wazuh for Compliance?
Wazuh provides continuous monitoring and file integrity tracking that auditors look for, supporting multiple regulatory frameworks.
GDPR
Continuous monitoring, breach detection and audit logging for data protection compliance
PCI-DSS
File integrity monitoring, log management and access control for payment card environments
ISO 27001 / NIST-2
Configuration assessment, vulnerability detection and security monitoring for ISMS compliance
Integration with GLPI
Wazuh integrates directly with GLPI, turning security alerts into service desk actions.
Agent Synchronisation
Wazuh agents synchronise with GLPI devices, linking security data to your asset inventory.
Automated Ticket Creation
Security alerts from Wazuh automatically create GLPI tickets for immediate action.
Device-Level Visibility
View Wazuh alerts and vulnerabilities directly on GLPI device pages for full context.
Cross-Referenced Intelligence
Correlate Wazuh security events with Zabbix performance data for comprehensive analysis.