Wazuh

Open-Source Security Monitoring & SIEM

Threat detection, log analysis, vulnerability management and compliance monitoring — unified in a single platform.

What is Wazuh?

Wazuh is a free, open-source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualised, containerised and cloud-based environments, providing enterprise-grade security capabilities without the hefty licensing fees of proprietary alternatives.

Think of it as a central security command centre for your infrastructure. It combines Host-based Intrusion Detection (HIDS) and Security Information and Event Management (SIEM) into a single tool, with over 10 million downloads per year and one of the largest open-source security communities worldwide.

Core Capabilities

Threat Detection

Monitor endpoints for malware, rootkits, suspicious behaviour and unauthorised file modifications

Log Data Analysis

Collect, aggregate and parse logs from OS, applications, firewalls and cloud environments

Vulnerability Detection

Scan systems for missing patches and known CVEs in installed software

Configuration Assessment

Audit systems against security benchmarks (CIS) to ensure hardened, secure configurations

File Integrity Monitoring

Track changes to critical files and directories for compliance and intrusion detection

Active Response

Automated actions on threat detection: block IPs, isolate hosts, execute remediation scripts

How It Works

Wazuh uses a classic Agent-Server architecture for comprehensive security monitoring.

Wazuh Agents

Lightweight agents installed on endpoints (Linux, Windows, macOS) monitor the local system and feed data to the manager

Wazuh Server (Manager)

The brain of the operation — receives data from agents, analyses against thousands of security rules and triggers alerts

Indexer & Dashboard

Powerful search engine and web UI (forked from OpenSearch) for visual tracking, filtering and analysis

Why Use Wazuh for Compliance?

Wazuh provides continuous monitoring and file integrity tracking that auditors look for, supporting multiple regulatory frameworks.

GDPR

Continuous monitoring, breach detection and audit logging for data protection compliance

PCI-DSS

File integrity monitoring, log management and access control for payment card environments

ISO 27001 / NIST-2

Configuration assessment, vulnerability detection and security monitoring for ISMS compliance

Integration with GLPI

Wazuh integrates directly with GLPI, turning security alerts into service desk actions.

Agent Synchronisation
Wazuh agents synchronise with GLPI devices, linking security data to your asset inventory.

Automated Ticket Creation
Security alerts from Wazuh automatically create GLPI tickets for immediate action.

Device-Level Visibility
View Wazuh alerts and vulnerabilities directly on GLPI device pages for full context.

Cross-Referenced Intelligence
Correlate Wazuh security events with Zabbix performance data for comprehensive analysis.