Wazuh 5.0 lands, your home SIEM evolves

Wazuh 5.0 in public beta, releasing late June/early July. Filebeat dit au revoir, clusters enabled by default, new engine. Your 4.x install will upgrade. Don't worry, we'll explain it all.

If you’ve set up your home SIEM following episode 2/7 of the Sovereign SIEM series, brace yourself: Wazuh 5.0 is here in public beta, and it’s shaking things up. Don’t panic, but do take a look before blindly updating. And we’ll update the SIEM series when the time comes.

The Deal

Wazuh has just released the public beta of its 5.0 version, with a stable release estimated for late June or early July 2026. This isn’t just a version bump, it’s an architectural overhaul.

What’s changing, concretely: Filebeat is gone, replaced by a native indexer-connector integrated into the manager. Every Wazuh server becomes a cluster node by default, even in a single-server install. The old analysisd engine, which handled logs and triggered rules, is replaced by a new one. Vulnerability detection has shifted to Wazuh Indexer, centralized. And Role-Based Access Control (RBAC), fine-grained permissions management, has been entirely revamped.

Direct consequence for MacSouverain: episode 2/7 of the Sovereign SIEM series, which documents the 4.x architecture step-by-step, will be partially outdated once 5.0 is released. We’ll update the series when 5.0 is stable, not before.

Why It Matters to You

If you’ve followed the guide in episode 2/7 of the Sovereign SIEM series to set up your own SIEM, you’re likely running on a 4.x version. Good news, your setup continues to work, no one’s pulling the plug. Bad news, upgrading to 5.0 won’t be as simple as apt upgrade without reading the docs. Bye-bye Filebeat, that means your log pipeline’s plumbing is changing. Default cluster, that changes your initial config even if you’re sticking to one machine.

Practical translation: if you were planning to upgrade as soon as it’s out, take an hour to read the release notes and make a snapshot first. If you’re on a stable setup you use daily, wait for one or two corrective versions, let the early adopters iron out the kinks.

What It Changes for You

1. Note which version of Wazuh you’re currently running. On your manager, use wazuh-control info or check the dashboard. If you’re on 4.11 or later, you’re on the branch that’s still receiving updates.

2. Before attempting to upgrade to 5.0, snapshot your VM or backup your config /var/ossec/etc/ and your Wazuh Indexer’s state. A clean rollback saves your bacon if the new engine doesn’t play nice with your custom rules.

3. Wait for the stable 5.0.x release (at least 5.0.1 or 5.0.2) before migrating a production personal install. Beta’s for testing on disposable VMs, not the one monitoring your network every day. Keep an eye on: Wazuh’s official migration guide from 4.x to 5.0, and the upcoming overhaul of episode 2/7 of the Sovereign SIEM series on MacSouverain.

Sources