Tutorial ·Going further ·MS Pro ·Episode 3/5 Santa in Wazuh, from noise to an alert that speaks A lone Santa block is noise. Correlated in Wazuh, it's a detection. Teach your SIEM to decode then aggregate Santa events.
Tutorial ·Going further ·MS Pro ·Episode 2/5 Wazuh, write the rule that catches what you're really after Writing a custom Wazuh rule isn't about covering everything. It's asking one precise question to a real log, testing it with wazuh-logtest, then shipping it.
Tutorial ·Going further ·MS Pro ·Episode 1/5 Your sovereign SIEM, learn to read it properly then make it act Wazuh is installed and you don't know what to do with it. Three first jobs in the right order, without drowning in alerts.
Tutorial ·Going further ·MS Pro ·Episode 7/7 Alerting and total cost, the final tally of your sovereign SIEM Wire up Wazuh alerting without drowning in noise, then the honest bottom line on your sovereign stack against a SaaS bill six to thirty times heavier.
Tutorial ·Going further ·MS Pro ·Episode 6/7 Santa on your Macs, the uninvited binary stays at the door Install Santa on your Macs, map the fleet in Monitor mode, switch to Lockdown, write your allowlist by TeamID, and feed every block into Wazuh.
Tutorial ·Going further ·MS Pro ·Episode 5/7 Rspamd in front of your inbox, phishing stops at the doormat Install Rspamd in front of your mail server, tune the anti-spam and anti-phishing scoring, and feed every verdict into your Wazuh SIEM.
Tutorial ·Going further ·MS Pro ·Episode 4/7 CrowdSec up front, blocking before they hit you Install CrowdSec on your hardened VPS, block malicious IPs upstream with the bouncer firewall, and feed its decisions into Wazuh.
Tutorial ·Going further ·MS Pro ·Episode 3/7 Deploy Wazuh everywhere, your SIEM finally sees your network Enroll Wazuh agents on your Linux servers, Macs, and Windows workstations, with log upload via Tailnet, never through the open internet.
Tutorial ·Going further ·MS Pro ·Episode 2/7 Wazuh: Your all-in-one, homegrown Splunk for the price of a VPS Install Wazuh (manager, indexer, dashboard) on a single node, harden passwords and dashboard in Tailnet-only, adjust JVM heap, initial dashboards without agents.
Tutorial ·Going further ·MS Pro ·Episode 1/7 Your sovereign SIEM's foundation, a hardened VPS outside the CLOUD Act A European VPS, Cloud Act-proof, hardened SSH, reduced attack surface via Tailscale, off-site encrypted backups.
Tutorial ·Going further ·MS Pro ·Episode 0/7 Build your sovereign SIEM for SMEs, compliant with GDPR/NIS2 without CLOUD Act You're already forced by GDPR to detect a breach within 72 hours. NIS2 just widened the net by 30x. Build your SIEM now, it's security today and compliance amortised before it lands on you.