Tutorial ·Going further ·MS Pro ·Episode 3/5 Santa in Wazuh, from noise to an alert that speaks A lone Santa block is noise. Correlated in Wazuh, it's a detection. Teach your SIEM to decode then aggregate Santa events.
Tutorial ·Going further ·MS Pro ·Episode 2/5 Wazuh, write the rule that catches what you're really after Writing a custom Wazuh rule isn't about covering everything. It's asking one precise question to a real log, testing it with wazuh-logtest, then shipping it.
Tutorial ·Going further ·MS Pro ·Episode 1/5 Your sovereign SIEM, learn to read it properly then make it act Wazuh is installed and you don't know what to do with it. Three first jobs in the right order, without drowning in alerts.
Tutorial ·Going further ·MS Pro ·Episode 7/7 Alerting and total cost, the final tally of your sovereign SIEM Wire up Wazuh alerting without drowning in noise, then the honest bottom line on your sovereign stack against a SaaS bill six to thirty times heavier.
Tutorial ·Going further ·MS Pro ·Episode 3/7 Deploy Wazuh everywhere, your SIEM finally sees your network Enroll Wazuh agents on your Linux servers, Macs, and Windows workstations, with log upload via Tailnet, never through the open internet.
Tutorial ·Going further ·MS Pro ·Episode 2/7 Wazuh: Your all-in-one, homegrown Splunk for the price of a VPS Install Wazuh (manager, indexer, dashboard) on a single node, harden passwords and dashboard in Tailnet-only, adjust JVM heap, initial dashboards without agents.