MacSouverain

  • Home
  • Tutorials
  • Comparisons
  • Explainers
  • AI
  • My stack
  • Radar
FREN

Wazuh

Wazuh, write the rule that catches what you're really after
Tutorial ·Going further ·MS Pro ·Episode 2/5

Wazuh, write the rule that catches what you're really after

Writing a custom Wazuh rule isn't about covering everything. It's asking one precise question to a real log, testing it with wazuh-logtest, then shipping it.
Your sovereign SIEM, learn to read it properly then make it act
Tutorial ·Going further ·MS Pro ·Episode 1/5

Your sovereign SIEM, learn to read it properly then make it act

Wazuh is installed and you don't know what to do with it. Three first jobs in the right order, without drowning in alerts.
Alerting and total cost, the final tally of your sovereign SIEM
Tutorial ·Going further ·MS Pro ·Episode 7/7

Alerting and total cost, the final tally of your sovereign SIEM

Wire up Wazuh alerting without drowning in noise, then the honest bottom line on your sovereign stack against a SaaS bill six to thirty times heavier.
Deploy Wazuh everywhere, your SIEM finally sees your network
Tutorial ·Going further ·MS Pro ·Episode 3/7

Deploy Wazuh everywhere, your SIEM finally sees your network

Enroll Wazuh agents on your Linux servers, Macs, and Windows workstations, with log upload via Tailnet, never through the open internet.
Wazuh: Your all-in-one, homegrown Splunk for the price of a VPS
Tutorial ·Going further ·MS Pro ·Episode 2/7

Wazuh: Your all-in-one, homegrown Splunk for the price of a VPS

Install Wazuh (manager, indexer, dashboard) on a single node, harden passwords and dashboard in Tailnet-only, adjust JVM heap, initial dashboards without agents.
MacSouverain © 2026 Privacy Legal notice Cookies Terms of use About