WazuhImplementation and monitoring

    Wazuh: implementation and 24/7 monitoring

    We stand Wazuh up and get it running in one week. Deployment goes through Terraform and Ansible, detection rules live in a versioned repository, and agents roll out in bulk. After that we can take it into round-the-clock monitoring.

    Wazuh

    What Wazuh is

    An open platform for detection that combines SIEM and XDR behind a single agent.

    Wazuh is an open-source security platform licensed under GPLv2. It combines SIEM and XDR: it collects logs and telemetry from agents on endpoints and servers, evaluates them against rulesets, watches file integrity, detects vulnerabilities and checks configuration against CIS benchmarks. Data lands in its own indexer built on OpenSearch. The licence is free, so you pay for infrastructure and for the people who operate the platform.

    Timeline

    One week to production

    The whole deployment is described as code. Every customer gets the same procedure with different parameters, which is why it can be planned in days.

    1. Days 1–2

      Architecture and deployment

      • Terraform stands up the cluster, the indexer and the network; Ansible finishes the configuration.

      • Indexer sizing, sharding and retention are set against the volume you give us.

    2. Days 3–4

      Agents and sources

      • Bulk agent rollout across Windows, Linux and macOS through your endpoint management.

      • Firewalls, cloud and network gear are onboarded over syslog and API.

    3. Day 5

      Detection content

      • We deploy our rule library mapped to MITRE ATT&CK and add decoders for your applications.

      • Rules and decoders live in a versioned repository and ship through the same pipeline as the rest of the infrastructure.

    4. Days 6–7

      Tuning and handover

      • We work through the first wave of alerts, silence the noise, and set up Active Response and ticketing integration.

      • By the end of the week the platform is running and sending what it should.

    That is the platform. If you also want a 24/7 team managing it, SOC and MDR onboarding takes 14 days, adding the threat model, deeper tuning and the live SOC portal. SOC & MDR

    How we do it

    Infrastructure as code, detection as code

    The two things that separate a one-week deployment from a quarter-long project.

    Infrastructure as Code
    Cluster, indexer, retention and network zones are described in Terraform and Ansible. The environment can be rebuilt, moved or extended without anyone having to remember what was once clicked through a UI.
    Detection as Code
    Rules, decoders and Active Response are files in Git. They have an author, a history and a review, so you know when detection changed and why. New versions ship through a pipeline rather than by hand on production.
    Implementation

    Where the time actually goes

    Installation finishes in minutes. This is the work that makes the platform catch anything.

    Capacity and retention
    Indexer sizing, sharding and retention period. Badly planned retention is the most common reason a Wazuh deployment collapses under its own data after six months.
    Agentless sources
    Firewalls, cloud audit logs and network gear over syslog and API. Usually a bigger job than the agent rollout.
    Custom decoders
    The default set understands common software. It does not understand your in-house applications, so we write decoders for them.
    Noise tuning
    On default rules Wazuh emits thousands of alerts a day and the team stops reading them. Tuning is the part a deployment without follow-on operations never finishes.
    Response and automation
    Active Response, ticketing integration and playbooks, so detection leads to an action.
    Operations and upgrades
    Versions, index migrations, backups and monitoring of the platform itself. Wazuh is a production system and needs the same care as the rest.
    Monitoring

    Wazuh monitoring, 24/7

    Who looks at the alerts at three in the morning.

    We can both build Wazuh and watch it around the clock. Alerts reach our analysts, who triage, separate noise from incident and contain the incident. The platform stays yours: it runs in your infrastructure or in ours, whichever suits you, and its data goes nowhere else. If you end the engagement you keep Wazuh along with the detection content we wrote for it, repository included.

    The decision

    Why Wazuh

    It does not fit everything. Where it fits, the cost difference is decisive.

    No per-gigabyte billing
    Commercial SIEMs charge by data volume, so logs stop being collected for budget reasons. Wazuh has no licence ceiling and you collect what you need.
    Data stays with you
    Running it in your own infrastructure answers data-locality requirements that a cloud SIEM struggles with.
    Evidence for regulators
    Configuration assessment, file integrity monitoring and vulnerability inventory are exactly the evidence NIS2, ISO/IEC 27001 and TISAX ask for.
    You can take it with you
    Rules and decoders are readable files in a versioned repository. You can review them, comment on them and leave with them.
    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    Wazuh is an open-source security monitoring platform that combines SIEM and XDR capabilities. It is released under GPLv2, so there are no licence fees and no charge for data volume. It collects logs and telemetry through agents on endpoints and servers, evaluates them against rulesets, monitors file integrity, detects vulnerabilities and checks configuration against CIS benchmarks. Source code and documentation are public at documentation.wazuh.com.

    The software itself is free; the cost is infrastructure and work. Because deployment runs through Terraform and Ansible, that work is short and predictable. Price is driven by agent count, the number of agentless sources, the retention period you need, and whether you operate the platform yourself or we take over monitoring. Because Wazuh does not bill per gigabyte, cost does not step up as log volume grows the way it does with commercial SIEMs. We scope the specifics against your environment.

    One week to full operation. Days 1 to 2 build the cluster, indexer and network with Terraform and Ansible; days 3 to 4 roll out agents and onboard agentless sources; day 5 deploys detection content and decoders for your applications; days 6 to 7 tune the noise and hand over. It holds because deployment and detection are both code, so every customer gets the same procedure with different parameters. If you also want a 24/7 team managing it, SOC and MDR onboarding takes 14 days and adds the threat model, deeper tuning and the live SOC portal.

    Wazuh covers a substantial part of the technical measures but does not deliver compliance on its own. Act No. 264/2025 Coll. on cybersecurity, in force since 1 November 2025, together with its implementing decrees, requires among other things detection and recording of cybersecurity events, vulnerability management and configuration management. Wazuh performs those specific functions. The organisational obligations, incident reporting to NÚKIB within the statutory windows, and evidencing that the measures actually work, are people and process rather than tooling. The Act is published in the Collection of Laws; guidance is issued by NÚKIB at nukib.gov.cz.

    For most mid-sized environments yes; for some, no. Wazuh covers collection, correlation, detection and inventory with no licence ceiling, so it pays off where data volume is high and budget is fixed. Commercial platforms offer broader ready-made integrations, more advanced behavioural analytics, and vendor support with a contractual response time. The deciding factor is who operates it: Wazuh moves cost from licence to people, and if you do not have those people the saving does not materialise.

    Yes, and it is more common than a greenfield build. We start with an assessment of the current state: what it collects, what is tuned, what the retention is, and how many alerts a day nobody reads. That produces a list of what needs finishing before a shift is worth switching on. If we find the platform only needs tuning and you can watch it yourselves, we will say so.

    Running Wazuh, or considering it?

    Tell us what state it is in. If it only needs tuning, we will say so.