Wazuh MCP Server: Query and Act on Your SIEM with Claude AI
Connect Wazuh to Claude with MCP. Ask about alerts and vulnerabilities in natural language and run actions like isolating servers or killing processes.
Technical articles on AI applied to IT systems and cybersecurity with Wazuh. Practical guides, real configurations and use cases without unnecessary theory.
20 articles published
Wazuh MCP Server: Query and Act on Your SIEM with Claude AI
Connect Wazuh to Claude with MCP. Ask about alerts and vulnerabilities in natural language and run actions like isolating servers or killing processes.
Monitor Agentless Devices in Wazuh with Syslog
Monitor routers, switches, NAS and agentless devices using rsyslog as a collector. Complete setup with templates, filters and Wazuh integration.
How to Create Custom Rules in Wazuh: Detect Access and Actions
Learn how to write custom Wazuh rules to detect folder access, specific users or Delete/Write actions. Practical examples with NAS logs and dynamic variables.
How to Configure Email Alerts in Wazuh with Postfix and Gmail/Microsoft
Set up email alerts in Wazuh with Postfix and Gmail/Microsoft 365. Covers ISO 27001 (A.5.24-A.5.26) and ENS (op.mon.1, op.mon.3) compliance.
How to Detect Software Installs and Uninstalls in Windows with Wazuh
Create Wazuh rules to detect software installs and uninstalls in Windows (Event IDs 11707 and 11724). ISO 27001 and compliance auditing included.
Case Study: Investigating an SSH Attack with Wazuh Discover and Threat Hunting
Investigate a real SSH brute-force attack step by step using Wazuh's Threat Hunting and Discover panels. A hands-on case study with remediation measures.
Wazuh Log Flow: Decoders, Rules and Alerts
Understand how Wazuh processes logs: pre-decoder, decoder, rules and alerts. Configure notifications by email, Discord or Slack.
Wazuh Vulnerability Detection: Meet ISO 27001 and ENS
Configure Wazuh's vulnerability detector to identify CVEs across your infrastructure. Meet ISO 27001 A.8.8 and ENS op.exp.6 with continuous scanning.
Monitor Digital Certificates with Wazuh FIM (ISO 27001 and ENS)
Hands-on lab: configure FIM to detect changes to .pfx, .p12 and .cer certificates. Meet ISO 27001 A.8.24 and ENS mp.com.3 with custom alerts.
Wazuh and VirusTotal Integration: Automated Malware Analysis
Set up Wazuh to automatically scan suspicious files against 70+ antivirus engines with the VirusTotal API. Step-by-step guide using FIM and EICAR.
How to Configure Agent Groups in Wazuh
Learn to organize your agents into groups (Windows, Linux, databases) and push centralized ossec.conf configurations to every agent in the group.
How to Install Wazuh with Docker Compose
Step-by-step guide to install Wazuh using Docker Compose. Deploy the full SIEM in minutes with containers: Indexer, Server and Dashboard up and running.
Install Wazuh Agent on Windows: Complete Guide 2026
How to install the Wazuh agent on Windows step by step: MSI download, install command, ossec.conf configuration, localfile and syscheck. Ready in 15 minutes.
How to Install the Wazuh Agent on Linux
Step-by-step guide to install and configure the Wazuh agent on Linux (Debian/Ubuntu). Install command, ossec.conf setup, localfile and restarting the service.
How to Install Wazuh on Linux (Ubuntu 24.04)
Learn how to install Wazuh on Ubuntu, Debian, CentOS and Rocky Linux. Step-by-step guide with the all-in-one method and separate component install.
What Is Wazuh and What Is It Used For: Open Source SIEM/XDR [2026]
What Wazuh is, what it's used for and how it protects your business: threat detection, compliance, log monitoring on Linux and Windows. Guide with real examples.
How to Monitor a Docker Server and Its Containers with Wazuh
Configure Wazuh to monitor the Docker host and its containers: Docker Listener, container logs, FIM, real alerts and suspicious docker exec detection.
Wazuh + Elastic Security: Complete SIEM Setup Guide
Build a complete SIEM by integrating Wazuh with Elastic Security. Step-by-step install of Elasticsearch, Kibana and Filebeat plus real-time alert dashboards.
How to Monitor Your Office 365 Tenant, Exchange & SharePoint Logs
Monitor your Office 365 tenant with Wazuh: ingest Exchange and SharePoint logs and build rules to detect foreign logins, brute force and phishing-driven breaches.
AI Threat Hunting in Wazuh: Installation Guide with Ollama
Integrate AI into Wazuh for threat hunting. Install Ollama with a local LLM, connect it to your Wazuh logs and query security events in natural language, on-prem.
Try another category or come back later