• nbailey@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Wazuh is a neat tool, but it’s really just good old OSSEC bolted into Elasticsearch with some custom plugins and middleware. You can get nearly the same result by just shipping logs from ossec and osquery with a lot less complexity.

      • nbailey@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        Not for a new selfhoster, no. It’s fairly complex and has lots of moving pieces. Start with a simple syslog server before going way into the deep end.