awesome-foss / awesome-sysadmin

A curated list of amazingly awesome open-source sysadmin resources.
Other
25.13k stars 1.44k forks source link

Add Wazuh to monitoring section (No other relavant section for SIEMs) #540

Closed natereprogle closed 5 months ago

natereprogle commented 11 months ago

Thank you for taking the time to work on a PR for Awesome-Sysadmin!

To ensure your PR is dealt with swiftly please check the following:


Please take some time to answer the following questions as best you can:

Wazuh is a awesome open source SIEM for everyone. It's easier to deploy than an ELK stack and is entirely free unless you decide you want to use their cloud.

I have not, however I am installing it now and wanted to post it here as well.

Personal

I will be using 8 devices (2 Linux hosts, 1 Windows host, 5 LXCs)

No licensing, used by many big name clients.

nodiscc commented 8 months ago

I have not, however I am installing it now and wanted to post it here as well.

Any other comments about your use case, things you've found excellent, limitations you've encountered... ? None for now

How did it go? Are you still running it? Any new insights on pros/cons?

natereprogle commented 8 months ago

Install went well, it was pretty straight forward to set up. I am not still running it, however, due to it requiring so many resources. I had those resources available, but didn’t want to waste them all on Wazuh, so after messing with it for a couple weeks I removed it. I will say it does require quite a bit of configuration to get it exactly how you want, but out of the box it works well already.

One thing to note is it does not support storing data on an external source such as a database without building it from source yourself and enabling some flags.