Wazuh, one picture of the host, the alert and on-call
Opselis
Agents, FIM, SCA and MITRE in one console. An alert with an owner, not another email nobody closes. The playbook has a threshold, a ticket and a date when the failed check is closed.
A SIEM without operations is a log warehouse. Wazuh makes sense when the agent sits on the host, rules match the stack and on-call knows what to do with an alert at a given level. Overview shows agents, the last 24 hours and modules: FIM, SCA, vulnerabilities, MITRE, compliance.
We deploy agents where production and data live: the store, the gateway, the database, the jump host. FIM on configuration files and store directories. SCA against CIS, with a backlog of failed checks and a change window. MITRE correlation says whether this is noise, or a tactic that needs escalation.
An alert without an owner comes back. That is why every playbook has: who looks, what threshold, what trail stays in the ticket. PCI DSS and GDPR in the dashboard are evidence of control, provided a failed check has a close date.
Wazuh does not replace a vulnerability scan or the edge. OpenVAS feeds gaps. Cloudflare holds exposure. Wazuh composes signal from host and application so on-call sees one incident, not five consoles.