Engineer builds free SIEM with Wazuh and Kibana to detect brute-force attacks in real time
A systems engineer managing infrastructure across 25 corporate sites built a fully functional, zero-cost SIEM using open-source tools Wazuh and Kibana, running on Docker. The project was motivated by a common industry problem: authentication logs are generated constantly by servers and firewalls but rarely monitored, leaving suspicious activity undetected. Commercial SIEM licenses are often unaffordable for small and medium businesses, making open-source alternatives a practical necessity. The setup consists of three Wazuh components — Indexer, Manager, and Dashboard — plus a Wazuh Agent installed on each monitored endpoint, all deployed via Docker Compose. The engineer documented real configuration challenges, including rsyslog and ossec.conf issues, that are largely absent from official documentation, and demonstrated live brute-force attack detection in a simulated lab environment.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in