Wazuh 4.14 Documentation - SIEM/XDR Platform Guide

Wazuh 4.14 Documentation - SIEM/XDR Platform Guide

Wazuh is an open-source security platform that combines SIEM and XDR capabilities into a unified solution. It delivers threat detection, integrity monitoring, vulnerability analysis, and regulatory compliance across infrastructure of any scale. This documentation covers Wazuh version 4.14 and is intended for security engineers and system administrators.

About Wazuh

Wazuh provides a single platform for protecting endpoints, servers, containerized environments, and cloud resources. The platform offers the following core capabilities:

  • Threat detection - security event analysis through rules and correlation
  • File integrity monitoring - tracking changes to critical files and registry entries
  • Vulnerability detection - scanning systems for known CVEs
  • Configuration assessment - verification against CIS benchmarks and security policies
  • Incident response - automated actions triggered by detected threats
  • Compliance support - PCI DSS, GDPR, HIPAA, NIST 800-53

Documentation Sections

Getting Started

  • Wazuh Architecture - platform components, data flows, communication protocols, and deployment models
  • Wazuh Components - agent, server, indexer, and dashboard in detail
  • Use Cases - practical security tasks addressed by Wazuh

Installation

Platform Capabilities

Infrastructure

Cloud Security

  • AWS - CloudTrail, GuardDuty, VPC Flow Logs monitoring
  • Azure - Azure Activity Log and Microsoft Entra ID integration
  • GCP - Cloud Audit Logs and Security Command Center
  • Office 365 - Microsoft 365 event auditing
  • GitHub - repository activity monitoring

Compliance

  • PCI DSS - Payment Card Industry Data Security Standard
  • GDPR - General Data Protection Regulation
  • HIPAA - Health Insurance Portability and Accountability Act
  • NIST 800-53 - federal information system security controls
  • TSC - Trust Services Criteria

Deployment

Operations

Rules and Decoders

Integrations

Development

PoC and Lab Scenarios

Frequently asked questions

What is Wazuh?
Wazuh is an open-source security platform that unifies SIEM and XDR: threat detection, file integrity monitoring, vulnerability analysis, and regulatory compliance. This documentation covers version 4.14.
What are the components of Wazuh?
An agent, a server, an indexer (based on OpenSearch), and a web dashboard.
What does Wazuh protect?
Endpoints, servers, containerized environments, and cloud resources.
Which compliance standards does Wazuh support?
PCI DSS, GDPR, HIPAA, and NIST 800-53.
What are the core capabilities?
Rule- and correlation-based threat detection, file integrity monitoring, CVE vulnerability detection, CIS configuration assessment, and automated incident response.
How do I deploy Wazuh with OpenNix?
Wazuh deploys on Yandex Cloud and VK Cloud; pfSense can forward logs to Wazuh for security monitoring via the Wazuh Agent.
Reviewed by OpenNix LLC · Last updated on