Cloudanix Joins AWS ISV Accelerate Program

What Is Wazuh?

Wazuh is an open-source security monitoring platform for log analysis, endpoint telemetry, file integrity monitoring, vulnerability detection, and compliance.

Wazuh is an open-source security monitoring platform used for log analysis, endpoint telemetry, file integrity monitoring, vulnerability detection, threat detection, and compliance monitoring. Many teams use Wazuh as part of a SIEM or security operations program.

Wazuh is popular because it gives security teams a flexible way to collect and analyze security signals without relying entirely on closed vendor tooling. It started as a fork of OSSEC (a host-based intrusion detection system) and grew into a broader platform that pairs agent-based endpoint telemetry with a central analysis engine and a search/visualization layer. Because it is free to run and self-hosted, it is a common starting point for teams that want detection and compliance coverage before they can justify a commercial SIEM.

The architecture: agents, manager, and indexer

Understanding Wazuh means understanding its three main pieces:

  • Wazuh agents run on the endpoints and servers you want to monitor (Linux, Windows, macOS, and cloud instances). They collect logs, watch files, inventory installed packages, and run local security checks, then ship that data to the manager.
  • The Wazuh manager (server) receives agent data, decodes and normalizes it, and runs it through a rule and decoder engine. This is where raw events become security decisions: a login failure log line becomes an “authentication failure” event, and repeated failures escalate into a brute-force alert.
  • The Wazuh indexer and dashboard store the enriched events and make them searchable. Analysts query, build dashboards, and pivot across hosts from here. In practice this layer is an OpenSearch-based store with a Kibana-style UI.

Agentless collection is also possible for devices you cannot install software on (network gear, some cloud APIs), typically via syslog or API polling.

How detection actually works

Wazuh detection is rule-driven. Incoming events are matched against decoders (which extract fields from raw log formats) and rules (which assign a severity level and description when conditions match). Rules can chain together, so a single event might be benign but a sequence within a time window fires a higher-severity alert. This is how Wazuh catches patterns like repeated SSH failures followed by a success, or a privilege escalation right after a new process spawns.

Two capabilities are worth calling out because teams rely on them heavily:

  • File Integrity Monitoring (FIM) watches specific directories and files for creation, modification, and deletion. This is directly useful for detecting tampering and is an explicit requirement in several compliance frameworks.
  • Security Configuration Assessment (SCA) runs policy checks against a host to confirm it matches a hardening baseline, such as CIS benchmarks. This gives you host-level configuration posture, not just event detection.

What Wazuh does

Wazuh can help teams collect logs, monitor endpoints, detect suspicious activity, watch file changes, check compliance policies, and identify known vulnerabilities. It is often deployed with agents on endpoints and servers, with a central manager that collects and analyzes events.

Common use cases include:

  • Endpoint monitoring
  • File integrity monitoring
  • Log analysis
  • Vulnerability detection
  • Compliance reporting
  • Threat detection rules
  • Integration with security dashboards and data stores

Wazuh and cloud security

Wazuh can collect signals from cloud workloads and infrastructure, but cloud security requires more than logs. Cloud environments also need resource inventory, IAM analysis, network exposure, Kubernetes context, cloud API activity, data access visibility, and attack path analysis.

That is why Wazuh is often complementary to a cloud security platform rather than a full replacement for one. Wazuh sees a host from the inside: what processes ran, what files changed, which log lines appeared. A cloud security platform sees the same workload from the outside and from the control plane: how it is exposed to the internet, what IAM role it can assume, which security groups surround it, and whether it can reach sensitive data. Both views are valuable, and incidents are easiest to understand when you have both.

Consider a compromised EC2 instance. Wazuh can tell you a suspicious binary executed and a config file was modified. It cannot easily tell you that the instance’s attached role has s3:* on a bucket holding customer PII, that the instance sits in a public subnet, and that the same role is reused by twelve other workloads. That blast-radius context comes from cloud posture and identity analysis. For more on that idea, see blast radius in cloud security.

Wazuh and compliance

A large part of Wazuh adoption is compliance. FIM, SCA, log retention, and audit-friendly reporting map to controls in frameworks like PCI DSS, HIPAA, and NIST. Wazuh ships rule tagging that references these frameworks, so an event can be labeled with the control it helps satisfy, and dashboards can filter by framework. This is helpful for continuous monitoring evidence, but note that Wazuh covers the host and log side of these controls. Cloud-control evidence, identity least-privilege proof, and posture history still need to come from your cloud tooling. For the broader picture, see what is cloud compliance.

Wazuh vs CNAPP

Wazuh is a security monitoring and detection platform. CNAPP is a cloud-native application protection platform that combines cloud posture, workload security, identity risk, code security, vulnerability prioritization, and compliance.

The overlap is strongest around detection and monitoring. The difference is cloud context: a CNAPP is expected to understand cloud assets, permissions, relationships, exposure, and business impact.

How Wazuh fits with Cloudanix

Cloudanix can complement Wazuh-style security operations by adding cloud graph context, CNAPP controls, JIT access, CDR, attack path analysis, and evidence reporting. Teams can use Wazuh for endpoint and log monitoring while using Cloudanix to understand cloud-native risk and remediation priority.

A practical division of labor looks like this:

  • Wazuh handles host-level detection, FIM, SCA, and log aggregation across your fleet.
  • Cloudanix maps the cloud around those hosts: the unified asset graph shows how an instance connects to identities, networks, data stores, and Kubernetes workloads, so a host alert can be scored by real exposure and reachability.
  • Cloudanix’s CIEM and JIT access reduce the standing permissions that make a compromised host dangerous in the first place, shrinking what any single Wazuh alert can escalate into.
  • For regulated teams, Cloudanix maps findings across 15+ frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, HITRUST, APRA, DPDPA, and more) with audit-evidence export, which complements the host-control evidence Wazuh produces.

The combination matters most for the regulated FSI and healthcare teams and cloud-native mid-market orgs that need both deep host telemetry and cloud-context prioritization without stitching everything together by hand.

Practical best practices

  • Tune before you trust. Out-of-the-box rules generate noise. Baseline normal activity per environment and suppress or adjust rules that fire constantly, or analysts will start ignoring the dashboard.
  • Scope FIM carefully. Monitoring every file path is expensive and noisy. Watch the directories that matter (binaries, config, credential paths) and exclude high-churn locations.
  • Retain logs for your compliance window. Confirm indexer retention matches the audit period your frameworks require, and archive cold data cheaply.
  • Correlate, don’t just collect. A pile of events is not detection. Invest in rule chaining and in pushing enriched alerts to a place where they get triaged.
  • Pair host telemetry with cloud context. Route Wazuh alerts into a workflow that can answer “how exposed is this workload and what can it reach,” so responders prioritize the incidents that actually carry blast radius.

Related pages include CDR, CNAPP+, CIEM, and Container Security.

People also read

Frequently asked questions

Is Wazuh open source?

Yes. Wazuh is an open-source security monitoring platform.

Is Wazuh a SIEM?

Wazuh can be used as part of a SIEM-like monitoring stack, especially for log analysis, detection, and compliance use cases.

Does Wazuh replace CNAPP?

No. Wazuh provides useful monitoring capabilities, but CNAPP covers broader cloud posture, identity, workload, code, access, and attack-path workflows.

Why would a team use Wazuh with Cloudanix?

Wazuh can provide endpoint and log telemetry, while Cloudanix adds cloud-native graph context, JIT access, CNAPP controls, and compliance evidence.

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo