Wazuh is an open-source security monitoring platform used for log analysis, endpoint telemetry, file integrity monitoring, vulnerability detection, threat detection, and compliance monitoring. Many teams use Wazuh as part of a SIEM or security operations program.
Wazuh is popular because it gives security teams a flexible way to collect and analyze security signals without relying entirely on closed vendor tooling. It started as a fork of OSSEC (a host-based intrusion detection system) and grew into a broader platform that pairs agent-based endpoint telemetry with a central analysis engine and a search/visualization layer. Because it is free to run and self-hosted, it is a common starting point for teams that want detection and compliance coverage before they can justify a commercial SIEM.
The architecture: agents, manager, and indexer
Understanding Wazuh means understanding its three main pieces:
- Wazuh agents run on the endpoints and servers you want to monitor (Linux, Windows, macOS, and cloud instances). They collect logs, watch files, inventory installed packages, and run local security checks, then ship that data to the manager.
- The Wazuh manager (server) receives agent data, decodes and normalizes it, and runs it through a rule and decoder engine. This is where raw events become security decisions: a login failure log line becomes an “authentication failure” event, and repeated failures escalate into a brute-force alert.
- The Wazuh indexer and dashboard store the enriched events and make them searchable. Analysts query, build dashboards, and pivot across hosts from here. In practice this layer is an OpenSearch-based store with a Kibana-style UI.
Agentless collection is also possible for devices you cannot install software on (network gear, some cloud APIs), typically via syslog or API polling.
How detection actually works
Wazuh detection is rule-driven. Incoming events are matched against decoders (which extract fields from raw log formats) and rules (which assign a severity level and description when conditions match). Rules can chain together, so a single event might be benign but a sequence within a time window fires a higher-severity alert. This is how Wazuh catches patterns like repeated SSH failures followed by a success, or a privilege escalation right after a new process spawns.
Two capabilities are worth calling out because teams rely on them heavily:
- File Integrity Monitoring (FIM) watches specific directories and files for creation, modification, and deletion. This is directly useful for detecting tampering and is an explicit requirement in several compliance frameworks.
- Security Configuration Assessment (SCA) runs policy checks against a host to confirm it matches a hardening baseline, such as CIS benchmarks. This gives you host-level configuration posture, not just event detection.
What Wazuh does
Wazuh can help teams collect logs, monitor endpoints, detect suspicious activity, watch file changes, check compliance policies, and identify known vulnerabilities. It is often deployed with agents on endpoints and servers, with a central manager that collects and analyzes events.
Common use cases include:
- Endpoint monitoring
- File integrity monitoring
- Log analysis
- Vulnerability detection
- Compliance reporting
- Threat detection rules
- Integration with security dashboards and data stores
Wazuh and cloud security
Wazuh can collect signals from cloud workloads and infrastructure, but cloud security requires more than logs. Cloud environments also need resource inventory, IAM analysis, network exposure, Kubernetes context, cloud API activity, data access visibility, and attack path analysis.
That is why Wazuh is often complementary to a cloud security platform rather than a full replacement for one. Wazuh sees a host from the inside: what processes ran, what files changed, which log lines appeared. A cloud security platform sees the same workload from the outside and from the control plane: how it is exposed to the internet, what IAM role it can assume, which security groups surround it, and whether it can reach sensitive data. Both views are valuable, and incidents are easiest to understand when you have both.
Consider a compromised EC2 instance. Wazuh can tell you a suspicious binary executed and a config file was modified. It cannot easily tell you that the instance’s attached role has s3:* on a bucket holding customer PII, that the instance sits in a public subnet, and that the same role is reused by twelve other workloads. That blast-radius context comes from cloud posture and identity analysis. For more on that idea, see blast radius in cloud security.
Wazuh and compliance
A large part of Wazuh adoption is compliance. FIM, SCA, log retention, and audit-friendly reporting map to controls in frameworks like PCI DSS, HIPAA, and NIST. Wazuh ships rule tagging that references these frameworks, so an event can be labeled with the control it helps satisfy, and dashboards can filter by framework. This is helpful for continuous monitoring evidence, but note that Wazuh covers the host and log side of these controls. Cloud-control evidence, identity least-privilege proof, and posture history still need to come from your cloud tooling. For the broader picture, see what is cloud compliance.
Wazuh vs CNAPP
Wazuh is a security monitoring and detection platform. CNAPP is a cloud-native application protection platform that combines cloud posture, workload security, identity risk, code security, vulnerability prioritization, and compliance.
The overlap is strongest around detection and monitoring. The difference is cloud context: a CNAPP is expected to understand cloud assets, permissions, relationships, exposure, and business impact.
How Wazuh fits with Cloudanix
Cloudanix can complement Wazuh-style security operations by adding cloud graph context, CNAPP controls, JIT access, CDR, attack path analysis, and evidence reporting. Teams can use Wazuh for endpoint and log monitoring while using Cloudanix to understand cloud-native risk and remediation priority.
A practical division of labor looks like this:
- Wazuh handles host-level detection, FIM, SCA, and log aggregation across your fleet.
- Cloudanix maps the cloud around those hosts: the unified asset graph shows how an instance connects to identities, networks, data stores, and Kubernetes workloads, so a host alert can be scored by real exposure and reachability.
- Cloudanix’s CIEM and JIT access reduce the standing permissions that make a compromised host dangerous in the first place, shrinking what any single Wazuh alert can escalate into.
- For regulated teams, Cloudanix maps findings across 15+ frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, HITRUST, APRA, DPDPA, and more) with audit-evidence export, which complements the host-control evidence Wazuh produces.
The combination matters most for the regulated FSI and healthcare teams and cloud-native mid-market orgs that need both deep host telemetry and cloud-context prioritization without stitching everything together by hand.
Practical best practices
- Tune before you trust. Out-of-the-box rules generate noise. Baseline normal activity per environment and suppress or adjust rules that fire constantly, or analysts will start ignoring the dashboard.
- Scope FIM carefully. Monitoring every file path is expensive and noisy. Watch the directories that matter (binaries, config, credential paths) and exclude high-churn locations.
- Retain logs for your compliance window. Confirm indexer retention matches the audit period your frameworks require, and archive cold data cheaply.
- Correlate, don’t just collect. A pile of events is not detection. Invest in rule chaining and in pushing enriched alerts to a place where they get triaged.
- Pair host telemetry with cloud context. Route Wazuh alerts into a workflow that can answer “how exposed is this workload and what can it reach,” so responders prioritize the incidents that actually carry blast radius.
Related pages include CDR, CNAPP+, CIEM, and Container Security.
People also read
- What Is CWPP?
- What Is Falco Runtime Security?
- What Is Cloud Detection and Response (CDR)?
- What Is Anomaly Detection?
- What Is Cloud Compliance?
Frequently asked questions
Is Wazuh open source?
Yes. Wazuh is an open-source security monitoring platform.
Is Wazuh a SIEM?
Wazuh can be used as part of a SIEM-like monitoring stack, especially for log analysis, detection, and compliance use cases.
Does Wazuh replace CNAPP?
No. Wazuh provides useful monitoring capabilities, but CNAPP covers broader cloud posture, identity, workload, code, access, and attack-path workflows.
Why would a team use Wazuh with Cloudanix?
Wazuh can provide endpoint and log telemetry, while Cloudanix adds cloud-native graph context, JIT access, CNAPP controls, and compliance evidence.