Guilgo Blog

Notes from my daily work with technology.

Wazuh 5: a production survival guide

Verifiable criteria to go live without the stack eating you

Verifiable criteria to take Wazuh 5 to production: fearless upgrades, signal vs noise, indexer performance, and a pilot with a clear stop rule.

Build a proactive SOC in a homelab: Kubernetes, Docker, Wazuh, Trivy and Telegram

Low-noise periodic checks: broken pods, high Wazuh alerts, CVEs in exposed images and Telegram reports, with deduplication and clear severity policy

Guide: proactive homelab SOC with k3s, Wazuh, Trivy (CVEs on exposed Docker images) and Telegram. Cron, low noise, dedupe and actionable alerts.

Auditing Kubernetes with Wazuh: API server audit logs to the SIEM step by step

Webhook, audit policy and rules to send Kubernetes audit logs to Wazuh and alert on resource create/delete

Step-by-step guide to audit Kubernetes with Wazuh: API server audit logs to the SIEM, webhook listener, audit policy and rules in local_rules.xml. Kubernetes security monitoring.