Wazuh All-In-One Deployment
Great Platform for Quick Threat Detection
All-in-One Open-Source SIEM/XDR with Powerful Customization and Integrations
File integrity monitoring has strengthened our data protection and supports compliance needs
What is our primary use case?
Our organization is focusing on the integrity part for implementing Wazuh. We were checking solutions for File Integrity Monitoring systems that are available online. Wazuh caught my attention as a very cool solution for verifying file integrity. We decided to try Wazuh for focusing on the integrity part. While implementing it, our objective was achieved. We were able to monitor entire file integrity. Because our organization's business requires core concepts of integrity to be maintained, this was very important for us. Wazuh did this very well. We were not able to make it available to all endpoints. Instead, we tried it with servers. We changed our business requirements by storing all files that are processing into the server as a shared server and then we put File Integrity Monitoring and Wazuh in a single server. This worked out very well.
What is most valuable?
The dashboards in Wazuh are very cool and they provided whatever data is required.
I would give ten out of ten for the technical suggestion that I received from the documentation of Wazuh. The documentation provides everything that we are expecting. I have not tried any support from staff for Wazuh, but the documentation was very clear and I can give it ten out of ten.
What needs improvement?
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique ID to all employees. Then with the unique ID, if you search any unique ID in the dashboard itself, you can get the unique ID everywhere, including where the laptop has been logged in, when the logout happened, and what actions have been done for that unique ID. I expected the same in Wazuh, but whenever we want to check any monitoring activities for a specific person, we need to search for the endpoint and then get the endpoint details from our Active Directory or wherever we have the endpoint name stored in our resources, and then search for the endpoint to see the history for that specific endpoint only. This made a simple thing a bit complex. If we had a correlation of logs where I could just search one unique ID and then the unique ID pulls every system in a time-wise manner, that would be a great improvement I would suggest.
For how long have I used the solution?
I have been using Wazuh for around seven to eight months. In my previous organization, I was about to install and work with Wazuh. Since it is open source, I was fully configuring it for the organization.
What do I think about the scalability of the solution?
When we use a very good configuration laptop, it functions very smoothly. However, when we use low-end laptops for low-level employees, then the laptops become slow. This is because of the backend work the agent is collecting and processing, causing the laptop to slow down and the bandwidth to decrease.
Which solution did I use previously and why did I switch?
We had FortiNet and then we had McAfee.
What other advice do I have?
I have not worked very well with Wazuh's threat detection capabilities because we already had some solution in place. Our focus was to implement Wazuh for integrity only and File Integrity Monitoring only. I have worked earlier with Wazuh and ManageEngine. When I was working with Wazuh, there was no artificial intelligence introduced. My overall review rating for Wazuh is eight out of ten.