Centralized Sysmon Configuration Management with Wazuh

Centralized Sysmon Configuration Management with Wazuh

December 24th 2025 / Ambassadors
By Hanif Kurniawan / Medium

This guide explains how to centrally manage and apply Sysmon configuration updates on Windows endpoints using the Wazuh Wodle Command, shared configuration, and PowerShell. The solution is designed to provide deterministic, hash-based Sysmon configuration management across Windows environments in an enterprise-ready and production-safe manner.

Read more
Understanding Wazuh 403 errors: When wazuh-states indexes are read-only

Understanding Wazuh 403 errors: When wazuh-states indexes are read-only

December 20th 2025 / Ambassadors
By Michael Muenz / Michael Muenz's Blog

In this article, I demonstrate a typical but often misinterpreted error in Wazuh + Wazuh Indexer (OpenSearch) :
Vulnerabilities and inventory data no longer function, logs show massive errors 403– even though authentication is correct.

Read more
Linux Kernel Monitoring with Wazuh

Linux Kernel Monitoring with Wazuh

December 19th 2025 / Ambassadors
By Marco Teixeira / Medium

This document presents a comprehensive security architecture centered on the Linux kernel, utilizing Wazuh as the primary SIEM/XDR platform.

Read more