Building a Telegram-Based AI Troubleshooter for Wazuh SIEM

Building a Telegram-Based AI Troubleshooter for Wazuh SIEM

March 25th 2026 / Ambassadors
By Joel Yang / Medium

How I combined LangGraph, Ollama, and a locally hosted LLM to create an on-call diagnostic assistant that SSHes into my Wazuh fleet and answers questions in plain English — from my phone.

Read more
Wazuh4j – Visualizing Wazuh Rule Sets with Neo4J

Wazuh4j – Visualizing Wazuh Rule Sets with Neo4J

March 24th 2026 / External Media
By DigiFors

Wazuh rule sets can be a real jungle – and nobody wants to blindly hack their way through it. That’s why we visualized the whole thing with Neo4j…

Read more
Blocking Brute-Force Attack

Blocking Brute-Force Attack

March 24th 2026 / Ambassadors
By Hafiz Javid / LinkedIn

Blocking the attacker’s IP is good. Locking the targeted account at the same time is better because IPs can change, accounts can’t escape a lock.
This tutorial shows how to configure two Wazuh active responses that fire simultaneously on a single brute-force detection: firewall-drop + disable-account.

Read more
Automating Threat Intelligence Alerts in Wazuh: A Practical Homelab Pipeline

Automating Threat Intelligence Alerts in Wazuh: A Practical Homelab Pipeline

March 23rd 2026 / Ambassadors
By Federico Fantini / Federico Fantini's Blog

A complete, reproducible Wazuh homelab setup that automates TI feed ingestion, normalizes & deduplicates indicators, updates Wazuh CDB lists, correlates with Sysmon/Suricata telemetry, and sends alerts to Discord.

Read more
Wazuh Indexer and needrestart on Ubuntu 24.04 Server: Understanding and Fixing the Java False Positive

Wazuh Indexer and needrestart on Ubuntu 24.04 Server: Understanding and Fixing the Java False Positive

March 21st 2026 / Ambassadors
By Stephan Wenderlich / Gray-Hat Security Consulting Blog

German – If you run the Wazuh Indexer on a hardened Ubuntu 24.04 server, you encounter an apparent issue after every apt upgrade: needrestart reports that the Wazuh Indexer needs to be restarted, even though the service is running stably and the installed updates have nothing to do with the indexer.

Read more