From endpoint to investigation
- 01Linux workloadAgent collects host activity
- 02Wazuh manager + indexerProcess, correlate, and store events
- 03Threat Hunting dashboardInspect events and ATT&CK mappings
Proxmox host · Ubuntu Server 24.04 LTS
4 vCPU / 8 GB RAM / 80 GB disk
The first 24 hours of signal
- Total events
- 57
- Authentication successes
- 5
- Critical alerts
- 0
Default rules mapped activity to Sudo and Sudo Caching and Valid Accounts.
Recorded in the August 1, 2026 writeup.
Historical results, not a live feed.
Two bugs. Two useful habits.
- Check the downloaded file.
A version placeholder returned an XML error instead of the installer.
- Read the component’s own log.
The agent was connected. The dashboard needed a refresh.
The writeup includes the commands, symptoms, and reasoning.
Standing up a SIEM
from nothing.
A single-node Wazuh deployment, from storage decisions on an unfamiliar hypervisor to real agent logs and ATT&CK mapping.
- My work
- Deployment, troubleshooting, validation
- Stack
- Proxmox · Ubuntu · Wazuh
- Outcome
- Live log ingestion validated
