Security monitoring stack
wazuh 4.14 · suricata 6.0 · graylog 7.1 · 8 agents · 3-node proxmox
Wazuh as the SIEM, Suricata feeding it, Graylog as a syslog tier for what can’t run an agent. The role boundaries are written down so the two never overlap.
The writeup covers what you’d need to rebuild it: verification you can re-run packet to alert, the gotchas that cost real time, and an honest account of a sensor that captured nothing for six months because a quiet feed and a blind feed look identical.