Wazuh Consulting

Security – SIEM & XDR

Do you need a SIEM that works reliably day in and day out? Through our Wazuh consulting services, we work with you to set up the platform so you can monitor your infrastructure, detect security incidents, and respond to threats in real time.

Does this sound familiar to you?

The audit is coming up

An auditor or an internal policy requires centralized security monitoring. We need a SIEM, but there’s no budget for Splunk or QRadar.

There is a lack of expertise

Decoders, rules, indexer sizing: Wazuh is powerful but complex. The first test ended with a flood of alerts that no one bothered to look at anymore.

The area is growing

New locations, more servers, more clients. What worked with 20 agents becomes slow, confusing, or crashes when scaled up to 500.

What Wazuh Can Do

Wazuh combines attack detection, file integrity, vulnerability scans, and configuration checks into a single platform.

Why NETWAYS?

We have been operating open-source infrastructures for over 30 years. Our consultants don’t just set up Wazuh—they also explain to your team how it works. This creates a SIEM that you can continue to develop on your own.

This is what Wazuh looks like in everyday life

Wazuh Web Interface

The dashboard consolidates all modules in one place: security events, vulnerabilities, configuration checks, and file integrity.

T

The “Configuration Assessment” feature regularly checks systems against predefined guidelines (e.g., CIS benchmarks) for hardening and security configuration weaknesses and reports which checks were passed or failed.

T

The “File Integrity Monitoring” feature monitors specified files and directories for changes (creation, modification, deletion) and reports when and by whom the contents, permissions, or attributes have been changed.

T
The “PCI DSS” feature maps detected events and alerts to the relevant requirements of the PCI DSS (Payment Card Industry Data Security Standard) and thus provides pre-generated compliance reports.

Wazuh Configuration Assessment

The Configuration Assessment regularly checks systems against predefined guidelines (e.g., CIS benchmarks) for hardening and security configuration weaknesses and reports which checks were passed or failed.

T

This row shows the details of a single failed test. On this system, root login via SSH is currently not disabled.

Here’s How Your Wazuh Consultation Works

We’ll be with you every step of the way, from planning to operation.

Step 1

Analysis & Concept

We look at your infrastructure and security requirements and plan together which systems should be monitored and which compliance requirements should be covered. From our experience with hundreds of projects, we know the pitfalls. This is how you avoid blind spots and false alarms that obscure real incidents.

!
Step 2

Setup & Integration

We roll out Wazuh agents and set up servers, rules, decoders and the dashboard precisely for your teams and systems. A well-thought-out design will save you from costly modifications down the road. From the very beginning, we've focused on a structure that grows along with your environment.

!
Step 3

Commissioning & alarming

During the first few weeks, it becomes clear which alarms are genuine alerts and which are just noise. We'll fine-tune the rules until Wazuh only flags items that someone needs to review, and we'll forward the alerts to the appropriate people.

!
Step 4

Support & Operations

On request, we can take over ongoing operations completely (outsourcing) or support your team with support and training. Updates, rule maintenance, and availability take up a lot of time internally. We keep your security platform running smoothly so you can focus on your core business.

Start small, make clear progress

Three ways to get started with Wazuh Consulting, each at a fixed price and with concrete results.

*If the appointments take place on site, the travel costs valid at the time the order is placed will also be charged.

Expertise on Wazuh

Want to dig deeper? You might find these blog posts about Wazuh interesting.

Questions & Answers

Frequently Asked Questions About Wazuh & Wazuh Consulting.

What is Wazuh?

2
3

Wazuh is an open-source security platform that combines SIEM and XDR. Agents on servers, clients, and VMs collect security data that is analyzed centrally for attack detection, vulnerability scans, configuration checks, and file integrity. You can read more about this in our article What is Wazuh?

How much does a Wazuh consultation cost at NETWAYS?

2
3

Wazuh itself is free. To get started, we offer three fixed-price packages: a review of your existing installation (€2,000), a strategy workshop (€4,000), or a proof of concept with real agents from your area (€8,000). We bill larger projects on a time-and-materials basis once we understand your requirements.

Wazuh is free, after all. Why do I need counseling?

2
3

The license is free, but operating the system isn't: sizing, deploying agents, configuring rules and decoders, updates, and filtering out false alarms. Without experience, this often takes months. With consulting support, the platform will be up and running faster, and your team will learn how to manage it on their own.

Can I run Wazuh on my own afterward?

2
3

Yes, that's the goal in most projects. We set up Wazuh in a way that makes it easy for your team to understand the configuration, and we explain rules, updates, and common error scenarios directly in your environment. If you need assistance later on, our support team will be happy to help.

Why am I getting so many alerts from Wazuh?

2
3

Wazuh's default rules are intentionally broad. Unless you configure Wazuh to match your environment, it will also report harmless events, such as scheduled maintenance or known services. The solution is rule tuning: adjust rules, define exceptions, and set appropriate alarm levels. That's exactly what we're looking at in the Wazuh Review.

Does Wazuh help with an ISO 27001 audit?

2
3

Wazuh provides much of the evidence that auditors want to see: centrally collected security events, logs of file changes, and regular checks against hardening policies. Wazuh alone does not make you eligible for certification, but it does make it much easier to document compliance. We'll clarify the specific requirements of your audit during the strategy workshop.

Wazuh or Elastic Security: Which Is a Better Fit?

2
3

Wazuh excels at monitoring endpoints: vulnerabilities, configuration, and file integrity. Elastic Security really shines when it comes to large volumes of data and flexible log analysis. Both can also be combined. We support both platforms and will recommend the one that's best suited to your environment.

What is the Wazuh Agent, and what does it do?

2
3

The Wazuh Agent is a lightweight piece of software that you install on servers, workstations, or virtual machines. It collects security-related data such as system logs, file changes, running processes, and installed software, and sends it to the Wazuh server. There, the data is analyzed to detect attacks, vulnerabilities, and configuration discrepancies. The agent runs on Linux, Windows, and macOS, and can also take action on its own when instructed by the server—for example, by blocking a suspicious IP address.

How do I install the Wazuh Agent?

2
3

To install the Wazuh Agent, first download the installation script or package for your operating system from the official Wazuh website or use the package manager of the respective system (e.g. `apt` for Ubuntu). After installation, configure the agent file (`ossec.conf`) to connect to the Wazuh server by specifying the server IP and other relevant parameters. Finally, start the agent with the command `sudo systemctl start wazuh-agent` and register it with the Wazuh server to activate the data transfer.

We look forward to your message






    captcha

    We look forward to your message






      captcha

      We look forward to your message






        captcha