Deployed a full Security Operations Center with Wazuh SIEM + XDR, combined with comprehensive metrics monitoring for an IT enterprise with many servers.
An IT enterprise with many servers had no centralized monitoring system. Key issues:
Deployed Wazuh with 15 agents across 2 groups: centralized log collection, intrusion detection, vulnerability scanning, FIM, and compliance monitoring. Wazuh Indexer (OpenSearch 2.19.5) stores tens of thousands vulnerability records.
Deployed Zabbix 7.4 monitoring 14 hosts. Real-time dashboard for CPU, RAM, disk, network, services. Smart alert thresholds with auto-escalation.
Integrated Telegram Bot — real-time alerts with severity, CVE ID, description, remediation links.
Auto-update vulnerability database from NVD and CISA Known Exploited Vulnerabilities.