Homelab Part 6: Wazuh SIEM Foundation

In Part 5, I added Kali and Metasploitable. In this part, I add the first visibility layer: Wazuh as the lab SIEM. The goal is to centralize security telemetry without trying to monitor everything at once. I start with the Wazuh server, a Docker host agent, Docker event collection, and pfSense syslog forwarding. What I Built Wazuh VM: 10.10.10.99 Segment: SIEM / VLAN 10 RAM: 8 GB CPU: 4 vCPU Disk: 128 GB Agent target: Docker host at 10.10.30.100 Syslog source: pfSense ‹ › ...

2026-05-28 · 4 min · plumy

Homelab Part 4: Docker Host, Portainer, and Macvlan

In Part 3, I created the VLAN structure. In this part, I build the container platform inside the CONTAINER VLAN. The goal is not only to run Docker. I want important containers to have real lab IP addresses. That way, pfSense rules and Wazuh events can point to the real service, not only to the Docker host. What I Built VM name: prod-docker VM ID: 103 OS: Ubuntu Server 24.04 VLAN: 30 / CONTAINER Host IP: 10.10.30.100 Docker UI: Portainer CE Macvlan net: 10.10.30.0/26 n8n IP: 10.10.30.10 ‹ › ...

2026-05-24 · 4 min · plumy