Homelab Part 6: Wazuh SIEM Foundation
In Part 5, I added Kali and Metasploitable. In this part, I add the first visibility layer: Wazuh as the lab SIEM. The goal is to centralize security telemetry without trying to monitor everything at once. I start with the Wazuh server, a Docker host agent, Docker event collection, and pfSense syslog forwarding. What I Built Wazuh VM: 10.10.10.99 Segment: SIEM / VLAN 10 RAM: 8 GB CPU: 4 vCPU Disk: 128 GB Agent target: Docker host at 10.10.30.100 Syslog source: pfSense ‹ › ...