← Blog From Wazuh

We started with Wazuh. Here is the floor we built above it.

Why a free, open detection agent was the right place to start, what a detection agent was never meant to do, and how a source-agnostic decision layer turns Wazuh — or whatever stack you already run — into qualified cases, explained verdicts and decisions, without an ingest meter.

If you run a lean internal SOC or a small MSSP in Europe, there is a fair chance Wazuh is already on the hosts you protect, and for good reason: the rules are open, the alerts are honest, the indexer is yours, and ingest costs nothing. That is where Seculogik started, and it is where the free edition still lives. It is also, to be clear from the first paragraph, not the only way in. Seculogik is the decision layer above whatever detection stack you already run. Wazuh is simply the one we grew up on.

The beachhead, not the foundation

Seculogik's free edition is Wazuh-only by design. It is a complete core SOC — alerts, cases, the analyst screens, the decision queue, SLA clocks, notifications, single sign-on and MFA, a tamper-evident audit trail — fed by your Wazuh manager and indexer and nothing else. It is not a trial. You can run it for as long as you like, and many teams should.

Starting there shaped the product more than a go-to-market choice usually does. Wazuh gave us an honest, high-volume, zero-cost alert stream and a customer base that would never accept a per-gigabyte meter for the privilege of reading its own logs. So we had to be good at the hard part — turning that stream into a small number of decisions a human can act on — rather than good at billing for it. A Wazuh alert arrives already understood: how serious it is, which host it came from, and therefore which client it belongs to. Its vulnerability findings flow straight into our Vulnerability Operations Centre. And the 72 MITRE-mapped detection packs we ship can be imported from a screen, so a fresh estate has real coverage on day one rather than a blank rule set.

Wazuh is where we started. It was never meant to be where the decisions get made.

What a detection agent was never meant to do

A rule fires on one event. A campaign is many events — across an EDR, an identity provider and a firewall — over days. A detection agent has alerts but no cases: no lifecycle, no assignee, no SLA, no record of why anyone decided anything. It has one flat alert stream, where an MSSP needs one case space per client with a wall between them that nobody can cross by accident. When a single rule fires eight thousand times in five minutes, it produces eight thousand rows and not one incident. Its response is a script, where a SOC needs a playbook that stops and waits for a person before it isolates a host. And a dashboard is not a report a risk committee can read.

None of that is a criticism of Wazuh. It is the shape of a detection layer, whichever one you run, and it is the reason a decision layer above it has to exist. That is what a Cyber Decision Center is: not a SIEM, not an EDR, not a replacement for your sensors or your log store, but the place where their output becomes a decision.

The floor above — and it is source-agnostic

Here is what Seculogik adds, in the order an alert meets it. The same alert is never counted twice. Known benign patterns are set aside before they reach an analyst. Hundreds of low-severity repeats collapse into one appropriately rated case — five hundred failed logons become one high-priority case, not five hundred rows — and nothing is lost if a component restarts mid-burst. Then the correlation engine, our crown jewel: nine independent strategies look at every alert from different angles — the entities involved, how far the attack has progressed, whether several sources agree, slow-burn risk, known attack storylines, attacker clustering — and vote on one verdict. Every case keeps a readable decision trace: which signals mattered, how the verdict was reached, and what would have changed it. Recognised storylines (phishing to account takeover, exploit to foothold, execution to ransomware) mean a case reads as a story, and its kill-chain position advances with the evidence, so the queue ranks what is genuinely furthest along.

Above that sits the Decision Center itself: a queue that says what to open next, SLA clocks, capacity-based auto-assignment, one case space per client with unattributed alerts held in quarantine rather than guessed, and white-label for MSSPs. SIROC, the AI analyst, lists its hypotheses and evidence before its verdict; that evidence is checked against the case's own alerts, and an unsupported verdict is downgraded in front of the analyst. Response workbooks pause for a person before anything destructive, such as isolating a host. The Vulnerability Operations Centre corroborates findings across scanners and runs a remediation lifecycle with due dates and a risk-acceptance register that expires. Reporting produces scorecards for NIST CSF, ISO 27001, GDPR, DORA and NIS2, and evidence packs that state their own methodology and coverage — every number carries its evidence, and a metric that cannot be computed says so.

None of that is Wazuh-specific. The floor sits above whatever you already run: open-source SIEM and data stacks such as Wazuh, OpenSearch, Elastic / ELK and ClickHouse; market platforms such as Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, SentinelOne, Cortex XDR, Fortinet, Okta and Entra ID; 23 vendor connectors, push webhooks, and passive tailing of the SIEM you have. If a source is not on the list, we build the connector — or you push events through the generic webhook and map them once in the universal data map. The Wazuh estate you started with can absorb Sentinel, CrowdStrike and Okta without a second platform, and a team that has never run Wazuh gets the same floor through its own connectors.

No ingest tax, still

The thing we were most careful not to break is the economics. Gartner puts it plainly: SIEM buyers have grown increasingly frustrated by SIEM cost bloat. Most SIEM and XDR vendors charge per gigabyte, per event or per asset for the privilege of putting your own logs in. At two hundred gigabytes a day, indicative public list rates in May 2026 put Microsoft Sentinel's ingest alone in the low-to-mid hundreds of thousands of dollars a year, and CrowdStrike's third-party ingest higher still. Seculogik does not meter your logs. Your log store stays yours — the Wazuh indexer, OpenSearch, Elastic, ClickHouse, whichever you run — and the platform sits above it on one self-hosted box, VPS or on-prem, no GPU required, installed in minutes. The licence is quoted per deployment and per year, across three editions and six add-ons. There is no per-GB, no per-endpoint and no per-tenant fee, so your line reads infrastructure plus operations, and an MSSP bills its clients without us billing its volume.

We will say the honest part too. Infrastructure plus operations still costs real money at scale; the win is the absence of a meter, not free. And for a Microsoft E5 shop, Sentinel's effective ingest can be very low — there we compete on sovereignty and the MSSP model, not raw price. Sovereignty, for us, is a switch you own rather than a slogan: AI runs on your box on a local open-licence model by default, you bring your own cloud key per task if you choose, and every cloud-bound call is recorded in a tamper-proof ledger you can audit.

Where to start

If you already run Wazuh, point the free edition at your manager and see the decision queue on your own alerts the same day — no licence, no meter, nothing sent anywhere. If you run something else, or you want to see what the correlation engine makes of a week of your alerts, request a demo: a thirty-minute session on your own telemetry, replayed in front of you. Either way, you keep the stack you have. We built the floor above it.