We started with Wazuh. Then we built the decision layer above it — and above everything else you run.
Wazuh is a superb free detection agent and a hard place to run a SOC from. Its alerts are honest, its rules are open, its ingest costs nothing — and then a person has to turn thousands of rows into a decision. Seculogik is what that person needed: a small number of qualified cases, a queue that says what to open next, and an AI analyst that shows its work. Wazuh stays exactly where it is. So does any other source you point at us.
The beachhead, not the foundation.
Our free edition is Wazuh-only by design: alerts, cases, the analyst screens, notifications and administration, fed by your Wazuh manager and indexer and nothing else. It is complete, it is self-hosted, and you can run it forever. It is also how most teams meet us.
Building on Wazuh first taught us what every SOC actually needs: an alert that arrives already rated, an asset that resolves to a client, vulnerability findings that land in an operations centre rather than a spreadsheet, and detection content that knows its own MITRE coverage. Those lessons became the platform — and the platform does not care where the alert came from.
Seculogik sits above whatever detection stack you already run. Open-source SIEM and data stacks: Wazuh, OpenSearch, Elastic / ELK, ClickHouse. Market platforms: Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, SentinelOne, Fortinet and more. And if your source is not on the list, we build the connector — or you push events through the generic webhook and map them once in the universal data map.
What Wazuh cannot do — and was never meant to.
- Correlate across sources and time. A rule fires on one event. A campaign is many events, across EDR, identity and firewall, over days. Nobody on your team has time to stitch them together by hand.
- Hold a case. Wazuh has alerts. It has no lifecycle, no SLA, no assignee, no decision trace, no record of what would have changed the verdict — nothing you can hand to an auditor.
- Separate clients. One manager, one flat alert stream. An MSSP needs one case space per client, enforced rather than promised.
- Absorb bursts. A single rule firing hundreds of times in a few minutes is hundreds of rows, not one incident — and the incident is what you need to see.
- Respond with approval. Active response is a script. A SOC needs a workflow that pauses for a person before isolating a host.
- Explain itself to a committee. A dashboard is not a report with a methodology, and your board and your regulator will ask for one.
None of this is a criticism of Wazuh. It is the gap between detection and decision — and it is the same gap on Elastic, Splunk or Sentinel.
Wazuh, then Seculogik. Side by side.
The right-hand column reads the same whatever feeds it. Swap Wazuh for Elastic, Sentinel or a custom connector and nothing on the right changes.
Seventy-two packs, named for the behaviour they catch.
Active Directory abuse. Cloud audit trails across AWS, Azure and Microsoft 365. Containers and hypervisors. Databases and email. Endpoint telemetry from CrowdStrike and SentinelOne. Identity providers such as Okta. Intrusion detection. Linux privilege and persistence. Network appliances from Fortinet, Palo Alto, Cisco, pfSense, Check Point and Sophos. Supply-chain compromise. Web servers and CMS. Windows Sysmon, PowerShell and the scheduled-task tricks attackers still rely on.
Every pack is mapped to MITRE ATT&CK, so the coverage matrix in the product shows what is actually deployed — not what a spreadsheet says. Independent research puts the average enterprise SIEM at 21% of ATT&CK techniques detected while the data already ingested could cover 90% (CardinalOps, 2025). Shipped content is how you close that gap on day one instead of rule by rule.
No ingest tax. Your log volume never drives your bill.
Most SIEM and XDR vendors charge per gigabyte, per event or per asset for the privilege of putting your own logs in. Seculogik ingests through Wazuh — or through the SIEM you already own — so volume is not a meter. Your cost is one box, the people who run it, and a licence quoted per deployment and per year.
Gartner puts it plainly: SIEM buyers “have grown increasingly frustrated by SIEM cost bloat”. Our pricing page sets editions and add-ons beside the public list prices of the usual suspects. Where ingest is already cheap for you — a Microsoft E5 estate, say — we compete on sovereignty and the MSSP model, not on raw price.
- No ingest tax. Your log volume doesn't drive your bill.
- Sovereign. Data and AI stay on your infrastructure, and cloud AI is a switch you own.
- MSSP-native. Multi-client and white-label from day one. You bill your clients; we don't bill your volume.
Point us at your manager. Keep everything.
Start free with the Wazuh-only edition, or book a thirty-minute session and we replay a week of your own alerts through the correlation engine — from Wazuh, or from whatever you run today.