OSS探訪

Wazuh — endpoint telemetryを集約してSIEM/XDR・FIM・vulnerability detectionを行う

スコアの見方

OSS規模スコアはStars・Watchers・Forks・Contributorsを対数圧縮して重み付けした現在の規模指標(上限なし)です。発掘スコアは現在のOSS規模スコアから発掘時点のOSS規模スコアを引いた値、更新ペースは直近30日Commit数、成長モメンタムは直近の観測期間におけるOSS規模スコア差、OSS健全度は取得できた更新状況・Community Health・Releaseの0〜100評価です。

Stars
16,937
主要言語
C++
ライセンス
GPL-2.0-only
リポジトリ最終更新
2026/09/20

概要

Wazuhは、monitor対象へendpoint agentを導入し、log、file change、software inventory、configuration情報などをcentral managerへ集約してthreat detectionとsecurity monitoringを行うOSS platformです。Wazuh IndexerとDashboardを組み合わせ、SIEM/XDR、File Integrity Monitoring、vulnerability detection、compliance確認などを一つの運用基盤へまとめます。

特徴と向いている用途

公式資料に基づく紹介・実機未検証 · 内容確認日:

endpoint agentからlog・file・inventory情報を収集する

agentがOS/application log、file integrity、software inventory、configuration情報を集め、manager側でruleやsecurity intelligenceと照合します。

出典:[2][4]

SIEM/XDR・vulnerability・compliance viewを一元化する

alertやsecurity eventをIndexerへ保存し、Dashboardから脆弱software、FIM event、configuration assessment、compliance関連情報を横断して確認できます。

出典:[2]

複数endpointとcloud workloadのsecurity monitoringを中央化したい場合に

server、workstation、container/cloud workloadへagentを展開し、host security telemetryとalert運用を共通platformへ集約したい組織に向きます。

出典:[2][4]

component構成とmajor version migrationを運用計画へ含める

agentだけで完結せずmanager/indexer/dashboardを含む設計が必要です。現行docsでは4.x managerから5.0へ直接upgradeできずfresh installとrestoreが必要とされるため、backupとmigration guideを事前に確認してください。

出典:[2][5]

参考にした公式資料

  1. [1]wazuh/wazuh repository(2026-09-20)
  2. [2]Wazuh README(2026-09-20)
  3. [3]Wazuh GPLv2 license and OpenSSL exception(2026-09-20)
  4. [4]Wazuh documentation(2026-09-20)
  5. [5]Wazuh 4.x to 5.x migration guide(2026-09-20)
編集部からの補足

単一hostのsecurity scannerではなく、endpoint agentが収集したtelemetryをcentral managerで解析し、Indexer/Dashboardまで含めて運用するplatformです。現行repository docsでは4.x managerから5.0へin-place upgradeできずfresh install+restoreが必要と明記されているため、major upgradeではmigration guideを必ず確認してください。

3ステップで試す

  1. 1

    公式installation guideを確認

    server/indexer/dashboardとagentの構成、対応OS、必要resourceを確認します。

    https://documentation.wazuh.com/current/installation-guide/index.html
  2. 2

    隔離VMへsingle-node構成を導入

    最初はproduction endpointではなく検証用VMへmanager/indexer/dashboardを構築します。

    Follow the single-node installation path in the official guide
  3. 3

    1台のtest agentを登録

    自分で管理するtest endpointを1台だけ追加し、log、FIM、software inventory、vulnerability viewが流れることを確認します。

    Enroll one test agent and verify it in the Wazuh Dashboard
公式READMEで確認

成長

成長の推移 · 直近30日

16,937 Stars

推移データを蓄積中です。

開発アクティビティ

直近90日・週次

Commit(直近30日)
948
Open PR
194
Issue登録
1,546
Issue解決
1,362
PR登録
805
PRマージ
683

Issues

1,546 / 1,362

6月23日9月20日
Issue登録Issue解決

Pull Requests

805 / 683

6月23日9月20日
PR登録PRマージ

メンテナンス状況

Issue初回応答中央値
3.6時間
Issue応答率
50% (25/50)

直近90日に外部から作成されたIssue(新しい順に最大100件)が対象です。OWNER・MEMBER・COLLABORATORによる最初のコメントを応答とし、全コメントを確認できないIssueは集計から除外します。中央値と応答率は週次更新です。

Built with

カテゴリとタグ

GitHubデータ

GitHubのデータGitHubの詳細データを見る

GitHub Topics

  • security
  • compliance
  • log-analysis
  • vulnerability-detection
  • cybersecurity
  • file-integrity-monitoring
  • infosec
  • malware-detection
  • cloud-security
  • container-security
  • security-automation
  • security-tools
Stars
16,937
Forks
2,490
Watchers
231
Open Issues
2,905
Contributors
214
主要言語
C++
ライセンス
GPL-2.0-only
リポジトリ最終更新
2026/09/20

このOSSの使い方や活用事例をMarkdownで投稿できます。管理者が承認した後に公開されます。

情報の誤りを報告

掲載内容に誤りや古い情報があればお知らせください。