概要
Wazuhは、monitor対象へendpoint agentを導入し、log、file change、software inventory、configuration情報などをcentral managerへ集約してthreat detectionとsecurity monitoringを行うOSS platformです。Wazuh IndexerとDashboardを組み合わせ、SIEM/XDR、File Integrity Monitoring、vulnerability detection、compliance確認などを一つの運用基盤へまとめます。
特徴と向いている用途
公式資料に基づく紹介・実機未検証 · 内容確認日:
endpoint agentからlog・file・inventory情報を収集する
agentがOS/application log、file integrity、software inventory、configuration情報を集め、manager側でruleやsecurity intelligenceと照合します。
SIEM/XDR・vulnerability・compliance viewを一元化する
alertやsecurity eventをIndexerへ保存し、Dashboardから脆弱software、FIM event、configuration assessment、compliance関連情報を横断して確認できます。
出典:[2]
複数endpointとcloud workloadのsecurity monitoringを中央化したい場合に
server、workstation、container/cloud workloadへagentを展開し、host security telemetryとalert運用を共通platformへ集約したい組織に向きます。
component構成とmajor version migrationを運用計画へ含める
agentだけで完結せずmanager/indexer/dashboardを含む設計が必要です。現行docsでは4.x managerから5.0へ直接upgradeできずfresh installとrestoreが必要とされるため、backupとmigration guideを事前に確認してください。
参考にした公式資料
- [1]wazuh/wazuh repository(2026-09-20)
- [2]Wazuh README(2026-09-20)
- [3]Wazuh GPLv2 license and OpenSSL exception(2026-09-20)
- [4]Wazuh documentation(2026-09-20)
- [5]Wazuh 4.x to 5.x migration guide(2026-09-20)
編集部からの補足
単一hostのsecurity scannerではなく、endpoint agentが収集したtelemetryをcentral managerで解析し、Indexer/Dashboardまで含めて運用するplatformです。現行repository docsでは4.x managerから5.0へin-place upgradeできずfresh install+restoreが必要と明記されているため、major upgradeではmigration guideを必ず確認してください。
3ステップで試す
- 1
公式installation guideを確認
server/indexer/dashboardとagentの構成、対応OS、必要resourceを確認します。
https://documentation.wazuh.com/current/installation-guide/index.html - 2
隔離VMへsingle-node構成を導入
最初はproduction endpointではなく検証用VMへmanager/indexer/dashboardを構築します。
Follow the single-node installation path in the official guide - 3
1台のtest agentを登録
自分で管理するtest endpointを1台だけ追加し、log、FIM、software inventory、vulnerability viewが流れることを確認します。
Enroll one test agent and verify it in the Wazuh Dashboard
成長
成長の推移 · 直近30日
16,937 Stars
推移データを蓄積中です。
開発アクティビティ
直近90日・週次
- Commit(直近30日)
- 948
- Open PR
- 194
- Issue登録
- 1,546
- Issue解決
- 1,362
- PR登録
- 805
- PRマージ
- 683
Issues
1,546 / 1,362
Pull Requests
805 / 683
メンテナンス状況
- Issue初回応答中央値
- 3.6時間
- Issue応答率
- 50% (25/50)
直近90日に外部から作成されたIssue(新しい順に最大100件)が対象です。OWNER・MEMBER・COLLABORATORによる最初のコメントを応答とし、全コメントを確認できないIssueは集計から除外します。中央値と応答率は週次更新です。
Built with
カテゴリとタグ
GitHubデータ
GitHubのデータGitHubの詳細データを見る
GitHub Topics
- security
- compliance
- log-analysis
- vulnerability-detection
- cybersecurity
- file-integrity-monitoring
- infosec
- malware-detection
- cloud-security
- container-security
- security-automation
- security-tools
- Stars
- 16,937
- Forks
- 2,490
- Watchers
- 231
- Open Issues
- 2,905
- Contributors
- 214
- 主要言語
- C++
- ライセンス
- GPL-2.0-only
- リポジトリ最終更新
- 2026/09/20
関連情報
関連記事を投稿するこのOSSの使い方や活用事例をMarkdownで投稿できます。管理者が承認した後に公開されます。
あわせて探訪
- Sherlock92,144 Stars
ユーザー名からSNS上のアカウント候補を横断検索するPython製OSINT CLI。
Python - Uptime Kuma91,570 Stars
HTTP/TCP/DNS/Ping等の監視、通知、status pageをまとめてself-hostするmonitoring tool。
JavaScript - Elasticsearch77,937 Stars
全文・ベクトル検索と分析を分散処理し、ログやメトリクスも扱う検索エンジン。
Java - Grafana76,812 Stars
複数ソースのメトリクス・ログ・トレースを可視化し、アラートへつなぐ基盤。
TypeScript - Prometheus66,130 Stars
label付き時系列metricをpull収集し、PromQL、rule、alert、service discoveryで監視する基盤。
Go
情報の誤りを報告
掲載内容に誤りや古い情報があればお知らせください。