Wazuh + AI

Wazuh + AI Security Operations

Wazuh is a powerful detection platform. Its output — thousands of events per day — requires triage that rules alone cannot deliver. ARIA adds an AI layer: deterministic enrichment, LLM investigation, and independent verification above Wazuh's detection engine.

What Wazuh Does Well — and Where It Stops

Wazuh generates events from endpoint agents, log analysis, file integrity monitoring, vulnerability detection, and cloud security modules. Its MITRE ATT&CK rule coverage is extensive, and its output includes technique and tactic mappings that most commercial SIEMs charge separately for. For breadth of detection, Wazuh is difficult to match at any price.

What Wazuh does not do is triage. Wazuh generates an alert when a rule fires. It cannot assess whether this specific alert, in the context of this specific environment, with this specific user history, is worth a security engineer's attention — or whether it is the fortieth instance of a known false positive that should have been suppressed three months ago. That decision requires context that Wazuh does not hold.

In practice, a self-managed Wazuh deployment without a triage layer produces too many alerts to review. Engineers either become desensitized to the volume and miss real threats in the noise, or they spend most of their time manually triaging events that are clearly benign. Neither outcome is acceptable. ARIA's role is to make Wazuh's detection output actionable.

What the AI Layer Adds

ARIA sits above Wazuh's detection layer. When a Wazuh event arrives, a deterministic enrichment stage runs first: the MITRE technique is preserved from the sensor's tag, threat intelligence lookups run against configured feeds, alert history for the involved entity is queried, and — for cloud events — identity context is collected. The enrichment stage is not AI; it is structured queries with deterministic outputs.

The enriched alert then goes to an LLM for triage. The model produces a structured verdict where each stated claim cites the enrichment data that supports it. The verdict is then verified by a second model from a different vendor. If the two models agree and the evidence is sufficient, the alert routes automatically — benign alerts close with their trace preserved; threat alerts escalate. If there is any dispute or evidence gap, the alert goes to a security engineer.

Deterministic bypass rules run before the AI stage for known-benign patterns — specific process-signature combinations that reliably produce false positives. These are narrow, explicitly maintained rules, not machine-learned classifiers. They close a subset of alerts without any AI invocation, reducing the load on the triage pipeline for the most predictable noise.

The Sub-Topics in This Cluster

This page is the hub for ARIA's Wazuh + AI cluster. The sub-pages cover specific aspects of how ARIA integrates AI with Wazuh:

  • Integration architecture — how data flows from Wazuh into ARIA's pipeline
  • Agentic AI on Wazuh — multi-step reasoning vs Wazuh's rule engine
  • SOC automation — what gets automated, what doesn't, and why
  • Alert triage — the step-by-step triage process for a Wazuh event
Common Questions
Does ARIA replace Wazuh, or does it work alongside it?
ARIA operates on top of Wazuh, not in place of it. Wazuh handles detection — generating events from endpoint telemetry, log sources, file integrity checks, and vulnerability scanning. ARIA handles everything above that: enrichment, triage, verification, and routing. The detection coverage comes from Wazuh; the triage and verdict layer comes from ARIA.
Which Wazuh capabilities does ARIA use?
ARIA ingests Wazuh's alert stream from the Wazuh Indexer. It preserves Wazuh's MITRE ATT&CK technique and tactic mappings from the sensor, using the sensor-sourced tag rather than inferring technique from alert content. Wazuh's vulnerability detection and file integrity monitoring output flows through the same enrichment and triage pipeline as other event types. ARIA operates Wazuh infrastructure on its own systems — clients do not need to deploy or manage Wazuh themselves.
Can ARIA work with a self-hosted Wazuh deployment?
The standard ARIA service operates Wazuh on infrastructure SeenProtect manages. Integration with an existing self-hosted Wazuh deployment is a different configuration — contact SeenProtect to discuss your specific situation before assuming it applies to your case.
Does ARIA use Wazuh's active response feature?
Response actions in ARIA are approval-gated. A security engineer reviews and approves any response action before it executes. ARIA does not configure Wazuh's active response module to fire autonomously on ARIA's behalf — that would bypass the approval requirement.

See ARIA in Practice

Book a free assessment to see how the pipeline handles your actual alert environment.

Book Free Assessment
No contract. No setup fee. Cancel anytime.

See Plans

Starting at $799/month. No long-term contracts required.

View Pricing