I’ve been working on a SOC project, and part of my task is to design a technical architecture using open-source tools. During my research, I stumbled upon a highly useful architecture proposed, utilizing ELK and other tools.
Here’s the architecture:
However, I encountered an issue. Since version 4.3 of Wazuh, they’ve developed their own SIEM/XDR architecture, rendering ELK unnecessary. Additionally, new plugins are no longer available for ELK 8.x.x.
My question is, can I exclusively use Wazuh as an SIEM/XDR solution, essentially replacing the first architecture with this one?
Or, for a robust architecture, would it be preferable to retain the original design and utilize older versions of both tools?
PS : the last version of Wazuh is just perfect like it integrate the EDR, network protection, incident respond and more.
-I wanna know the why Wazuh do not use ELK anymore
-Using Wazuh can replace the hall old architecture efficiently or do i have to add something
-I do not know Wazuh can control also the network i mean the firewall and IDS/IPS (Get logs from them) like elk do or not