// Endpoint Security & SIEM
Threats detected before they become incidents.
Wazuh SIEM deployed across your endpoints, servers, and network — correlated, alerted, and triaged by engineers who know your environment. Not a dashboard you log into. A service that pages you when it matters.
< 5 min
Mean time to alert
90 days
Hot log retention
24 / 7
Monitoring coverage
NPC-ready
Compliance reporting
// Coverage
Every layer of your stack. One correlated view.
Siloed alerts miss the story. We ingest from endpoints, servers, network, and cloud — so a login anomaly on a workstation correlates with the firewall event that preceded it.
Endpoints & workstations
Every Windows, Linux, and macOS device is enrolled in the Wazuh agent. File integrity, process execution, and login events — logged and alerted in real time.
Servers & virtualisation hosts
Proxmox, VMware, and bare-metal servers. Kernel events, privilege escalation attempts, and unexpected service restarts surface immediately, not in the next morning's report.
Network traffic & firewall logs
Log ingestion from pfSense, OPNsense, Cisco, and Mikrotik. Lateral movement and port-scan patterns are correlated across devices, not treated as isolated events.
Cloud workloads
AWS CloudTrail, Azure Activity Logs, and container runtime events fed directly into the SIEM. One dashboard, every environment.
// Process
From zero visibility to full coverage in under a week.
Agent deployment is the shortest part. Tuning your environment so alerts are signal, not noise, is where the work actually happens.
Agent deployment
Wazuh agents installed on every managed endpoint and server — typically completed within one business day for up to 50 nodes.
Baseline & tuning
We establish your environment's normal behaviour over 5–7 days, then suppress noise and sharpen detection rules to your actual threat surface.
Real-time alerting
Critical-severity events page your designated contact immediately. Medium events are batched into a daily digest unless they cluster into a pattern.
Incident response
When an alert fires, we triage first — you get a qualified finding, not a raw log dump. Containment steps are executed with your approval, fully documented.
// Technology
Open-source stack. No per-seat licensing. Fully auditable.
Every tool we deploy is open-source and self-hosted in your environment. You own the data, the config, and the stack — not a SaaS subscription that walks out the door if you stop paying.
// Your stack. Your data.
No vendor lock-in. No data leaving your network. Full documentation so your team can operate it independently.
Wazuh
SIEM & XDR
Open-source, agent-based. No per-endpoint licensing cost. Full source access — you own the stack.
Falco
Container & kernel runtime
eBPF-based syscall monitoring for containerised workloads and Kubernetes clusters.
Grafana / OpenSearch
Dashboards & log search
Custom dashboards per client. Full-text log search across every ingested source with 90-day hot retention.
pfSense / OPNsense
Perimeter log ingestion
Firewall rule hits, blocked IPs, and geo-anomalies correlated with endpoint events for full kill-chain visibility.
// Security scope
Physical and digital security — monitored from one platform.
Our Security pillar covers the full surface: CCTV and AI surveillance, physical access control, and cybersecurity. Frigate NVR motion events and door-controller logs feed into the same SIEM as your endpoint alerts — so a physical intrusion attempt correlates with the network activity that follows it.
Wazuh SIEM across endpoints, servers, and cloud
Firewall and network log correlation
Falco for container and kernel-level runtime monitoring
Frigate NVR + CCTV event correlation
NPC-compliant audit trail and retention
// FAQ
Common questions
Do we need to replace our existing antivirus?
No. Wazuh sits alongside your existing endpoint protection — it adds visibility at the OS and network layer that AV alone doesn't cover. We integrate, not replace.
How many endpoints is this suitable for?
We've deployed for environments from 5 to 300+ nodes. Below 20 endpoints the setup cost dominates, so we'll be honest if managed IT support is a better fit first.
Is this compliant with Philippine data privacy requirements?
Yes. Wazuh's log retention and access controls support NPC (National Privacy Commission) audit trail requirements. We provide a compliance report template on request.
What happens when a threat is detected at 2 AM?
Critical alerts page the on-call engineer immediately. We triage, assess, and contact your designated point of contact with a qualified finding — not a raw alert dump.
Can you monitor our CCTV and physical access control systems too?
Yes — this is a deliberate part of our Security pillar scope. Frigate NVR events and access control logs can be correlated with network and endpoint events in the same SIEM.
// Get started
Find out what your current stack is missing.
Free security assessment — we review your current environment, identify the highest-risk gaps, and give you a clear remediation plan. No sales pitch until you ask for one.
Or call +63 926 034 6800