Wazuh 4.14.7 vs 5.0 Beta 5: This Is a Migration, Not an Upgrade

The first thing 5.0 broke for me was not a feature. It was a habit.

When something looks stuck on a Wazuh 4.x server, you restart the manager. It is the cheapest diagnostic move there is, and on the 4.x installations I have run it has been safe, because by the time the manager restarts the alert is already written to disk. So I did the same thing on a 5.0.0 Beta 5 stand while its indexer happened to be down. Of the hundred events whose presence in the agent file was confirmed before that restart, none reached the indexer afterwards. How many the manager had already accepted I cannot say: 5.0 exposes no point between acceptance and indexing, which is part of what this comparison is about.

[Read More]

Wazuh + AWS Bedrock: RAG with Titan Embeddings (Part 3)

Introduction

Ask the chat agent from Part 1 what the team runbook prescribes for an SSH brute force against web-server-01, or ask the MCP sidecar from Part 2 whether a file hash appeared in a threat intelligence feed last month, and the answer is whatever Claude remembers about the world in general. Both tools query alerts well. Neither of them can read a document, and the runbook, the manual and the feed never reach the model.

[Read More]

Wazuh MCP Server: Claude Desktop + OpenSearch (Part 2)

Introduction

In Part 1 we connected AWS Bedrock Claude to the Wazuh Dashboard chat via ML Commons. That approach works well for analysts working inside the Wazuh UI. In this part we open a second channel: Model Context Protocol (MCP), which allows any compatible client - Claude Desktop, custom applications, CI pipelines - to query Wazuh Indexer data through a standardized tool interface.

[Read More]