Wazuh + AWS Bedrock: S3 Vectors for SOC Knowledge (Part 4)

Moving the knowledge corpus out of the Indexer

Part 3 ended with a condition, not a recommendation: the vector index belongs inside the Wazuh Indexer while the corpus is small and the clients already speak OpenSearch, and belongs somewhere else when the vector engine matters, when the corpus outgrows a single node, or when alert ingestion already claims that node’s CPU and heap. This part tests the other side of that condition. The same four sources went into Amazon S3 Vectors through an Amazon Bedrock Knowledge Base, the in-Indexer branch was rebuilt from the same snapshot so both could be measured on the same day, and the same frozen questions ran against both.

[Read More]