<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vector Search on pyToshka's DevSecOps Blog</title><link>https://blog.pytoshka.me/en/tags/vector-search/</link><description>Recent content in Vector Search on pyToshka's DevSecOps Blog</description><generator>Hugo</generator><language>en-US</language><managingEditor>ping@pytoshka.me (pyToshka)</managingEditor><webMaster>ping@pytoshka.me (pyToshka)</webMaster><lastBuildDate>Tue, 06 Oct 2026 18:27:11 +0400</lastBuildDate><atom:link href="https://blog.pytoshka.me/en/tags/vector-search/index.xml" rel="self" type="application/rss+xml"/><item><title>Wazuh + AWS Bedrock: S3 Vectors for SOC Knowledge (Part 4)</title><link>https://blog.pytoshka.me/en/post/wazuh-aws-bedrock-mcp-part-4/</link><pubDate>Tue, 06 Oct 2026 00:00:00 +0000</pubDate><author>ping@pytoshka.me (pyToshka)</author><guid>https://blog.pytoshka.me/en/post/wazuh-aws-bedrock-mcp-part-4/</guid><description>&lt;h2 id="moving-the-knowledge-corpus-out-of-the-indexer"&gt;
 Moving the knowledge corpus out of the Indexer
 &lt;a class="header-anchor" href="#moving-the-knowledge-corpus-out-of-the-indexer" aria-label="Permalink to this section"&gt;
 &lt;svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg"&gt;
 &lt;path d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.65 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z" fill="currentColor"/&gt;
 &lt;/svg&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Part 3 ended with a condition, not a recommendation: the vector index belongs inside the Wazuh Indexer while the corpus is small and the clients already speak OpenSearch, and belongs somewhere else when the vector engine matters, when the corpus outgrows a single node, or when alert ingestion already claims that node&amp;rsquo;s CPU and heap. This part tests the other side of that condition. The same four sources went into Amazon S3 Vectors through an Amazon Bedrock Knowledge Base, the in-Indexer branch was rebuilt from the same snapshot so both could be measured on the same day, and the same frozen questions ran against both.&lt;/p&gt;</description></item></channel></rss>