Wazuh SIEM Implementation with Agent and pfSense Integration
Downloads
In the current digital era, organizations are constantly facing an array of security threats that can compromise sensitive information and interfere with their operations. For them to properly safeguard their assets, companies need to implement powerful security monitoring systems. One example is Wazuh, an open-source security information and event management (SIEM) system that provides end-to-end visibility into an organization's security posture. The focus of this project is to install and set up Wazuh, including the installation of agents on different endpoints, such as Windows and Linux. Through log gathering and forwarding to the Wazuh server, we can guarantee that important security incidents are recorded and analyzed. The integration of log sources, such as pfSense firewalls, is an essential part of this process and helps us to better identify possible security threats. Also, the project will entail the establishment and personalization of rules and decoders in Wazuh to adapt its detection to the particular requirements of our company. This will allow us to better detect and react to security incidents by correlating events and triggering timely alerts. In addition to incident detection and response, Wazuh will also be used for monitoring compliance, ensuring our organization complies with applicable security standards and regulations. With the ability to produce compliance reports and observe system configurations, we are able to stay in a robust security stance and avoid risks. The significance of this project is underscored by the burgeoning number of cybersecurity incidents. As per CERT-In (Indian Computer Emergency Response Team), more than 1.2 million cybersecurity incidents occurred in India during 2023 alone, such as targeted attacks on government, healthcare, and financial institutions. The scenario turned worse in 2024 with cybercrime complaints crossing 25 lakh and estimated losses crossing Rs 20,000 crore. Through this project, we hope to create an overarching security monitoring system that not only increases our ability to respond to incidents, but also assists with compliance. In the end, we hope to help create a safer organizational environment in the wake of these increasing threats.
Farrel, S., et al. (2024). "Real-Time SIEM Response Using Telegram Alerts." IEEE Conference on Cybersecurity and Threat Intelligence
IEEE Conference Proceedings. (2025). "Open Source SIEMs for National Cyber Defense." IEEE Symposium on Open Source Security Tools.
S. Moiz, A. Majid, A. Basit, M. Ebrahim, A. A. Abro and M. Naeem, "Security and Threat Detection through Cloud-Based Wazuh Deployment," 2024 IEEE 1st Karachi Section Humanitarian Technology Conference (KHI-HTC), Tandojam, Pakistan, 2024, pp. 1-5, doi: 10.1109/KHI-HTC60760.2024.10482206.
González-Granadillo, G., et al. (2021). "SIEMs in Critical Infrastructures: A Comparative Study." Journal of Information Security and Applications, Elsevier.
Hidayat, A., et al. (2023). "CTI-based Malware Detection using Wazuh and MISP." International Journal of Cyber-Security and Digital Forensics.
Bezas, K., & Filippidou, F. (2023). "Evaluation of Open-Source SIEM Tools for SMEs." Proceedings of the 17th International Conference on Cyber Warfare and Security (ICCWS).
Islam, M. R., and Raisa Rafique. “Wazuh SIEM for Cyber Security and Threat Mitigation in Apparel Industries.” International Journal of Engineering Materials and Manufacture, vol. 9, no. 4, Oct. 2024, pp. 136–44, doi:10.26776/ijemm.09.04.2024.02.
Bhavana, V., et al. (2025). "SIEM and SOAR Integration for Automated Security Monitoring." Proceedings of the ACM Symposium on Security Automation.
M. R. Islam, M. Akhtaruzzaman, M. M. Rahman, M. T. Rahman, and M. R. Mehedi, “Wazuh SIEM for Cyber Security and Threat Mitigation in Apparel Industries,” ResearchGate, 2024.
D. Pawar and A. Choubey, “WAZUH – New Age Security Monitoring SIEM Tool,” International Research Journal of Modernization in Engineering Technology and Science, vol. 6, no. 5, 2024.
The Science and Information Organization, “SIEM and Threat Intelligence: Protecting Applications with Wazuh, TheHive, and Telegram,” International Journal of Advanced Computer Science and Applications, vol. 15, no. 9, 2024
Uetz, R., Herzog, M., Hackländer, L., Schwarz, S., & Henze, M. (2023). You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise Networks. arXiv preprint arXiv:2311.10197.
Farrel, F.I.F., Mardianto, I. and Qamar, M.Ir.A.S. (2024) “Implementation of Security Information & Event Management (SIEM) Wazuh with Active Response and Telegram Notification for Mitigating Brute Force Attacks on The GT-I2TI USAKTI Information System,” Intelmatics, 4(1), pp. 1–7. doi:10.25105/itm.v4i1.18529
R. Amami, M. Charfeddine and S. Masmoudi, "Exploration of Open Source SIEM Tools and Deployment of an Appropriate Wazuh-Based Solution for Strengthening Cyberdefense," 2024 10th International Conference on Control, Decision and Information Technologies (CoDIT), Vallette, Malta, 2024, pp. 1-7, doi: 10.1109/CoDIT62066.2024.10708476.
Alatise, T.I. and Nottidge, O.E. (2024) “Threat detection and response with SIEM system,” International Journal of Communication and Information Technology, 5(1), pp. 36–38. doi:10.33545/2707661x.2024.v5.i1a.78.
Jumiaty and Soewito, B. (2024) “SIEM and Threat Intelligence: Protecting Applications with Wazuh and TheHive,” International Journal of Advanced Computer Science and Applications, 15(9). doi:10.14569/ijacsa.2024.0150923.
Sufardy, D.B. and Widiasari, I.R. (2024) “The Use of PFSense and Suricata as a Network Security Attack Detection and Prevention Tool on Web servers,” INOVTEK Polbeng - Seri Informatika, 9(2), pp. 765–777. doi:10.35314/shxy204.
Amin, R. and Hasan, D. (2023) “Comparative Analysis of Flexiwan, OPNSense, and pfSense Cybersecurity Mechanisms in MPLS / SD-WAN Architectures,” passer, 6(1), pp. 27–32. doi:10.24271/psr.2023.390989.1295.
Analysis of Wazuh SIEM’s Effectiveness in Cloud Security Monitoring” (2024) Journal of Cybersecurity and Information Management, 15(1). doi:10.54216/jcim.150119.
