Wazuh SIEM Implementation with Agent and pfSense Integration

Cyber security, Wazuh, Threat Detection, Compliance Monitoring, pfSense firewall.

Authors

  • Ashvini Bais Assistant Professor, G H Raisoni College of Engineering, Nagpur, Maharashtra, India.
  • Asakti Rautkar Assistant Professor, G H Raisoni College of Engineering, Nagpur, Maharashtra, India.
  • Ketan Bodhe Assistant Professor, G H Raisoni College of Engineering, Nagpur, Maharashtra, India.
  • Kamlesh Kalbande Assistant Professor, G H Raisoni College of Engineering, Nagpur, Maharashtra, India.
  • Pooja Kalbande Faculty, G H Raisoni College of Engineering and Managment, Nagpur, Maharashtra, India.
May 25, 2026
May 26, 2026

Downloads

In the current digital era, organizations are constantly facing an array of security threats that can compromise sensitive information and interfere with their operations. For them to properly safeguard their assets, companies need to implement powerful security monitoring systems. One example is Wazuh, an open-source security information and event management (SIEM) system that provides end-to-end visibility into an organization's security posture. The focus of this project is to install and set up Wazuh, including the installation of agents on different endpoints, such as Windows and Linux. Through log gathering and forwarding to the Wazuh server, we can guarantee that important security incidents are recorded and analyzed. The integration of log sources, such as pfSense firewalls, is an essential part of this process and helps us to better identify possible security threats. Also, the project will entail the establishment and personalization of rules and decoders in Wazuh to adapt its detection to the particular requirements of our company. This will allow us to better detect and react to security incidents by correlating events and triggering timely alerts. In addition to incident detection and response, Wazuh will also be used for monitoring compliance, ensuring our organization complies with applicable security standards and regulations. With the ability to produce compliance reports and observe system configurations, we are able to stay in a robust security stance and avoid risks. The significance of this project is underscored by the burgeoning number of cybersecurity incidents. As per CERT-In (Indian Computer Emergency Response Team), more than 1.2 million cybersecurity incidents occurred in India during 2023 alone, such as targeted attacks on government, healthcare, and financial institutions. The scenario turned worse in 2024 with cybercrime complaints crossing 25 lakh and estimated losses crossing Rs 20,000 crore. Through this project, we hope to create an overarching security monitoring system that not only increases our ability to respond to incidents, but also assists with compliance. In the end, we hope to help create a safer organizational environment in the wake of these increasing threats.