Wazuh lab: deployment, clustering, and load testing
Why a lab
Learning a SIEM properly takes more than an installer. You have to see agents fail, certificates break, networking misbehave, queues build, and latency appear under load. A lab makes those failures safe to cause and repeat.
What I built
- Standalone and two-node cluster Wazuh deployments.
- Windows and Linux endpoint enrollment, with agent health and log ingestion validated.
- TLS, external access controls, syslog ingestion, hardening, and upgrades.
- Perimeter controls: firewall policy, NAT/PAT, and port forwarding with least-privilege rules.
- DDNS for remote monitoring on a dynamic IP, with periodic reviews of credentials and firewall rules.
- Load testing around 5–6K EPS to watch ingest behaviour, queueing, and latency.
The lab dashboard is not linked publicly here, on purpose: it runs on hardware at home.
What it is for
Reproduce it, measure it, understand it, then carry the lesson into production work.