Guilgo Blog

Notes from my daily work with technology.

Build a proactive SOC in a homelab: Kubernetes, Docker, Wazuh, Trivy and Telegram

Low-noise periodic checks: broken pods, high Wazuh alerts, CVEs in exposed images and Telegram reports, with deduplication and clear severity policy

Guide: proactive homelab SOC with k3s, Wazuh, Trivy (CVEs on exposed Docker images) and Telegram. Cron, low noise, dedupe and actionable alerts.

Wazuh Grafana integration: lightweight dashboard without Elasticsearch

Agents, security alerts (SCA, MITRE), AdGuard and parental control in one dashboard. No Indexer or official Dashboard.

Wazuh Grafana integration without Elasticsearch: a lightweight REST API dashboard for agents, SCA/MITRE alerts and AdGuard. JSON plugin, JWT and proxies.

Auditing Kubernetes with Wazuh: API server audit logs into your SIEM

Webhook listener, audit policy, and custom detection rules for create/delete events

Step-by-step guide to audit Kubernetes with Wazuh: API server audit logs to the SIEM, webhook listener, audit policy and rules in local_rules.xml. Kubernetes security monitoring.