VMTech
Discuss a project

Wazuh expands AI options for security operations teams

Wazuh expands AI options for security operations teams

Wazuh has outlined AI-assisted workflows for security operations centres, combining its cloud-based Wazuh AI Analyst with options to connect self-hosted and externally managed large language models. The Wazuh AI Analyst is available to Wazuh Cloud subscribers and produces scheduled reports on key indicators, protected endpoints, alert volumes, active vulnerabilities and overall security posture.

The service uses Amazon Bedrock and Anthropic’s Claude to process security data and generate the reports without manual configuration. Reports are emailed to the registered address on the subscription schedule, include a PDF attachment, and can also be viewed in the Wazuh Cloud console under Environments > AI Reports.

Automated reporting with advisory outputs

Security operations centres process alerts from endpoints, cloud workloads, network devices, identity providers and business applications. Wazuh positions AI as support for analysts who must correlate those signals, consult documentation and determine investigative steps, rather than as a replacement for their judgement.

For the cloud service, Wazuh says subscription data is not shared with third parties or used to train AI models. It says the information is processed only to generate reports, with encrypted transmission, isolated processing and no permanent storage. The company also stresses that AI recommendations are advisory and must be validated against an organisation’s own policies before action is taken.

Two integration paths for self-managed deployments

Teams running Wazuh themselves can use a local LLM path built around Meta’s open-source Llama 3 and Ollama. Ollama runs the model locally on the Wazuh server, while a Python script decompresses logs from a selected period and vectorises them into a FAISS store. A LangChain-powered chatbot can then be queried against that data.

This design keeps data on the organisation’s own network, which Wazuh presents as an option for threat-hunting teams with strict privacy or data-residency requirements. It provides a different operational model from the AI-enabled security tooling described in AI security threats and incident handling, where AI-related threats and incident handling are also central to security teams.

Wazuh also describes an externally managed route using Anthropic’s Claude 3.5 Haiku hosted on Amazon Bedrock. Through OpenSearch Assistant, the model appears as a chat box in the dashboard. Deployment requires enabling the model in Bedrock, installing relevant OpenSearch plugins, and creating an ML Commons connector, model and conversational agent.

Practical implication for security teams

These configurations can assist with common tasks such as interpreting a finding or explaining configuration choices, but they do not remove the need for analyst review. Security leaders should select the deployment model that fits their cloud, privacy and data-residency requirements, define how outputs will be checked, and keep humans responsible for consequential response decisions.

#cybersecurity#securityoperations#threathunting#artificialintelligence
Open analytics
On the site 1 views
min read 3 21.08.2026
Instagram

Wazuh expands AI options for security operations teams

Open the post on Instagram ↗