Wazuh, run for you. Every alert explained.
Suriq runs the open-source Wazuh engine for you, ranks what it finds into incidents, and Guardian explains each one in plain English. Nothing changes on your machines until you approve it. Wazuh is the engine. Suriq is the team that runs it and the console that makes it readable.
What is managed Wazuh as a service?
Managed Wazuh as a service means a provider runs the open-source Wazuh platform for you - provisioning the Wazuh manager and indexer, tuning rules and decoders, scaling storage, and patching - so your team gets Wazuh's detection without operating it. Suriq runs that core in your own cloud account and adds the layer around it, on one console.
With Suriq's managed Wazuh you get:
- Wazuh detection provisioned, tuned per host, and kept healthy, in a backend that is yours.
- Alerts correlated into ranked incidents with an audit trail, instead of a firehose.
- Guardian, the assistant, explaining what fired, why, and what to check next. Fixes it drafts run only after you approve them.
- When a new CVE lands, which machines it hits, ranked worst-first.
- File integrity monitoring tagged to MITRE ATT&CK, with changed system files checked against what your distribution or panel actually shipped.
- Uptime and external-surface monitoring, backups to the clouds you run, and secrets in a vault you choose.
You get Wazuh's detection. We carry the operating.
Self-hosting Wazuh means provisioning the manager and indexer, tuning rules and decoders, scaling storage, patching, and keeping it healthy around the clock. Suriq stands up and runs that core for you - provisioned, scaled, patched, and health-checked - so your team gets the detection without the second job.
Ranked incidents, not a firehose
Related alerts are deduplicated and bundled into one incident, tagged to MITRE ATT&CK, ranked by severity, and routed to the channels your team already uses. Every step is in the audit trail.
Guardian tells you what fired and why
Guardian, the Claude-powered assistant, turns a technical detection into a plain-English story: what happened, why the rule fired, what to check next. When it drafts a fix, the fix waits for your approval.
A new CVE lands and you know which machines it hits
Package inventories are matched against the CVE databases continuously, so exposure is ranked worst-first the moment a CVE is published. No fleet-wide scan to run first.
Changed files, checked against the vendor
File integrity monitoring reports the change. Suriq goes one step further and checks system files against the packages your distribution or control panel actually shipped, so you chase the one file that matters.
The outside is watched too
Certificate expiry, DNS and zone changes, WHOIS changes, BGP routes with RPKI validation, and uptime checks, from multiple regions. The exposure Wazuh does not see.
Backups and secrets, handled
Snapshots on the clouds you already run, with a clean restore point ready. Credentials the platform needs live in a vault you choose, with least-privilege access.
Self-hosted Wazuh vs. Managed by Suriq
| Dimension | Self-hosted Wazuh | Suriq |
|---|---|---|
| Setup and upkeep | You install, tune, scale, and patch | We provision, tune, and keep it healthy |
| Who operates it | Your team, on call | Suriq, in your own cloud account |
| Alert triage | Deep detections, decode them yourself | Ranked incidents, explained in plain English |
| Changes to your servers | You, by hand | Proposed by Guardian, applied after you approve |
| External surface | Not Wazuh's job | DNS, BGP/RPKI, certificates, uptime watched |
| Recovery | Manual | Snapshots ready, DNS failover that reverts on recovery |
| Secrets | Wherever you left them | In a vault you choose, least privilege |
Know which machines a new CVE hits.
Continuous package scanning against the CVE databases, scored by CVSS and ranked worst-first, with a fix Guardian can explain.
Incident response, with context in hand.
Detections bundled into one correlated incident, tagged to MITRE, routed to on-call, and explained in plain English.
The SIEM that is finally worth running.
Managed, Wazuh-powered detection in the box - a Splunk and Sentinel alternative with no SPL or KQL to hand-write.
What Suriq does not do
- No human analyst desk. Detection and Guardian run around the clock and incidents reach your channels; your team makes the call.
- No silent changes. Fixes are proposed and wait for approval. The one automatic action is DNS failover for a monitored host that drops, and it reverts when the host is back.
- Not every operating system yet. Tell us what you run when you request access and we will say plainly whether it installs today.
- No public pricing yet. Early access is open and pricing is being finalized; we scope it to your environment.
Frequently asked questions
What is managed Wazuh?
How is Suriq's managed Wazuh different from self-hosting Wazuh?
Does Suriq run the real open-source Wazuh?
Can I add my own detection rules?
Who watches at 3am? Is there a human SOC?
How fast can Suriq show my CVE exposure?
Does Suriq change anything on my servers by itself?
How is managed Wazuh priced?
See it on your own machines.
Agentless for uptime and cloud monitoring, a lightweight agent for detection, all on a Wazuh core we run for you. Request access and we will walk you through it on your fleet.