Home/Managed Wazuh
Managed Wazuh

Wazuh, run for you. Every alert explained.

Suriq runs the open-source Wazuh engine for you, ranks what it finds into incidents, and Guardian explains each one in plain English. Nothing changes on your machines until you approve it. Wazuh is the engine. Suriq is the team that runs it and the console that makes it readable.

What is managed Wazuh as a service?

Managed Wazuh as a service means a provider runs the open-source Wazuh platform for you - provisioning the Wazuh manager and indexer, tuning rules and decoders, scaling storage, and patching - so your team gets Wazuh's detection without operating it. Suriq runs that core in your own cloud account and adds the layer around it, on one console.

With Suriq's managed Wazuh you get:

  • Wazuh detection provisioned, tuned per host, and kept healthy, in a backend that is yours.
  • Alerts correlated into ranked incidents with an audit trail, instead of a firehose.
  • Guardian, the assistant, explaining what fired, why, and what to check next. Fixes it drafts run only after you approve them.
  • When a new CVE lands, which machines it hits, ranked worst-first.
  • File integrity monitoring tagged to MITRE ATT&CK, with changed system files checked against what your distribution or panel actually shipped.
  • Uptime and external-surface monitoring, backups to the clouds you run, and secrets in a vault you choose.

You get Wazuh's detection. We carry the operating.

Self-hosting Wazuh means provisioning the manager and indexer, tuning rules and decoders, scaling storage, patching, and keeping it healthy around the clock. Suriq stands up and runs that core for you - provisioned, scaled, patched, and health-checked - so your team gets the detection without the second job.

01

Ranked incidents, not a firehose

Related alerts are deduplicated and bundled into one incident, tagged to MITRE ATT&CK, ranked by severity, and routed to the channels your team already uses. Every step is in the audit trail.

02

Guardian tells you what fired and why

Guardian, the Claude-powered assistant, turns a technical detection into a plain-English story: what happened, why the rule fired, what to check next. When it drafts a fix, the fix waits for your approval.

03

A new CVE lands and you know which machines it hits

Package inventories are matched against the CVE databases continuously, so exposure is ranked worst-first the moment a CVE is published. No fleet-wide scan to run first.

04

Changed files, checked against the vendor

File integrity monitoring reports the change. Suriq goes one step further and checks system files against the packages your distribution or control panel actually shipped, so you chase the one file that matters.

05

The outside is watched too

Certificate expiry, DNS and zone changes, WHOIS changes, BGP routes with RPKI validation, and uptime checks, from multiple regions. The exposure Wazuh does not see.

06

Backups and secrets, handled

Snapshots on the clouds you already run, with a clean restore point ready. Credentials the platform needs live in a vault you choose, with least-privilege access.

Self-hosted Wazuh vs. Managed by Suriq

DimensionSelf-hosted WazuhSuriq
Setup and upkeepYou install, tune, scale, and patchWe provision, tune, and keep it healthy
Who operates itYour team, on callSuriq, in your own cloud account
Alert triageDeep detections, decode them yourselfRanked incidents, explained in plain English
Changes to your serversYou, by handProposed by Guardian, applied after you approve
External surfaceNot Wazuh's jobDNS, BGP/RPKI, certificates, uptime watched
RecoveryManualSnapshots ready, DNS failover that reverts on recovery
SecretsWherever you left themIn a vault you choose, least privilege

What Suriq does not do

  • No human analyst desk. Detection and Guardian run around the clock and incidents reach your channels; your team makes the call.
  • No silent changes. Fixes are proposed and wait for approval. The one automatic action is DNS failover for a monitored host that drops, and it reverts when the host is back.
  • Not every operating system yet. Tell us what you run when you request access and we will say plainly whether it installs today.
  • No public pricing yet. Early access is open and pricing is being finalized; we scope it to your environment.

Frequently asked questions

What is managed Wazuh?

Managed Wazuh means Suriq runs the open-source Wazuh detection platform for you - provisioning the manager and indexer in your own cloud account, tuning rules and decoders per host, scaling storage, patching, and watching its health - so your team gets Wazuh's detection without operating it.

How is Suriq's managed Wazuh different from self-hosting Wazuh?

Self-hosting means you provision, tune, scale, and patch Wazuh and stay on call for it. Suriq runs that core for you and adds the layer around it: alerts correlated into ranked incidents, Guardian explaining each one in plain English, external-surface and uptime monitoring, backups, and a secrets vault, all in one console.

Does Suriq run the real open-source Wazuh?

Yes. The detection engine is Wazuh, the open-source security platform, run and maintained by Suriq in a dedicated backend in your own cloud account. You keep Wazuh's detection rules and MITRE ATT&CK coverage; Suriq handles provisioning, tuning, scaling, and upkeep.

Can I add my own detection rules?

Yes. Because the engine is Wazuh, a fully programmable detection platform, you are not limited to a fixed set of detections. Suriq deploys managed and community rule packs mapped to each host, and you can add your own rules and decoders on top.

Who watches at 3am? Is there a human SOC?

Detection and Guardian's explanations run around the clock, and every incident reaches the channels your team already uses, so nothing waits for a night shift. Suriq does not staff a human analyst desk; your team decides and acts, with the incident already ranked and explained when they open it.

How fast can Suriq show my CVE exposure?

Straight away. Package inventories are collected continuously and matched against the CVE databases, so when a new CVE lands the console already shows which machines it affects, ranked worst-first, without a fleet-wide scan.

Does Suriq change anything on my servers by itself?

No. Suriq detects, ranks, and explains what is wrong and Guardian proposes a fix, but every change waits for someone on your team to approve it. The one automatic action is DNS failover for a monitored host that drops, and it reverts when the host recovers.

How is managed Wazuh priced?

Pricing is being finalized, so we are not publishing a billing model, plan structures, or numbers yet. Get on the early-access list and we will scope pricing to your environment - you will be first to see it when it is set.

See it on your own machines.

Agentless for uptime and cloud monitoring, a lightweight agent for detection, all on a Wazuh core we run for you. Request access and we will walk you through it on your fleet.