π Building an autonomous SIEM system overnight.
Wazuh + LLMs + Elasticsearch + optional SOAR.
Linux setup, code on screen, coffee & pizza on deck.
HP vs Voldemort β‘ on my left
Logs flowing soon.
The Watchtower is rising.
#CyberSecurity #AI #Wazuh #LLM #FYP #BuildInPublic
#siemphony
Wazuh + LLMs + Elasticsearch + optional SOAR.
Linux setup, code on screen, coffee & pizza on deck.
HP vs Voldemort β‘ on my left
Logs flowing soon.
The Watchtower is rising.
#CyberSecurity #AI #Wazuh #LLM #FYP #BuildInPublic
#siemphony
Comments
#siemphony #Docker #Wazuh #CyberSecurity #LLM #BuildInPublic
checked docker logs
traced it to the indexer not initializing .opendistro_security
turns out Docker mounted my certs as directories not files π€¦
wiped & recreated PEMs, then ran https://securityadmin.sh
#siemphony #Docker #Wazuh #CyberSecurity #LLM #BuildInPublic
BitLocker fought hard, but Linux won the war.
Docker Wazuh SIEM is initializing.
Learned alot , made mistakes too
#siemphony #CyberSecurity #LLM #Wazuh #BuildInPublic
Also BitLocker is a headache !!!
Setting up my Alienware , to run SIEM manager
#windows #LLM #Wazuh #BuildInPublic #apple #siem #ssh
Linux Box + Macbook Pro M2pro + iPad Air
#CyberSecurity #LLM #Wazuh #BuildInPublic #apple #ipad #ssh
#CyberSecurity #LLM #Wazuh #BuildInPublic
π Watchtower just got smarter.
Trying to setup a secure test environment to run attacks and parse logs
#CyberSecurity #LLM #Wazuh #BuildInPublic
Replacing the βScholarβ with something more intentional:
π§ Sentient β the LLM-powered brain of the system.
It reads logs, learns from threats, and writes custom Wazuh rules in real-time.
Phase 2 begins. Guardian is waking up.
#siemphony #CyberSecurity #LLM #FYP #BuildInPublic
π§Ή Purged the broken stack.
π§ Installed a full All-in-One SIEM on unsupported Linux
ποΈ Fixed agents, configs, API, services.
Logs are flowing.
Next up: feeding them to an LLM and letting it write defensive rules live.
#siemphony #CyberSecurity #LLM #FYP #BuildInPublic
Out by 7am, worked till 1pm.
Cleared my head with a bike ride β air, wind, throttle, peace.
Came back to the desk, VS Code, terminal, and a dream.
Time to get wired in again
#siemphony #buildinpublic #ai #llm #100daysofcode #wazu
Parsed real Wazuh logs and asked LLM to explain them + generate new detection rules.
It suggested a sudo alert, failed login tracking, and session monitoring
first time Iβve seen my logs write their own defenses.
#siemphony #CyberSecurity #LLM #Wazuh #FYP #BuildInPublic
βYou exceeded your current quota.β
Lesson: free OpenAI API keys only get you so far. Need to upgrade or use a local LLM next.
#siemphony #FYP #BuildInPublic #LLM #OpenAI
Hit a permissions error reading Wazuh logs β turned out they were root-protected.
Learned that security tools protect even their own outputs.
#siemphony #CyberSecurity #LLM #FYP #BuildInPublic
Wazuh SIEM stack installed and running. Logs flowing.
#siemphony #CyberSecurity #Wazuh #LLM #FYP #BuildInPublic