Wazuh Adds AI Analyst, Llama and Claude Integrations — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Wazuh introduced the Wazuh AI Analyst, an automated AI-powered security analysis service for Wazuh Cloud subscriptions that processes security data through Amazon Bedrock and Anthropic's Claude without manual configuration.
- The Wazuh AI Analyst delivers scheduled email reports covering key indicators, a histogram of protected endpoints, alert volume, active vulnerabilities, and a posture summary with a full PDF attachment, also viewable in the Wazuh Cloud console under Environments > AI Reports.
- Wazuh states that subscription data is not shared with third parties and is not used to train AI models, with encrypted transmission, isolated processing, and no permanent storage — though AI recommendations remain advisory and must be validated against internal policies.
- For privacy-sensitive deployments, Wazuh integrates Meta's open-source Llama via Ollama on the Wazuh server, using a Python script, FAISS vector store, and LangChain-powered chatbot to enable local threat hunting with no data sent to a cloud provider.
- Wazuh also offers an externally managed integration surfacing Anthropic's Claude 3.5 Haiku, hosted on Amazon Bedrock, through OpenSearch Assistant inside the dashboard to provide in-context guidance on findings and configuration tasks.
- Wazuh frames AI as augmenting rather than replacing SOC analysts, targeting the alert fatigue caused by millions of daily security events flowing from endpoints, cloud workloads, network devices, identity providers, and business applications.
Why it matters: SOC teams facing millions of daily alerts from endpoints, cloud workloads, and identity providers get a built-in path to automate routine report generation inside the Wazuh console without bolting on a separate AI stack. Wazuh's dual-track design — Anthropic's Claude on Bedrock for cloud subscribers and Meta's Llama via Ollama for self-hosted environments — lets organizations match AI adoption to their own data-residency and privacy constraints rather than accepting a single cloud dependency.
Ask SkimNews




