Guilgo Blog

Notes from my daily work with technology.

Monitor Docker containers with Wazuh docker-listener: no custom rules needed

On 4.14.7 the official ruleset already keys off docker.Action; keep the socket on the host agent, not the manager

Enable Wazuh docker-listener on 4.14.7 without custom rules: the official ruleset already maps docker.Action, and the socket stays on the host agent.

KIO Snapshot: previous file versions in Dolphin on Btrfs

Previous Versions comes to KDE Plasma: Btrfs snapshots reachable from Dolphin without root

How to set up KIO Snapshot on Plasma 6 for previous file versions in Dolphin with Btrfs and Snapper: ACLs and /home snapshots on CachyOS/Arch.

Prometheus and Alertmanager: automatic Kubernetes remediation with an allowlist

From alert to fix (with a brake): DiskPressure and Failed pods, a local gate, a short allowlist, and a single report

Prometheus and Alertmanager automatic remediation in Kubernetes with an allowlist: DiskPressure, Failed pods, one Telegram report, no cloud agents.

Integrating urlscan.io with Wazuh-lite for Automated Alert Enrichment

Automatically enrich AdGuard and parental control alerts with urlscan.io, dual Telegram notifications, and real reputation verdicts

Learn how to integrate urlscan.io with Wazuh-lite to enrich AdGuard alerts with URL reputation and threat intelligence while keeping your SIEM workflow.

How to Detect Compromised AUR Packages with Wazuh and Telegram on Arch Linux

Hourly checks against aur-malware-check, custom decoders, and level-12 alerts if a package from the atomic-lockfile attack is installed

Guide to detect compromised AUR packages on Arch Linux using Wazuh and Telegram: hourly aur-malware-check, custom decoders, and level-12 alerts.

Wazuh 5: a production survival guide

Verifiable criteria to go live without the stack overwhelming you

Verifiable criteria to take Wazuh 5 to production: predictable upgrades, signal vs noise, indexer performance, and a pilot with a clear stop rule.