1. What Wazuh Solves for Defenders
Wazuh is an open-source security platform for log collection, endpoint telemetry, detection, and monitoring that defenders use to build centralized visibility and response workflows.
Wazuh fits the "SIEM / XDR / log and telemetry platform" role in this course. Treat it as one tool in a workflow, not as a complete answer by itself. The key question is what decision quality it improves for a defender.
Before using Wazuh, define the operational question first (triage, validation, exposure review, monitoring, forensics, or documentation). Tool selection should follow the question, not the other way around.