AI Powered Anomaly Detection Using Wazuh and ELK

Let's See

AI Powered Anomaly Detection Using Wazuh and ELK

This project presents an AI-based anomaly detection system using Wazuh and the ELK Stack to identify malicious activities, such as SSH brute force attacks, in real time. Wazuh collects system logs, which are streamed through Kafka and ZooKeeper to an Isolation Forest model that detects unusual SSH login patterns and trigger alerts. The ELK Stack (Logstash, Elasticsearch, Kibana) processes, stores, and visualizes data for rapid threat identification. Experimental results show improved detection accuracy and reduced false positives, enhancing Security Operations Center (SOC) efficiency for small-to-medium enterprises. This scalable, open-source solution strengthens cybersecurity with actionable insights.

Keywords: cybersecurity,machine learning,soc analyst,siem solutions,wazuh
Tools: wazuh,elk stack,machine learning,google colab,apache kafka,zookeeper,python
Department: Department of Computer Science
Project Poster
Blog
Project Team Members
Name Email CV
Dilawer Khan dilawer2021@namal.edu.pk
Muhammad Toqeer touqeer2020@namal.edu.pk