Skip to main content
Labshock
LoginStart Free
← All Updates
RELEASEJuly 18, 2026

Wazuh Is Now a Free OT SIEM Lab Inside Labshock

Wazuh manager and dashboard, deployed and connected to a living industrial environment. Trigger an action on the OT side, find it in the dashboard, and test whether your rule fires.

Wazuh is one of the most asked-about tools in our community.

An open source SIEM many of you already run.

Now it runs inside Labshock, connected to a real industrial environment.

Free. No license, no trial, no card.

What Is Inside

  • Wazuh manager and dashboard, deployed and running
  • Real logs from industrial services flowing in
  • Rules and alerts you can trigger yourself
  • Connected to a living OT environment

The last point is the one that matters.

A SIEM fed by static sample logs teaches you the query language.

A SIEM fed by a running industrial process teaches you detection.

What You Do

  • Open the dashboard, see OT events reporting
  • Watch logs flow from the plant systems
  • Trigger an action on the OT side, then find it in Wazuh
  • Write a rule, and test whether it fires
  • Force a fault condition, and see what the alert says

Step three is where most SIEM learning stops short.

Knowing a rule exists is not the same as knowing what it looks like when the underlying event happens for real, in a plant, among other traffic.

The gap between "the rule is deployed" and "the rule fires on the thing I care about" is where detection quietly fails.

Step five is the other half.

An alert that fires is only useful if it tells the analyst what actually happened to the process.

Reading your own alert text after forcing a fault on your own system is the fastest way to find out whether it does.

Why We Made It Free

Detection is where OT security becomes real.

And you cannot learn detection from screenshots.

You need a SIEM connected to a living system, one you are allowed to test against, where the consequences are educational rather than industrial.

That combination is normally hard to get.

Production is not a place to test rules.

A pile of sample logs does not behave like a plant.

So detection ends up being the skill people read about and never practice, which is exactly backwards for the discipline where a missed alert has physical consequences.

Making this lab free removes the part of the problem we control.

Where This Fits

This is also part of a bigger move.

Phase 3 of Labshock is done.

Phase 4 is scale, and free labs like this one are how it starts.

Zeek and Suricata are next.

Where Wazuh gives you log-based detection over industrial services, those add network-based detection over industrial traffic.

Same environment, seen from the wire instead of from the host.

OT security must be testable.

Not documented.

Try It Yourself

  • Start free: github.com/zakharb/labshock — the lab runs locally with Docker, no cloud.
  • Open the Wazuh lab at labshocksecurity.com — no license, no trial, no card.
  • Trigger one action on the OT side, find the matching event, write a rule for it, then force a fault and read your own alert.
  • Already run Wazuh in production? Test whether the rules you rely on there fire here: discord.gg/bpmaQFfW76
LABSHOCK SECURITY — OT SECURITY MUST BE TESTABLE, NOT DOCUMENTED