SOC National ANTIC - Architecture Wazuh Cluster

AWSNetworkadvanced
SOC National ANTIC - Architecture Wazuh Cluster — AWS network diagram

About This Architecture

SOC National ANTIC deploys a distributed Wazuh cluster architecture across five security zones, with a centralized Wazuh Master managing five regional slave nodes (Telecoms, Finance, Administration, Energy, Transport) and aggregating logs into a three-node OpenSearch cluster. Data flows from diverse collection points—Wazuh agents, FortiGate firewalls, OPNsense, and Suricata/Zeek probes—through zone-specific collectors to slave nodes, then to the OpenSearch indexers for centralized storage and analysis. Analysts access the infrastructure via Apache Guacamole bastion behind FortiGate perimeter firewalls, with threat intelligence from MISP/Cortex, incident management via TheHive, and automation through Shuffle and Grafana dashboards feeding back to the Wazuh Master. This multi-zone, multi-sector design isolates critical infrastructure domains while maintaining unified visibility and response orchestration across telecommunications, financial, administrative, energy, and transport networks. Fork this diagram on Diagrams.so to customize collector endpoints, add additional slave nodes, or adapt the threat intelligence integrations for your SOC's specific operational requirements.

People also ask

How do you architect a distributed Wazuh security operations center across multiple critical infrastructure sectors with centralized threat intelligence and incident response?

SOC National ANTIC uses a five-zone architecture: a Wazuh Master node managing five regional slave nodes (Telecoms, Finance, Administration, Energy, Transport), a three-node OpenSearch cluster for log indexing, FortiGate perimeter firewalls, and integrated MISP/Cortex, TheHive, and Shuffle platforms for threat intelligence, incident management, and automated response workflows.

WazuhSOCOpenSearchAWSthreat-intelligenceincident-response
Domain:
Security
Audience:
Security operations center (SOC) architects and incident response teams managing national-scale threat detection and res

Generated by Diagrams.so — AI architecture diagram generator with native Draw.io output. Fork this diagram, remix it, or download as .drawio, PNG, or SVG.

Generate your own networkdiagram →

SOC National ANTIC - Architecture Wazuh Cluster — AWS architecture diagram

About This Architecture

SOC National ANTIC deploys a distributed Wazuh cluster architecture across five security zones, with a centralized Wazuh Master managing five regional slave nodes (Telecoms, Finance, Administration, Energy, Transport) and aggregating logs into a three-node OpenSearch cluster. Data flows from diverse collection points—Wazuh agents, FortiGate firewalls, OPNsense, and Suricata/Zeek probes—through zone-specific collectors to slave nodes, then to the OpenSearch indexers for centralized storage and analysis. Analysts access the infrastructure via Apache Guacamole bastion behind FortiGate perimeter firewalls, with threat intelligence from MISP/Cortex, incident management via TheHive, and automation through Shuffle and Grafana dashboards feeding back to the Wazuh Master. This multi-zone, multi-sector design isolates critical infrastructure domains while maintaining unified visibility and response orchestration across telecommunications, financial, administrative, energy, and transport networks. Fork this diagram on Diagrams.so to customize collector endpoints, add additional slave nodes, or adapt the threat intelligence integrations for your SOC's specific operational requirements.

People also ask

How do you architect a distributed Wazuh security operations center across multiple critical infrastructure sectors with centralized threat intelligence and incident response?

SOC National ANTIC uses a five-zone architecture: a Wazuh Master node managing five regional slave nodes (Telecoms, Finance, Administration, Energy, Transport), a three-node OpenSearch cluster for log indexing, FortiGate perimeter firewalls, and integrated MISP/Cortex, TheHive, and Shuffle platforms for threat intelligence, incident management, and automated response workflows.

SOC National ANTIC - Architecture Wazuh Cluster

AWSadvancedWazuhSOCOpenSearchthreat-intelligenceincident-response
Domain: SecurityAudience: Security operations center (SOC) architects and incident response teams managing national-scale threat detection and res
0 views0 favoritesPublic

Created by

June 19, 2026

Updated

June 19, 2026 at 2:45 PM

Type

network

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI