Read-only access. AlertWatch is a read-only visualization layer. It does not modify, create, delete, or transmit any data in your Wazuh or OpenSearch/Elasticsearch deployment. All operations are strictly read — no configuration changes, no data writes, no agent commands are issued.
Data presented as-is from your backend. AlertWatch displays only the events, alerts, and metadata that your Wazuh instance has already collected and stored. Detection gaps, misconfigured rules, disabled modules, or agents not reporting in Wazuh will appear as gaps or absences in AlertWatch. AlertWatch is not a substitute for professional security monitoring, incident response, or a fully configured SIEM. It is an analyst productivity tool layered on top of an existing Wazuh deployment.
No warranty or guarantee of completeness. Shaya Software and Systems LLC makes no warranty, express or implied, that AlertWatch will detect, surface, or alert on any specific security event, threat, or condition. The organization deploying AlertWatch retains full responsibility for the adequacy of its security posture, monitoring coverage, and incident response procedures.
Credential and deployment security. AlertWatch stores credentials for your OpenSearch and Wazuh API in a local configuration file. You are solely responsible for restricting access to that file and for the security of the host on which AlertWatch is deployed. Shaya Software and Systems LLC is not liable for any unauthorized access to your infrastructure resulting from improper deployment or credential exposure.
No telemetry. AlertWatch does not collect, transmit, or share any usage data, alert content, or personally identifiable information. All data remains within your environment.
AlertWatch is a read-only analyst interface layered on top of your Wazuh / OpenSearch deployment. It surfaces security events, timelines, compliance posture, and vulnerability data — all in one view, without touching your data.
AlertWatch never writes data, modifies Wazuh configuration, sends commands to agents, or transmits anything outside your environment. It is strictly read-only against OpenSearch.
The tab bar at the top switches the main view. The active tab is highlighted. Tabs that share context with the timeline bar (Summary, Alerts, Timelines) also show the global time window above.
The left panel changes depending on the active tab:
The Summary tab gives you a single-screen situational picture of your environment. It auto-loads when you sign in.
All three bottom cards are clickable — they navigate directly to the Compliance, Vulnerability, or Agents tab respectively.
Summary data reflects the currently selected tenant. The tenant name appears below the AlertWatch logo. Switch tenants with the selector in the top-left corner.
A full, filterable event list sourced from Wazuh. The list always reflects the active time window and any left-panel filter. Scroll to the bottom of the table to load more alerts.
Click any row to expand it. Sections appear only when data is present for that alert:
Click the checkmark icon (✓) on any alert row to acknowledge it. Add an optional note — investigation summary, ticket number, or escalation record. Acknowledged alerts show an amber checkmark visible to all analysts on the tenant. Acknowledgements are permanent audit evidence satisfying AU.3.3.1 audit log review requirements.
Expand any alert row and click + Incident to add that alert to a named incident. Incidents group related alerts into a single tracked case (e.g. all events from one intrusion attempt). Named incidents appear in the Operational report and in the CMMC Evidence Package under IR.3.6.1.
The CSV button in the table header exports the current filtered view. The file reflects the active time window, severity filter, tactic filter, and agent filter — what you see is what you get.
A visual event strip across all monitored agents. Each row is one agent. Colored ticks represent individual events. Use this view to correlate activity across your fleet and find suspicious timing patterns.
Click an agent row to pin it. Pinned agents are highlighted, and the Alerts tab filters to show only that agent's events. Press Escape or click again to unpin.
Filter by Severity (Critical / High / Medium / Low) to show only ticks of that level. The ATT&CK Tactic filter is hidden on Timelines — use Alerts for tactic-level filtering. The color legend at the bottom explains tick and severity colors.
Two capabilities in one tab: CIS benchmark results from Wazuh SCA scans, and a NIST 800-171 rule coverage matrix showing which CMMC L2 controls have active monitoring and which are gaps.
Wazuh periodically runs SCA scans on each agent, checking system settings against CIS hardening benchmarks. AlertWatch surfaces these results across your entire fleet.
Select NIST 800-171 / CMMC L2 in the left panel to open the rule coverage matrix. This maps every CMMC Level 2 control domain to the Wazuh rules that provide monitoring coverage.
Click any domain row to expand it and see the individual rules, their level, and how many times each fired. This is the artifact a C3PAO assessor expects when evaluating continuous monitoring.
The Generate Evidence Package button at the top of the left panel opens the report dialog pre-set to CMMC mode. See the Reports help section for details.
SCA data reflects the most recent scan in OpenSearch — scans run on Wazuh's configured schedule (typically daily). Rule catalog data reflects alert counts for the current time window.
Lists CVEs discovered by Wazuh's vulnerability detection module on your monitored agents.
Use the severity filter buttons at the top of the tab to narrow to Critical, High, Medium, or Low CVEs. Click any CVE link to open the NVD advisory in a new tab.
Vulnerability data comes from Wazuh's built-in detector and is limited to packages Wazuh monitors. It does not scan for web-application or network-layer vulnerabilities. Results reflect the last Wazuh vulnerability scan — not real-time.
A health dashboard for all Wazuh agents known to your deployment. Helps you identify agents that have gone silent or are running outdated versions.
Agents that have not reported any event within the "went silent" threshold (configurable in Settings → Connections) are flagged red. A completely absent agent — one that has never reported or was deleted from Wazuh — will not appear here.
File Integrity Monitoring events detected by Wazuh across your monitored endpoints. Wazuh watches configured paths and records every addition, modification, and deletion.
Select an agent name in the left panel to view only that agent's FIM events. Select All to see the full fleet.
Which paths Wazuh monitors for FIM is configured in the Wazuh agent (ossec.conf) and in AlertWatch Settings → FIM. AlertWatch cannot add or remove watch paths — that is done in the Wazuh manager configuration.
AlertWatch maps Wazuh rule levels (1–15) to four severity tiers. The same color scheme is used everywhere — badges, timeline ticks, charts, and filters.
When viewing the Timelines tab with All selected, tick colors indicate the attack phase Wazuh attributed to the event (Brute Force, Lateral Movement, FIM, etc.). When a Severity filter is active, tick colors switch to the severity palette above.
The blue bar above the main content area is the global time window. It applies to the Alerts, Timelines, and Summary tabs simultaneously.
The track shows a compressed view of your entire data range. The blue rectangle is the viewport — it shows which slice of time is currently visible in the detail views. Drag the rectangle to pan.
The dropdown between the arrows sets how much time fits in one screen — from 1 hour to 30 days. Narrowing the window shows more detail; widening it shows the big picture.
When Live is on, AlertWatch auto-refreshes every 60 seconds and keeps the viewport anchored to "now". The left panel filter nav is frozen while Live is active to prevent conflicting updates.
Manually triggers a full reload of alerts and timeline data for the current time window. The "updated X ago" badge next to the refresh button shows when the last load completed.
AlertWatch generates two report types from the same dialog. Open it with the Report button in the top bar, or click Generate Evidence Package in the Compliance & Rules left panel.
A summary of security activity for a defined period — useful for weekly team reviews, management briefings, and incident handoffs.
The report renders as a styled HTML document you can print or save as PDF from your browser.
An audit-ready HTML document covering six NIST 800-171 / CMMC Level 2 control families. Each section documents what was monitored, what was detected, and what analyst actions were taken — in the format a C3PAO assessor expects.
Enter your organization name at the top of the dialog before generating. The package includes a cover page with an analyst attestation statement.
Configure automatic email delivery of the Operational report (daily / weekly / monthly) in Settings → Notifications → Scheduled Reports. Requires SMTP configured in Settings → Connections.
This end-user license agreement governs the use of the AlertWatch™ software and does not transfer any ownership interest to the user, which is retained by Shaya Software and Systems LLC (hereinafter "Shaya"). AlertWatch is the intellectual property of Shaya. By digitally signing this agreement, the person signing this agreement (hereinafter "User") agrees to the following conditions of use.
User agrees not to copy, adapt, transfer, display, amend, modify, or distribute, or reverse engineer the software; not to assign, sublicense, or transfer the right to use the software to a third party; not to lease, rent, or publish the software; and not to use the software to create competing software.
AlertWatch is a read-only visualization layer. It does not modify, create, delete, or transmit any data in your Wazuh or OpenSearch/Elasticsearch deployment. All operations are strictly read with no configuration changes, no data writes, and no agent commands are issued.
AlertWatch displays only the events, alerts, and metadata that User's Wazuh instance has already collected and stored. Detection gaps, misconfigured rules, disabled modules, or agents not reporting in Wazuh will appear as gaps or absences in AlertWatch. AlertWatch is not a substitute for professional security monitoring, incident response, or a fully configured Security Information and Event Management (SIEM). It is an analyst productivity tool layered on top of an existing Wazuh deployment.
Shaya makes no warranty, express or implied, of any kind. Shaya does not guarantee that AlertWatch will detect, surface, or alert on any specific security event, threat, or condition. The User deploying AlertWatch retains full responsibility for the adequacy of its security posture, monitoring coverage, and incident response procedures.
User's sole remedy for alleged damages is limited to User's termination of use and refund of payments made. Shaya specifically disclaims consequential damages of any kind as a result of use of AlertWatch unless deemed unconscionable by a Court of Law having jurisdiction in Massachusetts.
AlertWatch is not designed, manufactured, or intended for use in the operation of nuclear facilities, aircraft navigation or communication systems, air traffic control, weapons systems, direct life-support machines, or any other application in which failure of AlertWatch could lead directly to death, personal injury, or severe physical, property, or environmental damage. Shaya expressly disclaims any warranty, express or implied, with respect to any such use.
AlertWatch stores connection credentials for User's OpenSearch and Wazuh API in a local
configuration file (alertwatch.yaml) on the host where AlertWatch is deployed.
User is solely responsible for: (a) restricting file-system access to that configuration file
to authorized administrators only; (b) the network exposure, patching, and general security
hardening of the host on which AlertWatch runs; (c) not copying, transmitting, or storing that
configuration file outside of User's own controlled infrastructure; and (d) the confidentiality
of any credentials contained within it. Shaya has no access to, visibility into, or control
over these credentials once deployed, and is not liable for any unauthorized access to User's
infrastructure resulting from improper deployment, inadequate access controls, or credential
exposure on User's systems.
AlertWatch supports authenticating AlertWatch user logins against User's own LDAP or Active Directory instead of storing user passwords locally. Where available, Shaya encourages User to use its organization's LDAP/Active Directory for user authentication rather than AlertWatch's local file-based user store, so that user credentials are managed and secured by User's existing identity infrastructure rather than persisted by AlertWatch.
AlertWatch does not collect, transmit, or share any usage data, alert content, or personally identifiable information. All data remains within your environment.
This Agreement shall be governed by the laws of the Commonwealth of Massachusetts. User consents to the exclusive jurisdiction and venue of the state and federal courts located in the Commonwealth of Massachusetts for any dispute arising under or relating to this Agreement.
AlertWatch is licensed on an annual subscription basis. This Agreement is effective upon acceptance and continues for an initial term of one (1) year from the date the applicable license fee is paid (the "Subscription Term"), unless earlier terminated as provided below. Upon expiration of the then-current Subscription Term, this Agreement renews automatically for successive one (1) year terms unless either party provides written notice of non-renewal at least thirty (30) days prior to the end of the then-current term, or User does not pay the applicable renewal fee. Continued use of AlertWatch beyond the end of a paid Subscription Term is not authorized.
Either party may terminate this Agreement upon written notice to the other. Shaya may terminate this Agreement immediately upon notice if User materially breaches any provision of this Agreement — including the License Restrictions above — and fails to cure such breach within thirty (30) days of written notice specifying the breach. Upon termination or expiration, User shall immediately cease all use of AlertWatch and destroy or return all copies of the software in User's possession. Fees already paid are non-refundable upon termination for User's breach.
Shaya shall defend User against any third-party claim alleging that AlertWatch, as provided by Shaya and used in accordance with this Agreement, infringes a United States patent, copyright, or trade secret, and shall indemnify User for damages finally awarded against User as a result, provided User promptly notifies Shaya in writing of the claim and allows Shaya sole control of Shaya's defense and settlement. Shaya has no obligation for claims arising from (a) modifications to AlertWatch not made by Shaya, (b) use of AlertWatch in combination with other software or systems not provided by Shaya, or (c) use outside the scope of this Agreement.
User shall indemnify and hold Shaya harmless from any claim, damage, or expense (including reasonable attorneys' fees) arising from User's breach of this Agreement, misuse of AlertWatch, or User's handling of its own infrastructure, credentials, or data.
User represents that it will comply with all applicable U.S. export control and economic sanctions laws and regulations, including the Export Administration Regulations and regulations administered by the U.S. Department of the Treasury's Office of Foreign Assets Control, in connection with its use of AlertWatch.
User further represents that it, and its employees, officers, directors, and agents, will not directly or indirectly offer, pay, promise to pay, or authorize the payment of anything of value to any government official or other person for the purpose of improperly influencing any act or decision in connection with this Agreement or User's use of AlertWatch, in violation of the U.S. Foreign Corrupt Practices Act or any other applicable anti-corruption law.
Severability. If any provision of this
Agreement is held unenforceable, the remaining provisions shall remain in full effect.
Assignment. User may not assign this
Agreement without Shaya's prior written consent. Shaya may assign this Agreement in connection
with a merger, acquisition, or sale of substantially all of Shaya's assets.
Force Majeure. Neither party is liable for
delays or failures caused by circumstances beyond its reasonable control.
Waiver. No failure to enforce any provision
of this Agreement waives the right to enforce it later.
Entire Agreement / Amendment. This Agreement
is the entire understanding between the parties on this subject and may only be modified in
writing signed by both parties.
By use of AlertWatch, User acknowledges and agrees that:
AlertWatch is a read-only tool. User organization retains full responsibility for security monitoring completeness and incident response. Shaya provides this software without warranty of any kind.