You run your own SIEM instead of buying a managed service because the maths worked. Licences, one engineer, a screen that stays green. That saving is real and it shows up on your P&L every month.
The exposure sits on a line nobody prints. What you are paying for is detection. What the console actually proves is ingestion. Those are two different facts, and during a real incident the first one keeps looking healthy while the second one is the only one that matters.
Here is the measurement I have. Default Wazuh build, stock rules, nothing tuned. I replayed 24 ATT&CK techniques against it (measured 01/09/2026). Three raised an alert. Discovery, collection, exfiltration and command-and-control produced nothing at all.
It is my own number and not an independent benchmark, and it carries a correction I published against myself: four of the 21 silent rows turned out to be measuring my observation window rather than the rule. Those four are marked in the data. A number that moves after someone checks it should show who moved it and why, otherwise you are being asked to trust a person instead of to read a measurement.
Raw data, host set and reproduction steps: https://github.com/xuxu298/siem-replay-24-techniques/
Run it against your own build rather than believing mine. What comes back is a number about your estate, which is the only version of this with any value to you.
The thing I do not know: for those of you running a self-hosted SIEM with no dedicated detection engineer, when someone above you asks whether you would actually see an intrusion, what do you put in front of them today?
Top comments (0)