Multi-Tenant Wazuh Dashboard for MSSPs
Give every client their own Wazuh dashboard, with their logo and only their data
Running Wazuh for several clients? Then you know the problem. The built-in dashboard shows everything to everyone. So you either give clients a shared login and hope they don't look around, or you paste screenshots into a monthly PDF nobody reads.
Neetrox sits on top of the Wazuh you already run. It is read-only and changes nothing in your SIEM. Each client gets a clean, isolated login to their own SOC dashboard.
What your clients get
Only their data. Every query is scoped on the server from the signed session, never from the browser. A client can't reach another client's data, whatever they send to the API.
Their logo. Upload each client's logo in the admin panel. When they sign in, they see their own logo and name at the top of their dashboard, not your tooling.
Live panels. 17 panels, including alerts, MITRE ATT&CK, compliance, vulnerabilities and a geolocation map, with 24-hour, 7-day and 30-day views.
Honest status. Freshness times and a "stale" badge when data is late. If a module is off, the panel says so instead of showing a broken chart.
What you control
One manager or many. Put clients on agent groups of a shared Wazuh manager, or give each client their own manager. Mix both in one install. Add managers in the admin panel and check each one with a single "Test connection" click. Passwords are stored encrypted.
You pick the panels. New clients start with zero panels. You grant each one. Least privilege by default.
Fast onboarding. Creating a client starts data collection right away, so their panels usually fill within minutes.
How it works
- Fill in one .env file with your secrets and admin login.
- Run docker compose up. The database, worker, API and dashboard start together.
- In the admin panel, add your Wazuh managers, create your clients, choose their panels and create their logins.
Video Demo
What you get
- Full source code (TypeScript ingest worker, Fastify API, React dashboard, Postgres schema)
- One docker-compose.yml deployment: self-hosted, no vendor lock-in, no per-seat fees
- Setup and upgrade guides, plus sample data for an instant demo
- Unlimited clients on your own infrastructure
- 12 months of updates
- Email support
Who it's for
- MSSPs running Wazuh for several clients
- Teams that give each customer their own Wazuh manager
- Anyone who has outgrown a shared OpenSearch login for client reports
Requirements
- Docker and Docker Compose
- Wazuh 4.x
- Wazuh Indexer
- Wazuh Manager access
Need help?
Want help deploying or customizing it for your business? Get deployment & customization