The inventory management of USM seems to be not only based on the IP but on the MAC address. At least this is what I can see from the UI. At the same time, I'm not a big fan of the old OSSEC version used in USM as HIDS, so we decided to replace it with the OSSEC-Wazuh fork…
It is so important because it will enable you to have this single pane of glass view onto all the security-related information from your infrastructure and even beyond. Getting an idea about the big picture is really essential for everything security, so a SIEM is a right…