I have been working with Wazuh and the ELK stack along with Suricata on servers and intel single board computers.
I have also worked with Rasberry PI. And I can get suricata to run I can't get filebeat to compile for ARM. Now I could just
forward the syslogs to a wazuh cluster but I would rather use filebeat to ship the logs.
Now that the Raspberry PI has 4 gigs of ram It looks more attractive to deploy on small networks.