Hello,
Wazuh uses signature-based approach for threat detection, however, it can be integrated to Elastic Stack machine learning.
The machine learning engine can automatically analyze large datasets, allowing for the detection of intrusions that otherwise would have gone undetected. It as well helps reduce the noise from numerous alerts generated by automatically identifying unusual behaviors.
You can use machine learning with Wazuh by creating machine learning jobs. This
link shows how to create a machine learning job on Elastic using Wazuh to detect malicious actors.
To deploy Wazuh with Elastic Stack follow
here.
Regards,