Instructions to use kholil-lil/wazuh-model with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use kholil-lil/wazuh-model with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("text-generation", model="kholil-lil/wazuh-model") messages = [ {"role": "user", "content": "Who are you?"}, ] pipe(messages)# Load model directly from transformers import AutoTokenizer, AutoModelForCausalLM tokenizer = AutoTokenizer.from_pretrained("kholil-lil/wazuh-model") model = AutoModelForCausalLM.from_pretrained("kholil-lil/wazuh-model", device_map="auto") messages = [ {"role": "user", "content": "Who are you?"}, ] inputs = tokenizer.apply_chat_template( messages, add_generation_prompt=True, tokenize=True, return_dict=True, return_tensors="pt", ).to(model.device) outputs = model.generate(**inputs, max_new_tokens=40) print(tokenizer.decode(outputs[0][inputs["input_ids"].shape[-1]:])) - Inference
- Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- llama.cpp
How to use kholil-lil/wazuh-model with llama.cpp:
Install (macOS, Linux)
curl -LsSf https://llama.app/install.sh | sh # Start a local OpenAI-compatible server with a web UI: llama serve -hf kholil-lil/wazuh-model:Q8_0 # Run inference directly in the terminal: llama cli -hf kholil-lil/wazuh-model:Q8_0
Install from WinGet (Windows)
winget install llama.cpp # Start a local OpenAI-compatible server with a web UI: llama serve -hf kholil-lil/wazuh-model:Q8_0 # Run inference directly in the terminal: llama cli -hf kholil-lil/wazuh-model:Q8_0
Use pre-built binary
# Download pre-built binary from: # https://github.com/ggerganov/llama.cpp/releases # Start a local OpenAI-compatible server with a web UI: ./llama-server -hf kholil-lil/wazuh-model:Q8_0 # Run inference directly in the terminal: ./llama-cli -hf kholil-lil/wazuh-model:Q8_0
Build from source code
git clone https://github.com/ggerganov/llama.cpp.git cd llama.cpp cmake -B build cmake --build build -j --target llama-server llama-cli # Start a local OpenAI-compatible server with a web UI: ./build/bin/llama-server -hf kholil-lil/wazuh-model:Q8_0 # Run inference directly in the terminal: ./build/bin/llama-cli -hf kholil-lil/wazuh-model:Q8_0
Use Docker
docker model run hf.co/kholil-lil/wazuh-model:Q8_0
- LM Studio
- Jan
- vLLM
How to use kholil-lil/wazuh-model with vLLM:
Install from pip and serve model
# Install vLLM from pip: pip install vllm # Start the vLLM server: vllm serve "kholil-lil/wazuh-model" # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:8000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "kholil-lil/wazuh-model", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker
docker model run hf.co/kholil-lil/wazuh-model:Q8_0
- SGLang
How to use kholil-lil/wazuh-model with SGLang:
Install from pip and serve model
# Install SGLang from pip: pip install sglang # Start the SGLang server: python3 -m sglang.launch_server \ --model-path "kholil-lil/wazuh-model" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "kholil-lil/wazuh-model", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker images
docker run --gpus all \ --shm-size 32g \ -p 30000:30000 \ -v ~/.cache/huggingface:/root/.cache/huggingface \ --env "HF_TOKEN=<secret>" \ --ipc=host \ lmsysorg/sglang:latest \ python3 -m sglang.launch_server \ --model-path "kholil-lil/wazuh-model" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "kholil-lil/wazuh-model", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }' - Ollama
How to use kholil-lil/wazuh-model with Ollama:
ollama run hf.co/kholil-lil/wazuh-model:Q8_0
- Unsloth Studio
How to use kholil-lil/wazuh-model with Unsloth Studio:
Install Unsloth Studio (macOS, Linux, WSL)
curl -fsSL https://unsloth.ai/install.sh | sh # Run unsloth studio unsloth studio -H 0.0.0.0 -p 8888 # Then open http://localhost:8888 in your browser # Search for kholil-lil/wazuh-model to start chatting
Install Unsloth Studio (Windows)
irm https://unsloth.ai/install.ps1 | iex # Run unsloth studio unsloth studio -H 0.0.0.0 -p 8888 # Then open http://localhost:8888 in your browser # Search for kholil-lil/wazuh-model to start chatting
Using HuggingFace Spaces for Unsloth
# No setup required # Open https://huggingface.co/spaces/unsloth/studio in your browser # Search for kholil-lil/wazuh-model to start chatting
- Pi
How to use kholil-lil/wazuh-model with Pi:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf kholil-lil/wazuh-model:Q8_0
Configure the model in Pi
# Install Pi: npm install -g @mariozechner/pi-coding-agent # Add to ~/.pi/agent/models.json: { "providers": { "llama-cpp": { "baseUrl": "http://localhost:8080/v1", "api": "openai-completions", "apiKey": "none", "models": [ { "id": "kholil-lil/wazuh-model:Q8_0" } ] } } }Run Pi
# Start Pi in your project directory: pi
- OpenClaw new
How to use kholil-lil/wazuh-model with OpenClaw:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf kholil-lil/wazuh-model:Q8_0
Configure OpenClaw
# Install OpenClaw: npm install -g openclaw@latest # Register the local server and set it as the default model: openclaw onboard --non-interactive --mode local \ --auth-choice custom-api-key \ --custom-base-url http://127.0.0.1:8080/v1 \ --custom-model-id "kholil-lil/wazuh-model:Q8_0" \ --custom-provider-id llama-cpp \ --custom-compatibility openai \ --custom-text-input \ --accept-risk \ --skip-health
Run OpenClaw
openclaw agent --local --agent main --message "Hello from Hugging Face"
- Docker Model Runner
How to use kholil-lil/wazuh-model with Docker Model Runner:
docker model run hf.co/kholil-lil/wazuh-model:Q8_0
- Lemonade
How to use kholil-lil/wazuh-model with Lemonade:
Pull the model
# Download Lemonade from https://lemonade-server.ai/ lemonade pull kholil-lil/wazuh-model:Q8_0
Run and chat with the model
lemonade run user.wazuh-model-Q8_0
List all available models
lemonade list
- Hermes Agent
How to use kholil-lil/wazuh-model with Hermes Agent:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf kholil-lil/wazuh-model:Q8_0
Configure Hermes
# Install Hermes: curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash hermes setup # Point Hermes at the local server: hermes config set model.provider custom hermes config set model.base_url http://127.0.0.1:8080/v1 hermes config set model.default kholil-lil/wazuh-model:Q8_0
Run Hermes
hermes
- Atomic Chat
Serious and urgent question to ask
Hello Ayesha,
can you drop some example of your wazuh logs? the true positive flag will appear when your wazuh alert level >= 5.
Hello,
Model also repond as true positive when alert severity level is less than 5 even I set temperature at 0.1 after locally deploy that model. Actually it shows every alert as a true positive : (
how you ingest wazuh log to the model?
Using the Wazuh API, we retrieved alerts and sent each alert individually to the model for analysis, processing one request at a time as true positive and false positive alert.
did you give the model prompt when ingest each alert? or you just pass it?
We gave model prompt when ingest each alert.
hmhm...interesting, can you share the screenshot or result of the model? include the prompt. I want understand more about this problem, so i can help you solve this. I has been used this model on production and so far the model successfully flag the alert correctly.
are you still using this model on production? The prompt I used is given below and I am also attaching low severity alerts classification in the below image.
first used the below prompt:
#"You are an expert cybersecurity analyst integrated into a Security Operations Center (SOC). "
"Classify the following Wazuh alert as a true positive or false positive. "
"Respond only with 'True Positive' or 'False Positive'.\n\n"
f"{alert_json}\n"
when every classified alert returned as true positive then prompt refined as below:
"You are an expert cybersecurity analyst in a SOC.\n"
"Use the Wazuh rule level as a key signal:\n"
" - Rule level 0-6 : likely routine/informational β lean False Positive\n"
" - Rule level 7-11 : moderate threat β consider context carefully\n"
" - Rule level 12-14 : high severity β lean True Positive\n"
" - Rule level 15+ : critical severity β lean True Positive\n\n"
f"Alert severity : {severity}\n"
f"Rule level : {rule_level}\n\n"
"Full alert JSON:\n"
f"{alert_json}\n\n"
"Classify this alert. Respond only with 'True Positive' or 'False Positive'."
Still alert classification is true positive even for low priority alerts.

