Wazuh (security monitoring)

An open-source SIEM and XDR in one deployment - what you get, how to connect your machines to it, and what is yours to look after.

Wazuh watches your machines. A small program on each one, the agent, reports what happens there - sign-ins, file changes, installed packages, running processes - and the server turns those reports into alerts: an intrusion attempt, a known vulnerability, a file that should not have changed.

On ISOGrid it is deployed from Security → Security tools, like a solution: pick a size, pick a network, deploy. A few minutes later the dashboard is on its own address.

What is deployed

Three containers, the versions Wazuh releases together:

Part What it does
Dashboard The web interface. The only part with a web address.
Manager Receives the agents' reports and applies the detection rules.
Indexer Stores alerts and events, and answers the dashboard's searches.

They run on one node, on a private network of their own. The indexer, which holds every alert, is reachable from nowhere else.

Three things are set up for you that the stock installation leaves to you:

  • No default password. The administrator's password is generated for your deployment, and the accounts the three parts use to sign in to each other are unique to it. The demo accounts of the stock installation do not exist.
  • Certificates. The three parts talk to each other over TLS, with certificates from an authority created for your deployment.
  • Enrollment password. A machine can only register as an agent with the password shown on the Agents tab.

Size

The smallest size offered has 4 GB of memory; the indexer uses most of it. For more than a few dozen agents, or to keep several months of events, take 8 GB or more. You can change the size later from the Size tab.

Signing in

Open the deployment, then Sign in. The user is admin; the password is on the Overview tab.

Connecting a machine

The Agents tab gives the command to run on each machine, for Debian and Ubuntu, RHEL and its relatives, Windows and macOS. It contains the manager's address, its two ports and the enrollment password, so there is nothing to fill in. The machine appears on the dashboard about a minute later.

Two addresses exist:

  • From outside the platform - your own servers, laptops, another cloud - agents connect to the address and the two ports shown on the tab. That traffic is encrypted by Wazuh itself.
  • From an application on the same private network, agents reach the manager by its internal name, on ports 1514 and 1515, without leaving the network. Choose Inside your network on the tab.

The enrollment password is used once. After that the agent holds a key of its own, and removing the agent from the dashboard revokes it.

What is yours to look after

  • Rules and configuration. The manager's configuration, rules and decoders are yours to edit, from the dashboard or from the Files tab.
  • Disk. Events accumulate. Set a retention policy in the dashboard (Indexer management → Index management) that matches the size you bought.
  • Backups. The Backups tab covers the manager's configuration: its rules, its decoders and the keys of the enrolled agents. The indexed events are not part of those backups.

If it is unpublished

Without a public address the dashboard is reachable only from your private network, and only applications on that network can report to it. Publish it again and the agents' address and ports are the same as before.