Wazuh (security monitoring)
An open-source SIEM and XDR in one deployment - what you get, how to connect your machines to it, and what is yours to look after.
Wazuh watches your machines. A small program on each one, the agent, reports what happens there - sign-ins, file changes, installed packages, running processes - and the server turns those reports into alerts: an intrusion attempt, a known vulnerability, a file that should not have changed.
On ISOGrid it is deployed from Security → Security tools, like a solution: pick a size, pick a network, deploy. A few minutes later the dashboard is on its own address.
What is deployed
Three containers, the versions Wazuh releases together:
| Part | What it does |
|---|---|
| Dashboard | The web interface. The only part with a web address. |
| Manager | Receives the agents' reports and applies the detection rules. |
| Indexer | Stores alerts and events, and answers the dashboard's searches. |
They run on one node, on a private network of their own. The indexer, which holds every alert, is reachable from nowhere else.
Three things are set up for you that the stock installation leaves to you:
- No default password. The administrator's password is generated for your deployment, and the accounts the three parts use to sign in to each other are unique to it. The demo accounts of the stock installation do not exist.
- Certificates. The three parts talk to each other over TLS, with certificates from an authority created for your deployment.
- Enrollment password. A machine can only register as an agent with the password shown on the Agents tab.
Size
The smallest size offered has 4 GB of memory; the indexer uses most of it. For more than a few dozen agents, or to keep several months of events, take 8 GB or more. You can change the size later from the Size tab.
Signing in
Open the deployment, then Sign in. The user is admin; the password is on
the Overview tab.
Connecting a machine
The Agents tab gives the command to run on each machine, for Debian and Ubuntu, RHEL and its relatives, Windows and macOS. It contains the manager's address, its two ports and the enrollment password, so there is nothing to fill in. The machine appears on the dashboard about a minute later.
Two addresses exist:
- From outside the platform - your own servers, laptops, another cloud - agents connect to the address and the two ports shown on the tab. That traffic is encrypted by Wazuh itself.
- From an application on the same private network, agents reach the manager by its internal name, on ports 1514 and 1515, without leaving the network. Choose Inside your network on the tab.
The enrollment password is used once. After that the agent holds a key of its own, and removing the agent from the dashboard revokes it.
What is yours to look after
- Rules and configuration. The manager's configuration, rules and decoders are yours to edit, from the dashboard or from the Files tab.
- Disk. Events accumulate. Set a retention policy in the dashboard (Indexer management → Index management) that matches the size you bought.
- Backups. The Backups tab covers the manager's configuration: its rules, its decoders and the keys of the enrolled agents. The indexed events are not part of those backups.
If it is unpublished
Without a public address the dashboard is reachable only from your private network, and only applications on that network can report to it. Publish it again and the agents' address and ports are the same as before.