Wazuh is an open source security platform that collects logs and events from agents on your servers, analyses them with thousands of built-in rules, and shows alerts, vulnerability data and compliance results in a web dashboard. In this tutorial you will install the three central components (indexer, server and dashboard) on a single Ubuntu 24.04 server, enroll a Linux agent, write a custom detection rule, and enable real-time file integrity monitoring.
Prerequisites
To follow this tutorial you need:
- A server running Ubuntu 24.04 LTS for the Wazuh central components, with at least 4 CPU cores, 8 GB of RAM and 50 GB of disk, for example a CubePath VPS. This size handles up to around 100 agents with 90 days of alerts.
- One or more Linux servers to monitor. This guide uses an Ubuntu 24.04 host as the agent.
- A non-root user with
sudoprivileges on all servers. - The following ports reachable on the Wazuh server:
| Port | Protocol | Used by |
|---|---|---|
| 443 | TCP | Web dashboard |
| 1514 | TCP | Agent event traffic |
| 1515 | TCP | Agent enrollment |
The Wazuh server IP is referred to as your_server_ip in this guide.
How Wazuh is organised
A Wazuh deployment has four parts:
- Wazuh indexer: a search engine based on OpenSearch that stores alerts and events.
- Wazuh server (manager): receives agent data, decodes it and applies the rules that generate alerts.
- Wazuh dashboard: the web interface, based on OpenSearch Dashboards.
- Wazuh agents: lightweight services on each monitored host that send logs, file changes, inventory and configuration checks to the server.
For a small or medium deployment, all central components can run on the same machine, which is what the Wazuh installation assistant sets up.
Step 1 - Opening the firewall
Allow SSH, the dashboard and the agent ports on the Wazuh server:
sudo ufw allow OpenSSH
sudo ufw allow 443/tcp
sudo ufw allow 1514/tcp
sudo ufw allow 1515/tcp
sudo ufw enable
If your agents live in a known network, restrict the agent ports to it, for example sudo ufw allow from 192.168.1.0/24 to any port 1514,1515 proto tcp.
Check the rules:
sudo ufw status
Step 2 - Installing the central components
Wazuh provides an installation assistant that installs the indexer, server and dashboard, generates the TLS certificates between them and creates random passwords. Download it on the Wazuh server:
curl -sO https://packages.wazuh.com/4.x/wazuh-install.sh
Review the script before you run it:
less wazuh-install.sh
Run it with -a (all-in-one) to install every central component on this host:
sudo bash wazuh-install.sh -a
The installation takes 10 to 20 minutes. It ends by printing the dashboard credentials:
INFO: --- Summary ---
INFO: You can access the web interface https://<wazuh-dashboard-ip>:443
User: admin
Password: <ADMIN_PASSWORD>
INFO: Installation finished.
Save the admin password in your password manager. The passwords for all internal users are also stored in wazuh-install-files.tar in the current directory. To display them:
sudo tar -O -xvf wazuh-install-files.tar wazuh-install-files/wazuh-passwords.txt
This archive contains every credential and the root certificate of the deployment. Move it to a safe place and delete it from the server once you have a copy.
Verify that the three services are running:
systemctl is-active wazuh-indexer wazuh-manager wazuh-dashboard
active
active
active
Step 3 - Logging in to the dashboard
Open https://your_server_ip in your browser. The dashboard uses a self-signed certificate, so the browser shows a warning the first time; accept it to continue. Log in as admin with the password from the previous step.
The overview page shows the agent summary (empty for now) and the main modules. The Wazuh server itself does not appear as an agent in the list, but it already analyses its own logs.
TipTo avoid the certificate warning, point a DNS name at the server and replace the dashboard certificate in
/etc/wazuh-dashboard/certs/with one issued for that name, then restartwazuh-dashboard.
Step 4 - Installing an agent on a Linux server
Run the following commands on the server you want to monitor, not on the Wazuh server. First add the Wazuh signing key:
curl -fsSL https://packages.wazuh.com/key/GPG-KEY-WAZUH | sudo gpg --dearmor -o /etc/apt/keyrings/wazuh.gpg
Add the Wazuh repository:
echo "deb [signed-by=/etc/apt/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | sudo tee /etc/apt/sources.list.d/wazuh.list
Install the agent. The WAZUH_MANAGER variable writes the server address into the agent configuration during installation, and WAZUH_AGENT_NAME sets the name shown in the dashboard:
sudo apt update
sudo WAZUH_MANAGER="your_server_ip" WAZUH_AGENT_NAME="web01" apt install wazuh-agent
Enable and start the agent:
sudo systemctl daemon-reload
sudo systemctl enable --now wazuh-agent
An agent must never run a newer version than the server. Hold the package so a routine apt upgrade does not update it ahead of the server:
sudo apt-mark hold wazuh-agent
When you upgrade the Wazuh server later, run sudo apt-mark unhold wazuh-agent on the agents and upgrade them afterwards.
Step 5 - Verifying the agent connection
On the Wazuh server, list the registered agents:
sudo /var/ossec/bin/agent_control -l
Wazuh agent_control. List of available agents:
ID: 000, Name: wazuh-server (server), IP: 127.0.0.1, Active/Local
ID: 001, Name: web01, IP: any, Active
List of agentless devices:
Active means the agent enrolled and is sending events. In the dashboard, the agent appears under Agents management > Summary within a minute or two. If it stays Never connected or Disconnected, check the agent log on the monitored host:
sudo tail -n 50 /var/ossec/logs/ossec.log
Step 6 - Writing a custom rule
Wazuh already detects common events such as SSH brute-force attempts, sudo usage and package installations. You add your own detections in /var/ossec/etc/rules/local_rules.xml, which is never overwritten by upgrades. Custom rules should use IDs between 100000 and 120000.
As an example, this rule raises a high-severity alert whenever someone logs in over SSH as root. It builds on the built-in rule 5715 (successful SSH authentication) and adds a condition on the user.
On the Wazuh server, edit the local rules file:
sudo nano /var/ossec/etc/rules/local_rules.xml
Add this group at the end of the file:
<group name="local,sshd,">
<rule id="100100" level="12">
<if_sid>5715</if_sid>
<user>^root$</user>
<description>sshd: successful SSH login as root.</description>
<mitre>
<id>T1078</id>
</mitre>
</rule>
</group>
Before restarting anything, test the rule with wazuh-logtest, which runs a log line through the decoders and rules and shows which rule matches:
sudo /var/ossec/bin/wazuh-logtest
Paste this sample line and press Enter:
Sep 25 10:42:17 web01 sshd[2231]: Accepted publickey for root from 203.0.113.50 port 51422 ssh2
The last phase of the output shows your rule:
**Phase 3: Completed filtering (rules).
id: '100100'
level: '12'
description: 'sshd: successful SSH login as root.'
groups: '['local', 'sshd']'
firing: 'True'
mail: 'True'
**Alert to be generated.
Press Ctrl+C to exit, then restart the manager to load the rule:
sudo systemctl restart wazuh-manager
If the manager fails to start, sudo journalctl -u wazuh-manager -n 50 and /var/ossec/logs/ossec.log show the line with the XML error.
Step 7 - Monitoring file changes in real time
File integrity monitoring (FIM) records when files are created, modified or deleted. By default, the agent scans system directories such as /etc, /usr/bin and /usr/sbin every 12 hours. For directories where changes matter immediately, such as a web root, enable real-time monitoring.
On the agent host, open the agent configuration:
sudo nano /var/ossec/etc/ossec.conf
Find the <syscheck> section and add a directories entry inside it:
<directories realtime="yes" check_all="yes" report_changes="yes">/var/www</directories>
report_changes stores a copy of text files so that alerts include a diff of what changed. Do not use it on directories with secrets or large binaries.
Restart the agent:
sudo systemctl restart wazuh-agent
Test it by creating and modifying a file:
sudo mkdir -p /var/www
echo "test" | sudo tee /var/www/fim-test.txt
echo "changed" | sudo tee -a /var/www/fim-test.txt
In the dashboard, open File Integrity Monitoring (or Threat Hunting) and filter by the agent. Within a few seconds you see alerts for rule 554 (file added) and rule 550 (integrity checksum changed), the second one including the diff.
Step 8 - Reviewing vulnerability detection
The Wazuh server includes vulnerability detection that is enabled by default. The agents send their package inventory, and the server compares it with its vulnerability feed. Check that it is enabled on the Wazuh server:
sudo grep -A 3 '<vulnerability-detection>' /var/ossec/etc/ossec.conf
<vulnerability-detection>
<enabled>yes</enabled>
<index-status>yes</index-status>
<feed-update-interval>60m</feed-update-interval>
The first feed download and the first inventory scan take a while. After about an hour, open Vulnerability Detection in the dashboard and select your agent to see the CVEs affecting its installed packages, grouped by severity. Updating the packages on the agent (sudo apt upgrade) clears the resolved entries on the next inventory scan.
Troubleshooting
The dashboard shows Wazuh dashboard server is not ready yet. The indexer is still starting or ran out of memory. Check sudo systemctl status wazuh-indexer and sudo journalctl -u wazuh-indexer. On servers with less than 8 GB of RAM, the indexer often fails to start.
The agent stays Never connected. The agent cannot reach TCP 1514 or 1515 on the server. Test from the agent with nc -zv your_server_ip 1514, and check that <address> inside the <client><server> block of the agent's /var/ossec/etc/ossec.conf contains the right IP.
Agent version must be lower or equal to manager version. The agent is newer than the server. Upgrade the server or install the matching agent version, then hold the package as shown in step 4.
The disk fills up. Alerts and events are kept in the indexer until you delete them. Configure an index lifecycle policy under Indexer management > Index Management to delete old wazuh-alerts-* indices after the retention period you need.
Conclusion
You installed the Wazuh indexer, server and dashboard on Ubuntu 24.04, enrolled a Linux agent, created and tested a custom detection rule, and enabled real-time file integrity monitoring and vulnerability detection. Next, deploy agents to the rest of your servers, set up alert notifications by email or through an integration such as Slack, and review the Security Configuration Assessment results to harden each host.
