Wazuh
Getting started with Wazuh
Wazuh is a free and open source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments.
Wazuh helps organizations and individuals to protect their data assets against security threats. It is widely used by thousands of organizations worldwide, from small businesses to large enterprises.
Installation
Container Setup
- Create a new Ubuntu LXC
- Name: wazuh
- CPU: 4 cores
- Storage: 55 GB
- Memory: 8200 MB
- Swap: 4100 MB
- Network:
static
- Update the container
- Install Dependencies
- Install the GPG key
- Download and run the Wazuh installation script
Password Missed?
If the interface lost connection and you didn't see the password, you can run:
Firewall Configuration
From Wazuh Docs we must port forward or open the following ports:
- 1514 (TCP) for agent connection
- 1515 (TCP) for agent enrollment service