• Blog
  • Documentation
  • Contact us
Wazuh
  • Platform
    • Overview
    • XDR
    • SIEM
  • Cloud
  • CTI
  • Services
    • Professional support
    • Consulting services
    • Training courses
  • Partners
    • Become a partner
    • Find a partner
  • Company
    • Customers
    • About us
    • Our team
    • Resources
  • Community
    • Overview
    • Ambassadors
    • Events
    Search now!
    • Getting started
      • Components
        • Wazuh indexer
        • Wazuh manager
        • Wazuh dashboard
        • Wazuh agent
      • Architecture
    • Quickstart
    • Installation guide
      • Wazuh indexer
        • Assisted installation
        • Step-by-step installation
      • Wazuh manager
        • Assisted installation
        • Step-by-step installation
      • Wazuh dashboard
        • Assisted installation
        • Step-by-step installation
      • Wazuh agent
        • Linux
        • Windows
        • macOS
      • Packages list
      • Uninstalling Wazuh
        • Uninstalling the Wazuh agent
        • Uninstalling the Wazuh central components
    • Installation alternatives
      • Virtual machine (VM)
      • Deployment on Docker
        • Wazuh Docker deployment
        • Building Docker images locally
        • Wazuh Docker utilities
        • Upgrading the Wazuh Docker deployment
        • Uninstalling the Wazuh Docker deployment
      • Deployment on Kubernetes
        • Wazuh Kubernetes architecture
        • Deployment
        • Changing the password of Wazuh users
        • Clean Up
      • Offline installation guide
        • Install Wazuh components using the assisted method
        • Install Wazuh components step by step
      • Deployment with Ansible
        • Requirements
        • Deploying Wazuh
        • Roles
        • Variables references
    • User manual
      • Wazuh agent
        • Wazuh agent enrollment
          • Requirements
          • Wazuh agent life cycle
          • Enrollment methods
            • Enrollment through agent configuration
              • Linux/Unix
              • Windows
              • macOS
            • Enrollment through the Wazuh manager API
              • Request the client key
              • Importing the client key to the Wazuh agent
          • Additional security options
            • Enroll Wazuh agents with password authentication
            • Wazuh manager identity verification
            • Wazuh agent identity verification
          • Troubleshooting
        • Wazuh agent connection
        • Wazuh agent administration
          • Query the Wazuh agent configuration
          • Group agents
          • List agents
          • Anti-tampering
          • Remove agents
          • Upgrade agents remotely
      • Wazuh dashboard
        • Navigating the Wazuh dashboard
        • Wazuh dashboard configurations
        • Querying security information on the Wazuh dashboard
        • Certificates deployment
          • Configuring third-party SSL certificates
            • Configuring SSL certificates on the Wazuh dashboard using Let’s Encrypt
            • Configuring SSL certificates on the Wazuh dashboard using NGINX
        • Setting up custom branding
        • Troubleshooting
      • Wazuh manager
        • Wazuh manager architecture
        • Wazuh normalization engine
        • Wazuh indexer connector
        • Wazuh manager services
        • Logging
        • Reference
      • Data analysis
        • Data analysis components
          • Content management
          • Space
          • Integration
          • Events
          • Filters
          • Decoders
          • Key-Value Databases (KVDBs)
          • Enrichment
          • Rules
          • Detectors
          • Findings
        • Create a security analytics detection workflow
      • User administration
        • Password management
        • Wazuh RBAC - How to create and map internal users
        • Single Sign-On
          • Okta
          • Microsoft Entra ID
          • PingOne
          • Google Workspace
          • JumpCloud
          • OneLogin
          • Keycloak
          • authentik
        • Active Directory and LDAP integration
      • Capabilities
        • File integrity monitoring
          • How it works
          • Configuration
          • Interpreting FIM scans
          • Basic configuration options
          • Creating custom FIM rules
          • Advanced configuration options
          • Use cases
            • Detect malware persistence technique
            • Detect account manipulation
            • Monitor files at specific intervals
            • Report file changes
            • Monitor configuration changes
          • Windows Registry monitoring
        • Security Configuration Assessment
          • How it works
          • Configuration
          • Available SCA policies
          • Use cases
        • Active response
          • How it works
          • Types of active response
          • Configuration
          • Default active response scripts
          • Custom active response scripts
            • Python active response script sample
          • Migrating active response scripts from Wazuh 4.x to Wazuh 5.x
          • Use cases
            • Blocking web attacks with active response
            • Removing a malicious file with active response
        • Log data collection
          • How log data collection works
          • Configuring log collection
            • Collecting logs from a file
            • Collecting logs from operating systems
          • Log data analysis
          • Use cases
        • Vulnerability detection
          • How it works
          • Configuration
          • Use cases
        • Command monitoring
          • How it works
          • Requirements
          • Configuration
          • Security considerations
          • Use cases
            • Monitoring running processes
            • Monitoring disk space utilization
        • Container security
          • Using Wazuh to monitor Docker
          • Use case
        • System inventory
          • How it works
          • Configuration
          • Viewing system inventory data
          • Generating system inventory reports
          • Available inventory fields
          • Syscollector information findings
          • Use cases
          • Compatibility matrix
        • Monitoring Linux system calls
          • How it works
          • Configuration
          • Use cases
            • Detect when the Audit daemon stops
            • Detect when the Audit daemon starts
            • Detect abnormal process termination
            • Detect a network interface entering promiscuous mode
      • Reference
        • Wazuh manager local configuration (wazuh-manager.conf)
          • global
          • logging
          • remote
          • auth
          • indexer
          • vulnerability-detection
          • agent-upgrade
          • task-manager
          • wdb
          • cluster
        • Wazuh agent local configuration (ossec.conf)
          • active-response
          • agent-upgrade
          • anti_tampering
          • client
          • client_buffer
          • github
          • labels
          • localfile
          • logging
          • ms-graph
          • office365
          • rootcheck
          • sca
          • socket
          • syscheck
          • wodle name="aws-s3"
          • wodle name="azure-logs"
          • wodle name="command"
          • wodle name="docker-listener"
          • wodle name="syscollector"
          • gcp-pubsub
          • gcp-bucket
        • Centralized configuration for Wazuh agents
        • Internal configuration
        • Daemons
          • wazuh-manager-analysisd
          • wazuh-manager-apid
          • wazuh-manager-authd
          • wazuh-manager-clusterd
          • wazuh-manager-db
          • wazuh-manager-modulesd
          • wazuh-manager-monitord
          • wazuh-manager-remoted
          • wazuh-agentd
          • wazuh-execd
          • wazuh-logcollector
          • wazuh-modulesd
          • wazuh-syscheckd
        • Tools
          • agent_groups
          • agent_upgrade
          • cluster_control
          • rbac_control
          • verify-agent-conf
          • wazuh-control
          • wazuh-manager-control
          • wazuh-manager-keystore
        • Installation utilities
          • Wazuh Installation Assistant
          • Wazuh certs tool
      • Wazuh manager API reference
      • Wazuh indexer API reference
    • Wazuh CTI
      • How it works
      • Managing Wazuh CTI
      • Troubleshooting Wazuh CTI
    • Cloud security
      • Monitoring GitHub
        • Monitoring GitHub audit logs
      • Monitoring Office 365
        • Monitoring Office 365 audit logs
    • Regulatory compliance
      • Using Wazuh for PCI DSS compliance
        • Log data analysis
        • Configuration assessment
        • Malware detection
        • File integrity monitoring
        • Vulnerability detection
        • Active response
        • System inventory
      • Using Wazuh for GDPR compliance
        • GDPR II, Principles
        • GDPR III, Rights of the data subject
        • GDPR IV, Controller and processor
      • Using Wazuh for TSC compliance
        • Common Criteria 2.1 (COSO Principle 13)
        • Common Criteria 3.1 (COSO Principle 6)
        • Common criteria 5.1 (COSO Principle 10)
        • Common criteria 6.1
        • Common criteria 7.1
        • Common criteria 8.1
        • TSC additional criteria
          • Availability - A1.1
          • Processing integrity - PI1.4
    • Proof of Concept guide
      • File integrity monitoring
      • Vulnerability detection
      • Security configuration assessment
      • Monitoring Docker events
      • Detecting an SQL injection attack
      • Detecting a Cross-Site Scripting (XSS) attack
      • Monitoring AWS infrastructure
      • Network IDS integration
      • Detecting hidden processes
      • Blocking a known malicious actor
    • Migration guide
      • Migration planning
      • Wazuh indexer
      • Wazuh manager
      • Wazuh dashboard
      • Wazuh agents
    Attention This documentation covers an upcoming release that is still under development. For the current stable documentation, check out the latest version.
    Explore
    • Overview
    • XDR
    • SIEM
    Services
    • Wazuh Cloud
    • Professional support
    • Consulting services
    • Training courses
    Company
    • About us
    • Customers
    • Partners
    Documentation
    • Quickstart
    • Getting started
    • Installation guide
    Resources
    • Blog
    • Community
    • Legal
    © 2026 Wazuh Inc.
    Contact us
    +1 (844) 349 2984
    • X
    • LinkedIn
    • Reddit
    • GitHub
    • Discord
    • Slack
    • Mailing list