Wazuh indexer
The Wazuh indexer is the storage, search, and analysis component of the Wazuh platform. It stores and processes security data generated by monitored endpoints and provides the services required to detect threats, investigate security events, and manage detection content. This change makes the Wazuh indexer the central component for security analytics.
The Wazuh indexer provides the following capabilities:
Manage detection content, including rules, decoders, integrations, policies, and threat intelligence feeds.
Detects threats by evaluating events against Sigma rules and generating findings for investigation.
Store and search security data by indexing events, findings, metrics, and endpoint state information.
Support security operations through alerting, notifications, reporting, and active response orchestration.
Manage data lifecycles by automatically creating indices, rolling over data streams, and enforcing retention policies.
The Wazuh indexer includes several plugin modules that extend its functionality. The primary modules are:
Setup module which creates and manages index templates, data streams, stateful indices, and lifecycle policies.
Security Analytics module which detects threats by evaluating events against Sigma rules and generating findings.
Content Manager module which synchronizes and manages rules, decoders, integrations, policies, and threat intelligence content.
Security module which provides authentication, authorization, and role-based access control.
Reporting module which generates reports and exports from indexed security data.
Together, these modules enable the Wazuh indexer to operate as an integrated security platform.
As the Wazuh indexer ingests security data, it organizes it into data streams and stateful indices based on the type of information ingested. Index State Management (ISM) policies automatically manage rollover and retention to maintain consistent performance as data volumes grow.
You can deploy the Wazuh indexer as a single-node installation or as a multi-node cluster. Cluster deployments distribute data across multiple nodes to provide scalability, high availability, and improved performance.