Requirements
Before deploying Wazuh with Ansible, ensure your environment meets the following requirements.
Control node requirements
The control node is the endpoint where you install Ansible and run the playbooks. The control node must meet the following requirements before you proceed with the deployment:
Ansible is installed and configured: Install
ansible-coreversion 2.16 or later. This document was tested onansible-core2.16. Verify the installed version with the command,ansible --version. Ensure the version is compatible with the operating systems of your target endpoints. Therequirements.ymlfile does not pin collection versions, soansible-galaxyinstalls the latest release of each one. When a release requires a neweransible-corethan yours,ansible-galaxyandansible-playbookcan print a warning such asCollection community.general does not support Ansible version 2.16.19, and continue.Python is installed: Install Python 3.10 or later. Verify the version with the command,
python3 --version.Inventory file is configured: Create and configure the
/etc/ansible/hostsfile that defines your target endpoints and connection variables. You can verify connectivity withansible <HOST_OR_GROUP> -m pingfor Linux and macOS endpoints, and withansible <HOST_OR_GROUP> -m win_pingfor Windows endpoints. Replace<HOST_OR_GROUP>with a host or group from your inventory. Each module works only on its own operating system.Git is installed: Required to clone the
wazuh-ansiblerepository.OpenSSL is installed: The playbooks run
opensslon the control node to read the certificates and to generate the cluster key.Root privileges: Run the commands and playbooks of this guide as root (or with
sudo).SSH key access: The control node logs in to every Linux and macOS target with an SSH key, as a user with
sudoprivileges.
Target node requirements
Target nodes are the endpoints where Wazuh components will be installed. Your endpoints must meet the following requirements before you deploy Wazuh:
Ansible version compatibility: Ensure the Ansible version installed on the control node is compatible with the target endpoints on which Wazuh components will be installed.
Python is installed on Linux endpoints: Install Python 3.10 or later on all Linux endpoints. Ansible requires Python on managed Linux endpoints.
Private network DNS: If you use hostnames instead of IP addresses for endpoints, configure a DNS server. Ensure it resolves the FQDN of your endpoints. Otherwise, use the hosts file.
SSH Access to Linux endpoints: By default, Ansible connects to Linux endpoints on TCP port 22. Ensure that this port is open on all managed hosts and any intermediate firewalls. If Ansible is configured to use a different port, verify that the corresponding port is also opened and accessible.
Windows Remote Management (WinRM) access to Windows endpoints: A WinRM listener over HTTPS is configured and running on port 5986 of the Windows endpoints. An HTTPS listener requires a server authentication certificate. Ansible connects over WinRM only to hosts whose inventory entry sets
ansible_connection=winrm, and it needs thepywinrmPython package on the control node.Required open ports: Refer to the Required ports section for details about the network ports used by the Wazuh components for communication.
Hardware requirements: Ensure that each endpoint meets the hardware requirements for the Wazuh component being installed. Refer to the documentation for Wazuh indexer, Wazuh manager, Wazuh dashboard, or Wazuh agent for detailed hardware specifications.