Install Wazuh components using the assisted method
All-in-one offline installation
Use the Wazuh assisted installation method to install and configure the Wazuh indexer, Wazuh manager, and Wazuh dashboard on one 64-bit (x86_64/AMD64 or AARCH64/ARM64) host.
Note
You need root user privileges to run all the commands described below.
Make sure that copies of the wazuh-install-5.0.0-rc1.sh and wazuh-offline.tar.gz files are placed in your working directory.
Install the following dependencies from your local package mirror, installation media, or copied packages (see Prerequisites) before you run the assistant on this host.
coreutils
curl
diffutils
findutils
gawk
gnupg2
grep
hostname
iproute
libcap
lsof
openssl
procps-ng
sed
tar
util-linux
adduser
apt-transport-https
curl
debconf
diffutils
gnupg
hostname
iproute2
libcap2-bin
lsof
openssl
procps
tar
util-linux
Run the following command to install all the central components on this host.
-a|--all-in-oneinstalls the Wazuh indexer, Wazuh manager, and Wazuh dashboard, and--offline-installationinstalls them fromwazuh-offline.tar.gzin the same directory as the script:# bash wazuh-install-5.0.0-rc1.sh --offline-installation -a
If Wazuh agents reach this host through an address that it doesn't have, such as a NAT address or a public DNS name, add the address with
-as, once per address. For example:# bash wazuh-install-5.0.0-rc1.sh --offline-installation -a -as 203.0.113.10 -as wazuh.example.com
After the installation completes, the output shows where the access credentials are, and a message confirming the installation was successful.
INFO: --- Summary --- INFO: You can access the web interface https://<WAZUH_DASHBOARD_ADDRESS>:443 INFO: User: admin (Wazuh dashboard login and Wazuh indexer administrator) INFO: Password: to read it from the credentials file, run: INFO: sudo grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' /etc/wazuh/credentials.env | cut -d= -f2- INFO: The other users of the deployment are listed at the top of /etc/wazuh/credentials.env. INFO: Installation finished.
Note
The assisted all-in-one installation creates the root CA on this host. Its private key,
root-ca.key, is in/etc/wazuh/ca, and the five passwords are in/etc/wazuh/credentials.env. Nowazuh-install-files.taris created. Back up/etc/wazuh/caand store the passwords before you remove/etc/wazuh/credentials.env. You need the root CA private key to add nodes and to renew certificates.Access the Wazuh web interface with your
adminuser credentials. This is the administrator account for the Wazuh indexer, and it allows you to access the Wazuh dashboard.URL:
https://<WAZUH_DASHBOARD_ADDRESS>. Replace<WAZUH_DASHBOARD_ADDRESS>with an address of this host that your browser can reach.Username:
adminPassword: the
WAZUH_INDEXER_ADMIN_PASSWORDvalue in/etc/wazuh/credentials.env. Run the following command to show it.# grep -m 1 '^WAZUH_INDEXER_ADMIN_PASSWORD=' /etc/wazuh/credentials.env | cut -d= -f2-
When you first access the Wazuh dashboard, your browser displays a warning that a trusted authority did not issue the certificate. To trust it, import
/etc/wazuh/ca/root-ca.pemfrom this host into the certificate manager of the browser, or add an exception in the advanced options of the browser. The dashboard certificate names the addresses of this host, not the addresses you add with-as.If a firewall is active on this host, allow incoming connections to 443/TCP for the Wazuh dashboard and to 1517/TCP for Wazuh 5.x agents. Wazuh 4.x agents use 1514/TCP and 1515/TCP.
Multi-node offline installation
Installing the Wazuh indexer
Install and configure the Wazuh indexer nodes on a 64-bit (x86_64/AMD64 or AARCH64/ARM64) architecture.
Install the following dependencies from your local package mirror, installation media, or copied packages (see Prerequisites) before you run the assistant on the Wazuh indexer nodes.
coreutils
curl
diffutils
gnupg2
hostname
iproute
lsof
openssl
procps-ng
tar
util-linux
adduser
curl
debconf
diffutils
gnupg
iproute2
lsof
openssl
procps
tar
Run the multi-node assisted method with the
--offline-installationoption to perform an offline installation. Use the option--wazuh-indexerand the node name to install and configure the Wazuh indexer. The node name must be the same one used inconfig.ymlin step 4 of Download the packages and configuration files, for example,indexer.# bash wazuh-install-5.0.0-rc1.sh --offline-installation --wazuh-indexer indexer
Repeat this step for every Wazuh indexer node in your cluster. Then, proceed with initializing your multi-node cluster in the next step.
Run the Wazuh installation assistant with the
--offline-installationand--start-clusteroptions on any Wazuh indexer node to load the new certificate information and start the cluster:# bash wazuh-install-5.0.0-rc1.sh --offline-installation --start-cluster
Note
You only have to initialize the cluster once; there is no need to run this command on every node.
Testing the cluster installation
Run the following command to confirm that the installation is successful. Replace
<WAZUH_INDEXER_ADDRESS>with the address of a Wazuh indexer node. Whencurlasks for the password, enter theWAZUH_INDEXER_ADMIN_PASSWORDvalue from/etc/wazuh/credentials.envon any Wazuh indexer node, or from thecredentials.envfile inwazuh-install-files.tar. Every node holds the same value.# grep -m 1 '^WAZUH_INDEXER_ADMIN_PASSWORD=' /etc/wazuh/credentials.env | cut -d= -f2- # curl -k -u admin https://<WAZUH_INDEXER_ADDRESS>:9200
The command output looks similar to this:
{ "name" : "indexer", "cluster_name" : "wazuh-cluster", "cluster_uuid" : "095jEW-oRJSFKLz5wmo5PA", "version" : { "distribution" : "opensearch", "number" : "3.6.0", ... }, "tagline" : "The OpenSearch Project: https://opensearch.org/" }Verify that the cluster is running correctly. Replace
<WAZUH_INDEXER_ADDRESS>in the following command, then execute it and enter the same password:# curl -k -u admin https://<WAZUH_INDEXER_ADDRESS>:9200/_cat/nodes?v
The output lists every Wazuh indexer node, and the node that manages the cluster has
*in thecluster_managercolumn. For example:ip heap.percent ram.percent cpu load_1m load_5m load_15m node.role node.roles cluster_manager name 10.0.0.1 37 89 9 0.27 0.24 0.18 dimr cluster_manager,data,ingest,remote_cluster_client * indexer 10.0.0.2 44 91 5 0.09 0.09 0.02 dimr cluster_manager,data,ingest,remote_cluster_client - indexer-2
Installing the Wazuh manager
Install the following dependencies from your local package mirror, installation media, or copied packages (see Prerequisites) before you run the assistant on the Wazuh manager nodes.
coreutils
curl
diffutils
findutils
gawk
gnupg2
grep
hostname
iproute
lsof
openssl
sed
tar
util-linux
apt-transport-https
curl
diffutils
gnupg
hostname
iproute2
lsof
openssl
tar
util-linux
Run the installation assistant with the
--offline-installationoption to perform an offline installation. Use the option--wazuh-managerfollowed by the node name to install the Wazuh manager. The node name must be the same one used inconfig.ymlin step 4 of Download the packages and configuration files, for example,manager.# bash wazuh-install-5.0.0-rc1.sh --offline-installation --wazuh-manager manager
Your Wazuh manager is now successfully installed. Repeat this step on every Wazuh manager node.
Installing the Wazuh dashboard
Install the following dependencies from your local package mirror, installation media, or copied packages (see Prerequisites) before you run the assistant on the Wazuh dashboard node.
curl
diffutils
gnupg2
libcap
lsof
openssl
tar
util-linux
adduser
curl
debconf
diffutils
gnupg
libcap2-bin
lsof
openssl
tar
Run the installation assistant with the
--offline-installationoption to perform an offline installation. Use the option--wazuh-dashboardand the node name to install and configure the Wazuh dashboard. The node name must be the same one used inconfig.ymlin step 4 of Download the packages and configuration files, for example,dashboard.# bash wazuh-install-5.0.0-rc1.sh --offline-installation --wazuh-dashboard dashboard
The Wazuh dashboard uses port 443. The installation assistant has no option to change it.
After the installation completes, the output shows where the access credentials are and a message that confirms that the installation was successful.
INFO: --- Summary --- INFO: You can access the web interface https://<WAZUH_DASHBOARD_ADDRESS>:443 INFO: User: admin (Wazuh dashboard login and Wazuh indexer administrator) INFO: Password: to read it from wazuh-install-files.tar, run: INFO: sudo tar -xOf wazuh-install-files.tar wazuh-install-files/credentials.env | grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' | cut -d= -f2- INFO: The other users of the deployment are listed at the top of wazuh-install-files/credentials.env of wazuh-install-files.tar. INFO: Installation finished.
You have now installed and configured Wazuh.
Access the Wazuh web interface with your
adminuser credentials. This is the administrator account for the Wazuh indexer, and it allows you to access the Wazuh dashboard.URL:
https://<WAZUH_DASHBOARD_ADDRESS>Username:
adminPassword: the
WAZUH_INDEXER_ADMIN_PASSWORDvalue. Run the command that the summary shows to read it.
When you first access the Wazuh dashboard, your browser displays a warning that a trusted authority did not issue the certificate. An exception can be added in the advanced options of the web browser. For increased security, the
root-ca.pemfile previously generated can be imported to the certificate manager of the browser instead. Alternatively, a certificate from a trusted authority can be configured. The certificate names only the Wazuh dashboard addresses inconfig.yml. To reach the dashboard by another address or a DNS name without the warning, add it to theipordnslist of the dashboard node inconfig.ymlbefore you run-g.