Running Wazuh offline
The Wazuh manager loads its ruleset, its vulnerability feed, and its GeoIP databases from snapshots included in the packages, so detection works without an Internet connection. Loading takes longest on the first start after the installation, and its time depends on the host. Run the following command on a Wazuh manager node to check its progress:
# grep -E 'Event processing is now active|CVE feed fully loaded' /var/wazuh-manager/logs/wazuh-manager.log
The Wazuh manager discards incoming events until it logs
Event processing is now active. In tests, this took up to about 4 minutes on the first start, and a few seconds after a restart.Vulnerability detection starts when the Wazuh manager logs
CVE feed fully loaded. In tests, the first load took from about 6 to about 18 minutes. If the Wazuh manager restarts before the first load completes, the load starts over. After that, the Wazuh manager logsCVE feed fully loadedwithin seconds of a restart.The Wazuh manager tries to download a GeoIP manifest after each start and then about every 7 minutes, and logs a
Cannot download manifestwarning each time.Every hour, the Wazuh indexer tries to synchronize its content catalog and logs a burst of
ERRORandWARNlines in/var/log/wazuh-indexer/wazuh-cluster.log, ending withImmediate retry also failed; waiting for the next scheduled run.The detection content is not updated while the deployment has no Internet connection. Wazuh 5.0 doesn't support loading a newer vulnerability feed offline. See Unsupported offline feed.
If the deployment gets Internet access later, allow outbound HTTPS on port 443/TCP from the Wazuh indexer and Wazuh manager nodes to
api.pre.cloud.wazuh.com. The Wazuh indexer downloads ruleset, IOC, and vulnerability content updates from it, and the Wazuh manager downloads GeoIP database updates from it. The CVE links in the Wazuh dashboard opencti.wazuh.comin your browser, so the hosts that run the Wazuh central components don't need access to it.
Next steps
Once the Wazuh environment is ready, Wazuh agents can be installed on every endpoint to be monitored. To install the Wazuh agents and start monitoring the endpoints, see the Wazuh agent installation section.
To uninstall all the Wazuh central components, see the Uninstalling the Wazuh central components section.