Installation guide
Wazuh is a security platform that provides unified XDR and SIEM protection for endpoints and cloud workloads. The solution is composed of the Wazuh agent and three central components: the Wazuh manager, the Wazuh indexer, and the Wazuh dashboard.
Wazuh is a free and open source platform. Its components abide by the GNU General Public License, version 2, and the GNU Affero General Public License version 3 (AGPLv3).
This guide shows how to install Wazuh on your own infrastructure. To use Wazuh without installing anything, try Wazuh Cloud, our SaaS solution: see the Wazuh Cloud service documentation or start a free trial.
Installing the Wazuh central components
You can install the Wazuh indexer, Wazuh manager, and Wazuh dashboard on a single host or distribute them in cluster configurations. Each Wazuh central component supports two deployment methods: Assisted installation and Step-by-step installation. Both methods provide instructions to install the central components on a single host or on separate hosts.
Check our Quickstart documentation to perform an all-in-one installation of the Wazuh central components. This is the fastest way to get the Wazuh central components up and running.
For more deployment flexibility and customization, install the Wazuh central components by starting with the Wazuh indexer deployment. This deployment method supports both an all-in-one installation and installing components on separate hosts.
Before you start, choose the name and IP address of every Wazuh indexer, Wazuh manager, and Wazuh dashboard node. You create the certificates and passwords for all of them on one host, usually the first Wazuh indexer node, then copy one archive to every other node.
I want to... |
Use |
|---|---|
Try Wazuh on one Linux host |
|
Install on one or more hosts with a script |
|
Control every step |
|
Install without internet access |
|
Import a ready virtual machine |
|
Run in containers |
|
Automate with Ansible |
The assisted and step-by-step methods install one component at a time, and both start on the Wazuh indexer page. Use the same method for the three components.
Follow this installation workflow:
All-in-one deployment
To install the Wazuh indexer, Wazuh manager, and Wazuh dashboard on one host with the step-by-step method:
Follow the Wazuh indexer, Wazuh manager, and Wazuh dashboard step-by-step sections in that order, as root, from the same directory.
In
config.yml, use the same IP address for the indexer, manager, and dashboard nodes.In the
<indexer>block of the Wazuh manager and inopensearch.hostsof the Wazuh dashboard, replace127.0.0.1andlocalhostwith the IP address you set inconfig.yml. The Wazuh indexer listens only on that address. Keephttps://localhostinwazuh_core.hosts.Skip the steps for other nodes, and skip Adding the Wazuh repository in the Wazuh manager and Wazuh dashboard sections, because the repository is already added.
Keep
wazuh-certificates.taruntil you install the Wazuh dashboard.Run Disable Wazuh updates once, after you install all three components.
For hardware requirements, see the all-in-one requirements in the Quickstart.
Installing the Wazuh agent
The Wazuh agent is a single, lightweight monitoring software. It is a multi-platform component that you can deploy to laptops, desktops, servers, cloud instances, containers, or virtual machines. It provides visibility into the monitored endpoint by collecting critical system and application records, inventory data, and detecting potential anomalies.
Before you install a Wazuh agent, create an enrollment token on the Wazuh manager, as described in Generate the enrollment token. Then select your endpoint operating system below and follow the installation steps.
Packages list
The Packages list section contains all the packages required for installing Wazuh.
Uninstalling Wazuh
In the Uninstalling Wazuh section, you will find instructions on how to uninstall the Wazuh central components and the Wazuh agent.
Installation alternatives
Wazuh provides other installation alternatives as well. These are complementary to the installation methods of this installation guide. You will find instructions on how to deploy Wazuh using ready-to-use machines, containers, and orchestration tools. There is also information on how to install Wazuh offline.