Installation guide

Wazuh is a security platform that provides unified XDR and SIEM protection for endpoints and cloud workloads. The solution is composed of the Wazuh agent and three central components: the Wazuh manager, the Wazuh indexer, and the Wazuh dashboard.

Wazuh is a free and open source platform. Its components abide by the GNU General Public License, version 2, and the GNU Affero General Public License version 3 (AGPLv3).

This guide shows how to install Wazuh on your own infrastructure. To use Wazuh without installing anything, try Wazuh Cloud, our SaaS solution: see the Wazuh Cloud service documentation or start a free trial.

Installing the Wazuh central components

You can install the Wazuh indexer, Wazuh manager, and Wazuh dashboard on a single host or distribute them in cluster configurations. Each Wazuh central component supports two deployment methods: Assisted installation and Step-by-step installation. Both methods provide instructions to install the central components on a single host or on separate hosts.

Check our Quickstart documentation to perform an all-in-one installation of the Wazuh central components. This is the fastest way to get the Wazuh central components up and running.

For more deployment flexibility and customization, install the Wazuh central components by starting with the Wazuh indexer deployment. This deployment method supports both an all-in-one installation and installing components on separate hosts.

Before you start, choose the name and IP address of every Wazuh indexer, Wazuh manager, and Wazuh dashboard node. You create the certificates and passwords for all of them on one host, usually the first Wazuh indexer node, then copy one archive to every other node.

I want to...

Use

Try Wazuh on one Linux host

Quickstart

Install on one or more hosts with a script

Assisted installation

Control every step

Step-by-step installation

Install without internet access

Offline installation

Import a ready virtual machine

Virtual machine (OVA)

Run in containers

Docker, Kubernetes

Automate with Ansible

Ansible

The assisted and step-by-step methods install one component at a time, and both start on the Wazuh indexer page. Use the same method for the three components.

Follow this installation workflow:

All-in-one deployment

To install the Wazuh indexer, Wazuh manager, and Wazuh dashboard on one host with the step-by-step method:

  • Follow the Wazuh indexer, Wazuh manager, and Wazuh dashboard step-by-step sections in that order, as root, from the same directory.

  • In config.yml, use the same IP address for the indexer, manager, and dashboard nodes.

  • In the <indexer> block of the Wazuh manager and in opensearch.hosts of the Wazuh dashboard, replace 127.0.0.1 and localhost with the IP address you set in config.yml. The Wazuh indexer listens only on that address. Keep https://localhost in wazuh_core.hosts.

  • Skip the steps for other nodes, and skip Adding the Wazuh repository in the Wazuh manager and Wazuh dashboard sections, because the repository is already added.

  • Keep wazuh-certificates.tar until you install the Wazuh dashboard.

  • Run Disable Wazuh updates once, after you install all three components.

  • For hardware requirements, see the all-in-one requirements in the Quickstart.

Installing the Wazuh agent

The Wazuh agent is a single, lightweight monitoring software. It is a multi-platform component that you can deploy to laptops, desktops, servers, cloud instances, containers, or virtual machines. It provides visibility into the monitored endpoint by collecting critical system and application records, inventory data, and detecting potential anomalies.

Before you install a Wazuh agent, create an enrollment token on the Wazuh manager, as described in Generate the enrollment token. Then select your endpoint operating system below and follow the installation steps.

Packages list

The Packages list section contains all the packages required for installing Wazuh.

Uninstalling Wazuh

In the Uninstalling Wazuh section, you will find instructions on how to uninstall the Wazuh central components and the Wazuh agent.

Installation alternatives

Wazuh provides other installation alternatives as well. These are complementary to the installation methods of this installation guide. You will find instructions on how to deploy Wazuh using ready-to-use machines, containers, and orchestration tools. There is also information on how to install Wazuh offline.