Installing the Wazuh dashboard using the assisted installation method

Install and configure the Wazuh dashboard on a 64-bit (x86_64/AMD64 or AARCH64/ARM64) architecture using the assisted installation method. Wazuh dashboard is a flexible and intuitive web interface for mining and visualizing security data.

Wazuh dashboard installation

  1. Download the Wazuh installation assistant. Skip this step if the Wazuh installation assistant is already in your working directory:

    # curl -sO https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/installation-assistant/wazuh-install-5.0.0-rc1.sh
    
  2. Run the Wazuh installation assistant with the option --wazuh-dashboard and the node name to install and configure the Wazuh dashboard. The node name must be the same one used in config.yml for the initial configuration, for example, dashboard:

    Note

    Make sure that a copy of wazuh-install-files.tar, created in Initial configuration of the Wazuh indexer assisted installation, is in your working directory.

    # bash wazuh-install-5.0.0-rc1.sh --wazuh-dashboard dashboard -id -d pre-release
    

    The default Wazuh web user interface port is 443, used by the Wazuh dashboard. To use another port after the installation, set server.port in /etc/wazuh-dashboard/opensearch_dashboards.yml to the new port and restart the Wazuh dashboard service.

    When the installation finishes, the assistant prints the address of the Wazuh dashboard, the username, and the command that shows the password:

    INFO: Wazuh dashboard web application initialized.
    INFO: --- Summary ---
    INFO: You can access the web interface https://<WAZUH_DASHBOARD_ADDRESS>:443
    INFO:     User: admin (Wazuh dashboard login and Wazuh indexer administrator)
    INFO:     Password: to read it from wazuh-install-files.tar, run:
    INFO:         sudo tar -xOf wazuh-install-files.tar wazuh-install-files/credentials.env | grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' | cut -d= -f2-
    INFO: The other users of the deployment are listed at the top of wazuh-install-files/credentials.env of wazuh-install-files.tar.
    INFO: Installation finished.
    

    The assistant prints one URL for each address in the Wazuh dashboard certificate. Use the one your browser can reach.

    You have now installed and configured the Wazuh dashboard.

  3. Get the admin password. On a Wazuh indexer node, run the following command:

    # grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' /etc/wazuh/credentials.env | cut -d= -f2-
    

    On a host without the Wazuh indexer, read it from wazuh-install-files.tar instead:

    # tar -xOf wazuh-install-files.tar wazuh-install-files/credentials.env | grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' | cut -d= -f2-
    
  4. Access the Wazuh web interface with your admin user credentials. This is the default administrator account for the Wazuh indexer and it allows you to access the Wazuh dashboard.

    • URL: https://<WAZUH_DASHBOARD_ADDRESS>

    • Username: admin

    • Password: the password from step 3

    The browser warns that the certificate wasn't issued by a trusted authority. Add an exception in the browser, or, for better security, import root-ca.pem into the browser's certificate manager. You can also configure a certificate from a trusted authority.

Securing your Wazuh installation

After every component is installed and running, each component stores the passwords it needs in its own keystore or database. No component reads /etc/wazuh/credentials.env after the installation, and deleting it doesn't affect running or restarted components. wazuh-install-files.tar holds all five passwords. On each node, the installation assistant writes to /etc/wazuh/credentials.env only the passwords that node's components need, and the host where you ran --generate-config-files holds all five.

  1. Log in to the Wazuh dashboard. A successful login shows that the Wazuh dashboard reaches the Wazuh indexer. Then open the menu and go to Dashboard management > Server API. In the API connection card, the Host is the address of the Wazuh manager master node, and the Status is Online. This shows that the Wazuh dashboard reaches the Wazuh manager. If the Status is Offline, check that the wazuh-manager service is running on the master node, and that port 55000/TCP is reachable from the Wazuh dashboard host, then click Refresh.

  2. Store the five passwords in a safe place. The credentials.env file in wazuh-install-files.tar holds all five. Run the following command to show them:

    # tar -xOf wazuh-install-files.tar wazuh-install-files/credentials.env
    
  3. Remove the credentials file and the installation files. On every node, run the following command from the directory where you ran the installation assistant:

    # rm -rf /etc/wazuh/credentials.env ./wazuh-install-files.tar ./artifact_urls_5.0.0-rc1.yaml ./wazuh-install-packages ./wazuh-install-5.0.0-rc1.sh
    
  4. Only the host where you ran --generate-config-files keeps the root CA private key. On every other node, /etc/wazuh/ca holds only root-ca.pem. Run the following command to check:

    # ls -A /etc/wazuh/ca
    

    If the command lists root-ca.key on any other node, remove the key there. Don't remove it from the host where you ran --generate-config-files, because you need the key to add nodes or renew certificates later:

    # rm -f /etc/wazuh/ca/root-ca.key /etc/wazuh/ca/root-ca.srl
    

To change a password after installation, see the password management documentation.

Next steps

All the Wazuh central components are successfully installed.

The Wazuh environment is now ready, and you can proceed with installing the Wazuh agent on the endpoints to be monitored. To perform this action, see the Wazuh agent section.