Installing the Wazuh dashboard using the assisted installation method
Install and configure the Wazuh dashboard on a 64-bit (x86_64/AMD64 or AARCH64/ARM64) architecture using the assisted installation method. Wazuh dashboard is a flexible and intuitive web interface for mining and visualizing security data.
Wazuh dashboard installation
Download the Wazuh installation assistant. Skip this step if the Wazuh installation assistant is already in your working directory:
# curl -sO https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/installation-assistant/wazuh-install-5.0.0-rc1.sh
Run the Wazuh installation assistant with the option
--wazuh-dashboardand the node name to install and configure the Wazuh dashboard. The node name must be the same one used inconfig.ymlfor the initial configuration, for example,dashboard:Note
Make sure that a copy of
wazuh-install-files.tar, created in Initial configuration of the Wazuh indexer assisted installation, is in your working directory.# bash wazuh-install-5.0.0-rc1.sh --wazuh-dashboard dashboard -id -d pre-release
The default Wazuh web user interface port is 443, used by the Wazuh dashboard. To use another port after the installation, set
server.portin/etc/wazuh-dashboard/opensearch_dashboards.ymlto the new port and restart the Wazuh dashboard service.When the installation finishes, the assistant prints the address of the Wazuh dashboard, the username, and the command that shows the password:
INFO: Wazuh dashboard web application initialized. INFO: --- Summary --- INFO: You can access the web interface https://<WAZUH_DASHBOARD_ADDRESS>:443 INFO: User: admin (Wazuh dashboard login and Wazuh indexer administrator) INFO: Password: to read it from wazuh-install-files.tar, run: INFO: sudo tar -xOf wazuh-install-files.tar wazuh-install-files/credentials.env | grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' | cut -d= -f2- INFO: The other users of the deployment are listed at the top of wazuh-install-files/credentials.env of wazuh-install-files.tar. INFO: Installation finished.
The assistant prints one URL for each address in the Wazuh dashboard certificate. Use the one your browser can reach.
You have now installed and configured the Wazuh dashboard.
Get the
adminpassword. On a Wazuh indexer node, run the following command:# grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' /etc/wazuh/credentials.env | cut -d= -f2-
On a host without the Wazuh indexer, read it from
wazuh-install-files.tarinstead:# tar -xOf wazuh-install-files.tar wazuh-install-files/credentials.env | grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' | cut -d= -f2-
Access the Wazuh web interface with your
adminuser credentials. This is the default administrator account for the Wazuh indexer and it allows you to access the Wazuh dashboard.URL:
https://<WAZUH_DASHBOARD_ADDRESS>Username:
adminPassword: the password from step 3
The browser warns that the certificate wasn't issued by a trusted authority. Add an exception in the browser, or, for better security, import
root-ca.peminto the browser's certificate manager. You can also configure a certificate from a trusted authority.
Securing your Wazuh installation
After every component is installed and running, each component stores the passwords it needs in its own keystore or database. No component reads /etc/wazuh/credentials.env after the installation, and deleting it doesn't affect running or restarted components. wazuh-install-files.tar holds all five passwords. On each node, the installation assistant writes to /etc/wazuh/credentials.env only the passwords that node's components need, and the host where you ran --generate-config-files holds all five.
Log in to the Wazuh dashboard. A successful login shows that the Wazuh dashboard reaches the Wazuh indexer. Then open the menu and go to Dashboard management > Server API. In the API connection card, the Host is the address of the Wazuh manager master node, and the Status is Online. This shows that the Wazuh dashboard reaches the Wazuh manager. If the Status is Offline, check that the
wazuh-managerservice is running on the master node, and that port 55000/TCP is reachable from the Wazuh dashboard host, then click Refresh.Store the five passwords in a safe place. The
credentials.envfile inwazuh-install-files.tarholds all five. Run the following command to show them:# tar -xOf wazuh-install-files.tar wazuh-install-files/credentials.env
Remove the credentials file and the installation files. On every node, run the following command from the directory where you ran the installation assistant:
# rm -rf /etc/wazuh/credentials.env ./wazuh-install-files.tar ./artifact_urls_5.0.0-rc1.yaml ./wazuh-install-packages ./wazuh-install-5.0.0-rc1.sh
Only the host where you ran
--generate-config-fileskeeps the root CA private key. On every other node,/etc/wazuh/caholds onlyroot-ca.pem. Run the following command to check:# ls -A /etc/wazuh/ca
If the command lists
root-ca.keyon any other node, remove the key there. Don't remove it from the host where you ran--generate-config-files, because you need the key to add nodes or renew certificates later:# rm -f /etc/wazuh/ca/root-ca.key /etc/wazuh/ca/root-ca.srl
To change a password after installation, see the password management documentation.
Next steps
All the Wazuh central components are successfully installed.
The Wazuh environment is now ready, and you can proceed with installing the Wazuh agent on the endpoints to be monitored. To perform this action, see the Wazuh agent section.