Installing the Wazuh dashboard step-by-step
Install and configure the Wazuh dashboard following step-by-step instructions. The Wazuh dashboard is a web interface for mining and visualizing security data.
Note
You need root user privileges to run all the commands described below.
Wazuh dashboard installation
Follow these steps to install the Wazuh dashboard.
Installing package dependencies
Install the following packages if missing:
# apt-get install -y tar curl libcap2-bin openssl
# yum -y install libcap
# dnf -y install libcap
Adding the Wazuh repository
Note
If the Wazuh repository is already configured and enabled on this host, for example on the Wazuh indexer host, skip these steps.
Install the following packages if missing:
# apt-get install -y gnupg apt-transport-https curl
Install the GPG key:
# curl -s https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
Add the repository:
# echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/apt/ unstable main" | tee /etc/apt/sources.list.d/wazuh.list
Update the package information:
# apt-get update
Import the GPG key:
# rpm --import https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH
Add the repository:
For RHEL-compatible systems version 8 and earlier, use the following command:
# echo -e '[wazuh]\ngpgcheck=1\ngpgkey=https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH\nenabled=1\nname=EL-$releasever - Wazuh\nbaseurl=https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/yum/\nprotect=1' | tee /etc/yum.repos.d/wazuh.repo
For RHEL-compatible systems version 9 and later, use the following command:
# echo -e '[wazuh]\ngpgcheck=1\ngpgkey=https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH\nenabled=1\nname=EL-$releasever - Wazuh\nbaseurl=https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/yum/\npriority=1' | tee /etc/yum.repos.d/wazuh.repo
Import the GPG key:
# rpm --import https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH
Add the repository:
# echo -e '[wazuh]\ngpgcheck=1\ngpgkey=https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH\nenabled=1\nname=EL-$releasever - Wazuh\nbaseurl=https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/yum/\npriority=1' | tee /etc/yum.repos.d/wazuh.repo
Deploying certificates and passwords
Do this before installing the package. The package then uses these files and passwords instead of generating its own.
Note
Make sure that a copy of the wazuh-certificates.tar file, created in the Wazuh indexer Certificate creation stage, is placed in your working directory.
Replace
<DASHBOARD_NODE_NAME>with your Wazuh dashboard node name, the same one used in theconfig.ymlfile to create the certificates. In our case, the node name isdashboard. Then place the root CA, the passwords, and this node's certificates:# NODE_NAME=<DASHBOARD_NODE_NAME>
# umask 022 # mkdir wazuh-certificates # tar -xf wazuh-certificates.tar -C wazuh-certificates # install -d -m 0700 -o root -g root /etc/wazuh /etc/wazuh/ca # install -m 0644 wazuh-certificates/root-ca.pem /etc/wazuh/ca/root-ca.pem # [ -e /etc/wazuh/credentials.env ] || install -m 0600 /dev/null /etc/wazuh/credentials.env # for key in WAZUH_INDEXER_KIBANASERVER_PASSWORD WAZUH_MANAGER_WUI_PASSWORD; do sed -i "/^${key}=/d" /etc/wazuh/credentials.env grep "^${key}=" wazuh-certificates/credentials.env >> /etc/wazuh/credentials.env done # mkdir -p /etc/wazuh-dashboard/certs # install -m 0400 wazuh-certificates/$NODE_NAME.pem /etc/wazuh-dashboard/certs/dashboard.pem # install -m 0400 wazuh-certificates/$NODE_NAME-key.pem /etc/wazuh-dashboard/certs/dashboard-key.pem # rm -rf wazuh-certificates
The
wazuh-dashboarduser does not exist yet. When the package is installed, it gives these files to thewazuh-dashboarduser and installsroot-ca.pemin/etc/wazuh-dashboard/certs/.Recommended action: If no other Wazuh components will be installed on this node, remove the
wazuh-certificates.tarfile.# rm -f ./wazuh-certificates.tar
Installing the Wazuh dashboard
Install the Wazuh dashboard package:
# apt-get -y install wazuh-dashboard=5.0.0-rc1
# yum -y install wazuh-dashboard-5.0.0-rc1
# dnf -y install wazuh-dashboard-5.0.0-rc1
Configuring the Wazuh dashboard
Make sure the service user owns the certificates and restrict their directory:
# chown -R wazuh-dashboard:wazuh-dashboard /etc/wazuh-dashboard/certs # chmod 500 /etc/wazuh-dashboard/certs
Edit the
/etc/wazuh-dashboard/opensearch_dashboards.ymlfile. The package ships it pre-filled with single-host values, so change onlyopensearch.hostsandwazuh_core.hosts.default.url, and leave the rest of the file as shipped:server.host: The package sets0.0.0.0, which accepts connections on every address of the host. You don't need to change it.opensearch.hosts: The package setshttps://localhost:9200. Replace it with the URL of the Wazuh indexer node, using the address you set innetwork.hostin Configuring the Wazuh indexer. The Wazuh indexer listens only on that address, solocalhostfails even when the Wazuh indexer runs on this host.server.host: 0.0.0.0 server.port: 443 opensearch.hosts: https://<WAZUH_INDEXER_ADDRESS>:9200 opensearch.ssl.verificationMode: certificate
For a Wazuh indexer cluster, list every node:
opensearch.hosts: ["https://10.0.0.2:9200", "https://10.0.0.3:9200", "https://10.0.0.4:9200"]
wazuh_core.hosts.default.url: The Wazuh manager master node. Replace<WAZUH_MASTER_ADDRESS>with the IP address or DNS name of the master node. If the Wazuh manager master node is on this host, keep the shipped value,https://localhost.wazuh_core.hosts: default: url: https://<WAZUH_MASTER_ADDRESS> port: 55000 username: wazuh-wui run_as: true
Note
Firewalls can block communication between Wazuh components on different hosts. Refer to the Required ports section and ensure the necessary ports are open.
Starting the Wazuh dashboard service
Enable and start the Wazuh dashboard service:
# systemctl daemon-reload # systemctl enable wazuh-dashboard # systemctl start wazuh-dashboard
Choose one option according to your operating system:
RPM-based operating system:
# chkconfig --add wazuh-dashboard # service wazuh-dashboard start
Debian-based operating system:
# update-rc.d wazuh-dashboard defaults 95 10 # service wazuh-dashboard start
Run the following command to verify the Wazuh dashboard status. Check that the output shows
Active: active (running):# systemctl status wazuh-dashboard
# service wazuh-dashboard status
If the service stops at once, run
journalctl -u wazuh-dashboard. AMISSING WAZUH_INDEXER_KIBANASERVER_PASSWORDorMISSING WAZUH_MANAGER_WUI_PASSWORDline means that the password is not in/etc/wazuh/credentials.env. Repeat Deploying certificates and passwords, then start the service again.Get the
adminpassword. On the Wazuh indexer node where you ranindexer-security-init.sh, run the following command:# grep '^WAZUH_INDEXER_ADMIN_PASSWORD=' /etc/wazuh/credentials.env | tr -d '"' | sort -u | cut -d= -f2-
Access the Wazuh web interface with your
adminuser credentials. This is the default administrator account for the Wazuh indexer, and it allows you to access the Wazuh dashboard.URL:
https://<WAZUH_DASHBOARD_ADDRESS>Username:
adminPassword: the password from step 3
The browser warns that the certificate wasn't issued by a trusted authority. Add an exception in the browser, or, for better security, import
root-ca.peminto the browser's certificate manager. You can also configure a certificate from a trusted authority.
Securing your Wazuh installation
Once every component is installed and running, each component stores the passwords it needs in its own keystore or database. Nothing reads /etc/wazuh/credentials.env after installation, and deleting it doesn't affect running or restarted components. Every node received the passwords it needs from the credentials.env file you created in Creating the passwords, directly on the first Wazuh indexer node and through wazuh-certificates.tar on the others.
Log in to the Wazuh dashboard. A successful login shows that the Wazuh dashboard reaches the Wazuh indexer. Then open the menu and go to Dashboard management > Server API. In the API connection card, the Host is the address of the Wazuh manager master node, and the Status is Online. This shows that the Wazuh dashboard reaches the Wazuh manager. If the Status is Offline, check that the
wazuh-managerservice is running on the master node and that port 55000/TCP is reachable from the Wazuh dashboard host, then click Refresh.Securely store the five passwords. The
credentials.envfile in the working directory of the first Wazuh indexer node holds all five.Remove the credentials file, the
credentials.envyou created on the first Wazuh indexer node, and anywazuh-certificates.tarleft behind, on every node:# rm -f /etc/wazuh/credentials.env ./credentials.env ./wazuh-certificates.tar
Only the first Wazuh indexer node must hold the root CA private key. On every other node,
/etc/wazuh/camust hold onlyroot-ca.pem:# ls -A /etc/wazuh/ca
If the command lists
root-ca.keyon any node other than the first Wazuh indexer node, remove the key there. Never run this on the first Wazuh indexer node, which must keep the key to add nodes or renew certificates:# rm -f /etc/wazuh/ca/root-ca.key /etc/wazuh/ca/root-ca.srl
To change a password after installation, see the password management documentation.
Disable Wazuh updates
After all Wazuh components on this host are installed, disable the Wazuh repository to prevent accidental upgrades:
# sed -i "s/^deb /#deb /" /etc/apt/sources.list.d/wazuh.list
# apt update
# sed -i "s/^enabled=1/enabled=0/" /etc/yum.repos.d/wazuh.repo
# sed -i "s/^enabled=1/enabled=0/" /etc/yum.repos.d/wazuh.repo
Next steps
All the Wazuh central components are successfully installed and secured.
The Wazuh environment is now ready, and you can proceed with installing the Wazuh agent on the endpoints to be monitored. To perform this action, see the Wazuh agent section.
If you want to uninstall the Wazuh dashboard, see Uninstall the Wazuh dashboard.