Wazuh manager
The Wazuh manager analyzes event data received from Wazuh agents and forwards the processed events to the Wazuh indexer. It is also used to remotely manage the configurations of Wazuh agents and monitor their status. If you want to learn more about the Wazuh components, check the Getting started section.
You can install the Wazuh manager on a single host or distribute it across multiple nodes in a cluster configuration. Multi-node configurations provide high availability and improved performance. When combined with a network load balancer, you can achieve efficient use of its capacity.
Check the requirements below and choose an installation method to start installing the Wazuh manager.
Assisted installation: Install this component by running an assistant that automates the installation and configuration process.
Step-by-step installation: Install this component following detailed step-by-step instructions.
Requirements
Check the recommended operating systems and hardware requirements for the Wazuh manager installation. Make sure that your system environment meets all requirements and that you have root user privileges.
Recommended operating systems
The Wazuh manager requires a 64-bit Intel, AMD, or ARM Linux processor (x86_64/AMD64 or AARCH64/ARM64 architecture). Wazuh recommends the following operating system versions:
Amazon Linux 2023
Ubuntu 24.04, 26.04
Red Hat Enterprise Linux 9, 10
Hardware requirements
You can install the Wazuh manager as a single-node or multi-node cluster.
Hardware requirements for each node:
Minimum
Recommended
Component
RAM (GB)
CPU (cores)
RAM (GB)
CPU (cores)
Wazuh manager
8
4
16
8
Disk space requirements
The Wazuh manager no longer stores alerts from monitored endpoints. Instead, it stores the content and databases required by its server-side modules. Because the Vulnerability Scanner feed requires at least 15 GB of storage, Wazuh recommends allocating at least 20 GB of disk space for a Wazuh manager.
Required ports
The Wazuh manager uses the following ports.
Port |
From |
Purpose |
|---|---|---|
1517/TCP |
Wazuh 5.x agents, load balancer |
Agent enrollment and connection over HTTPS |
1516/TCP |
Other Wazuh manager nodes |
Cluster communication, multi-node only |
55000/TCP |
Wazuh dashboard, API clients, and agents removing themselves under anti-tampering |
Wazuh manager API, master node |
1514/TCP |
Wazuh 4.x agents |
Legacy agent connection |
1515/TCP |
Wazuh 4.x agents |
Legacy enrollment |
9200/TCP, outbound |
This Wazuh manager |
Connection to the Wazuh indexer |
If no Wazuh 4.x agents connect to this Wazuh manager, you can keep 1514 and 1515 closed. You can also disable them in /var/wazuh-manager/etc/wazuh-manager.conf with <remote><legacy><enabled> and <auth><disabled>.
Agent connection address
Agents connect to the Wazuh manager only through an address in its agent listener certificate, and you can create enrollment tokens only for those addresses. The certificates include each Wazuh manager node's name and its ip and dns values from config.yml. To add any other address, such as a load balancer, a NAT address, or a public name, use -as <ALTERNATE_ADDRESS> when you create the certificates. For a cluster behind a load balancer, use a TCP passthrough load balancer on 1517/TCP and add its address with -as.