Wazuh manager

The Wazuh manager analyzes event data received from Wazuh agents and forwards the processed events to the Wazuh indexer. It is also used to remotely manage the configurations of Wazuh agents and monitor their status. If you want to learn more about the Wazuh components, check the Getting started section.

You can install the Wazuh manager on a single host or distribute it across multiple nodes in a cluster configuration. Multi-node configurations provide high availability and improved performance. When combined with a network load balancer, you can achieve efficient use of its capacity.

Check the requirements below and choose an installation method to start installing the Wazuh manager.

Requirements

Check the recommended operating systems and hardware requirements for the Wazuh manager installation. Make sure that your system environment meets all requirements and that you have root user privileges.

Hardware requirements

You can install the Wazuh manager as a single-node or multi-node cluster.

  • Hardware requirements for each node:

    Minimum

    Recommended

    Component

    RAM (GB)

    CPU (cores)

    RAM (GB)

    CPU (cores)

    Wazuh manager

    8

    4

    16

    8

  • Disk space requirements

    The Wazuh manager no longer stores alerts from monitored endpoints. Instead, it stores the content and databases required by its server-side modules. Because the Vulnerability Scanner feed requires at least 15 GB of storage, Wazuh recommends allocating at least 20 GB of disk space for a Wazuh manager.

Required ports

The Wazuh manager uses the following ports.

Port

From

Purpose

1517/TCP

Wazuh 5.x agents, load balancer

Agent enrollment and connection over HTTPS

1516/TCP

Other Wazuh manager nodes

Cluster communication, multi-node only

55000/TCP

Wazuh dashboard, API clients, and agents removing themselves under anti-tampering

Wazuh manager API, master node

1514/TCP

Wazuh 4.x agents

Legacy agent connection

1515/TCP

Wazuh 4.x agents

Legacy enrollment

9200/TCP, outbound

This Wazuh manager

Connection to the Wazuh indexer

If no Wazuh 4.x agents connect to this Wazuh manager, you can keep 1514 and 1515 closed. You can also disable them in /var/wazuh-manager/etc/wazuh-manager.conf with <remote><legacy><enabled> and <auth><disabled>.

Agent connection address

Agents connect to the Wazuh manager only through an address in its agent listener certificate, and you can create enrollment tokens only for those addresses. The certificates include each Wazuh manager node's name and its ip and dns values from config.yml. To add any other address, such as a load balancer, a NAT address, or a public name, use -as <ALTERNATE_ADDRESS> when you create the certificates. For a cluster behind a load balancer, use a TCP passthrough load balancer on 1517/TCP and add its address with -as.