Installing the Wazuh manager step-by-step

Install and configure the Wazuh manager as a single-node or multi-node cluster following step-by-step instructions. The Wazuh manager analyzes event data received from Wazuh agents and forwards the processed events to the Wazuh indexer.

The installation process is divided into two stages:

  1. Wazuh manager node installation

  2. Cluster configuration for multi-node deployment

Note

You need root user privileges to run all the commands described below.

Wazuh manager node installation

Follow these steps to install a single-node or multi-node cluster Wazuh manager.

Adding the Wazuh repository

Note

If the Wazuh repository is already configured and enabled on this host, for example, on the Wazuh indexer host, skip these steps.

  1. Install the following packages if missing:

    # apt-get install -y gnupg apt-transport-https curl
    
  2. Install the GPG key:

    # curl -s https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
    
  3. Add the repository:

    # echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/apt/ unstable main" | tee /etc/apt/sources.list.d/wazuh.list
    
  4. Update the package information:

    # apt-get update
    

Deploying certificates and passwords

Do this before installing the package. The package then uses these files and passwords instead of generating its own.

Note

Make sure that a copy of the wazuh-certificates.tar file, created in the Wazuh indexer Certificate creation stage, is placed in your working directory.

  1. Replace <MANAGER_NODE_NAME> with your Wazuh manager node certificate name, the same used in config.yml when creating the certificates. In our case, the node name is manager. Then place the root CA, the passwords, and this node's certificates:

    # NODE_NAME=<MANAGER_NODE_NAME>
    
    # umask 022
    # mkdir wazuh-certificates
    # tar -xf wazuh-certificates.tar -C wazuh-certificates
    # install -d -m 0700 -o root -g root /etc/wazuh /etc/wazuh/ca
    # install -m 0644 wazuh-certificates/root-ca.pem /etc/wazuh/ca/root-ca.pem
    # [ -e /etc/wazuh/credentials.env ] || install -m 0600 /dev/null /etc/wazuh/credentials.env
    # for key in WAZUH_MANAGER_API_PASSWORD WAZUH_MANAGER_WUI_PASSWORD WAZUH_INDEXER_MANAGER_PASSWORD; do
        sed -i "/^${key}=/d" /etc/wazuh/credentials.env
        grep "^${key}=" wazuh-certificates/credentials.env >> /etc/wazuh/credentials.env
      done
    # mkdir -p /var/wazuh-manager/etc/certs
    # install -m 0640 wazuh-certificates/$NODE_NAME.pem /var/wazuh-manager/etc/certs/indexer-connector.pem
    # install -m 0640 wazuh-certificates/$NODE_NAME-key.pem /var/wazuh-manager/etc/certs/indexer-connector-key.pem
    # install -m 0640 wazuh-certificates/$NODE_NAME-remoted.pem /var/wazuh-manager/etc/certs/remoted.pem
    # install -m 0640 wazuh-certificates/$NODE_NAME-remoted-key.pem /var/wazuh-manager/etc/certs/remoted-key.pem
    # rm -rf wazuh-certificates
    

    The wazuh-manager user does not exist yet. When the package is installed, it gives each file its owner and copies root-ca.pem to /var/wazuh-manager/etc/certs.

  2. Recommended action: If no other Wazuh components will be installed on this node, remove the wazuh-certificates.tar file.

    # rm -f ./wazuh-certificates.tar
    

Installing the Wazuh manager

  1. Install the Wazuh manager package:

    # apt-get -y install wazuh-manager=5.0.0-rc1
    

    Note

    Firewalls can block communication between Wazuh components on different hosts. Refer to the Required ports section and ensure the necessary ports are open.

Checking the agent listener certificate

  1. Check the agent listener certificate:

    # openssl verify -CAfile /var/wazuh-manager/etc/certs/root-ca.pem /var/wazuh-manager/etc/certs/remoted.pem
    # openssl x509 -in /var/wazuh-manager/etc/certs/remoted.pem -noout -ext subjectAltName
    

    The first command prints /var/wazuh-manager/etc/certs/remoted.pem: OK. The second lists this node's address, its name, and every address you added with -as. Only these addresses can be used to create enrollment tokens on this node.

Configuring the Wazuh indexer connection

  1. Edit /var/wazuh-manager/etc/wazuh-manager.conf file to configure the indexer connection. Do it on the master node and on every worker node, as the cluster does not synchronize this block. By default, the indexer settings configure one host. It's set to 127.0.0.1:

    <indexer>
       <hosts>
         <host>https://127.0.0.1:9200</host>
       </hosts>
       <ssl>
         <certificate_authorities>
           <ca>etc/certs/root-ca.pem</ca>
         </certificate_authorities>
         <certificate>etc/certs/indexer-connector.pem</certificate>
         <key>etc/certs/indexer-connector-key.pem</key>
       </ssl>
     </indexer>
    
    • Replace 127.0.0.1 with the address of your Wazuh indexer node: its ip value in config.yml, which is also its network.host value in /etc/wazuh-indexer/opensearch.yml on that node.

    If you are running a Wazuh indexer cluster infrastructure, add a <host> entry for each one of your Wazuh indexer nodes. For example, in a two-node configuration:

    <hosts>
      <host>https://10.0.0.1:9200</host>
      <host>https://10.0.0.2:9200</host>
    </hosts>
    

    The Wazuh manager prioritizes reporting to the first Wazuh indexer node in the list. It switches to the next node if it is unavailable.

Starting the Wazuh manager

  1. Enable and start the Wazuh manager service:

    # systemctl daemon-reload
    # systemctl enable wazuh-manager
    # systemctl start wazuh-manager
    
  2. Run the following command to verify the Wazuh manager status. Check that the output shows Active: active (running):

    # systemctl status wazuh-manager
    
  3. Check that the Wazuh manager reaches the Wazuh indexer:

    # grep -E 'indexer is reachable|No configured indexer host' /var/wazuh-manager/logs/wazuh-manager.log | tail -1
    

    The output is a line that ends in INFO: The indexer is reachable; inventory documents can be delivered. If the command prints nothing, wait a minute and run it again. If it still prints nothing, or it prints a line with No configured indexer host is currently reachable, check the <indexer> block and that port 9200/TCP of the Wazuh indexer is reachable from this host.

Your Wazuh manager node is now successfully installed. Repeat this stage of the installation process for every Wazuh manager node in your Wazuh cluster, then proceed with configuring the Wazuh cluster. If you want a Wazuh manager single-node cluster, everything is set, and you can proceed directly with Installing the Wazuh dashboard step-by-step.

Cluster configuration for multi-node deployment

After completing the installation of the Wazuh manager on every node, configure one Wazuh manager node as the master and the rest as workers. Every node receives the same Wazuh manager API passwords from wazuh-certificates.tar in Deploying certificates and passwords, so the workers need no extra password step.

The package writes a single-node <cluster> block on every node, with node_type set to master, a random key, and 127.0.0.1 as the bind_addr and node address. Edit that block in place on each node, and don't add a second <cluster> block. The node_name parameter is the node's name inside the Wazuh manager cluster. It doesn't need to match the certificate name in config.yml.

Configuring the Wazuh manager master node

  1. On the master node, create the cluster key and keep the output. You use the same value on the master node and on every worker node:

    # openssl rand -hex 16
    

    Then edit the following settings in the /var/wazuh-manager/etc/wazuh-manager.conf file and configure the necessary parameters:

    <cluster>
      <name>wazuh</name>
      <node_name>master-node</node_name>
      <node_type>master</node_type>
      <key><CLUSTER_KEY></key>
      <port>1516</port>
      <bind_addr>0.0.0.0</bind_addr>
      <nodes>
          <node><WAZUH_MASTER_ADDRESS></node>
      </nodes>
      <hidden>no</hidden>
    </cluster>
    

    Configuration parameters:

    name

    Indicates the name of the cluster. All nodes must use the same cluster name.

    node_name

    Indicates the name of the current node. Each node of the cluster must have a unique name.

    node_type

    Specifies the role of the node. It has to be set to master.

    key

    Key that encrypts communication between cluster nodes. Replace <CLUSTER_KEY> with a 32-character key that is the same on every node. Create it once, on the master node, with openssl rand -hex 16.

    port

    It indicates the destination port for cluster communication.

    bind_addr

    It is the network IP to which the node is bound to listen for incoming requests (0.0.0.0 to listen on all interfaces.).

    nodes

    It is the address of the master node and can be either an IP or a DNS. This parameter must be specified in all nodes, including the master itself. Replace <WAZUH_MASTER_ADDRESS> with the IP address or DNS name of the master node.

    hidden

    Whether the node is hidden from the cluster. Default: no.

  2. Restart the Wazuh manager:

    # systemctl restart wazuh-manager
    

Configuring the Wazuh manager worker nodes

  1. The Wazuh manager cluster lets you scale horizontally by distributing the load across multiple nodes. On each worker node, edit the <cluster> block in /var/wazuh-manager/etc/wazuh-manager.conf as follows. Use a unique node_name, for example worker-node1 and worker-node2, set node_type to worker, and use the same <CLUSTER_KEY> as the master node:

    <cluster>
        <name>wazuh</name>
        <node_name>worker-node1</node_name>
        <node_type>worker</node_type>
        <key><CLUSTER_KEY></key>
        <port>1516</port>
        <bind_addr>0.0.0.0</bind_addr>
        <nodes>
            <node><WAZUH_MASTER_ADDRESS></node>
        </nodes>
        <hidden>no</hidden>
    </cluster>
    

    Configuration parameters:

    name

    Indicates the name of the cluster. All nodes must use the same cluster name.

    node_name

    Indicates the name of the current node. Each node of the cluster must have a unique name.

    node_type

    Specifies the role of the node. It has to be set as worker.

    key

    The <CLUSTER_KEY> value you created on the master node (the package wrote a different random key on this node). It must be the same on every node.

    nodes

    Specifies the address of the master node. Replace <WAZUH_MASTER_ADDRESS> with the IP address or DNS name of the master node, the same value you set on the master node.

  2. Restart the Wazuh manager:

    # systemctl restart wazuh-manager
    

Repeat these configuration steps for every Wazuh manager worker node in your cluster.

Testing the Wazuh manager cluster

On any Wazuh manager node, run the following command to verify that the Wazuh cluster is enabled and all the nodes are connected:

# /var/wazuh-manager/bin/cluster_control -l

An example output of the command looks as follows:

NAME         TYPE    VERSION  ADDRESS
master-node  master  5.0.0    10.0.0.3
worker-node1 worker  5.0.0    10.0.0.4
worker-node2 worker  5.0.0    10.0.0.5

Note that the IP addresses 10.0.0.3, 10.0.0.4, and 10.0.0.5 are used as examples.

Disable Wazuh updates

After all Wazuh components on this host are installed, disable the Wazuh repository to prevent accidental upgrades. If you will also install another component on this host, do this after installing it:

# sed -i "s/^deb /#deb /" /etc/apt/sources.list.d/wazuh.list
# apt update

Next steps

The Wazuh manager installation is now complete, and you can proceed with Installing the Wazuh dashboard step-by-step.

If you want to uninstall the Wazuh manager, see Uninstall the Wazuh manager.