Wazuh server

The Wazuh server is in charge of analyzing the data received from the Wazuh agents, triggering alerts when threats or anomalies are detected. It is also used to manage the agents’ configuration remotely and to monitor their status. If you want to learn more about Wazuh components, check the Getting started section.

You can install the Wazuh server on a single host. Alternatively, you can install it distributed in multiple nodes in a cluster configuration. Multi-node configurations provide high availability and improved performance. And if combined with a network load balancer an efficient use of its capacity can be achieved.

Check the requirements below and choose an installation method to start installing the Wazuh server.

Wazuh server installation

Requirements

Check the supported operating systems and the recommended hardware requirements for the Wazuh server installation. Make sure that your system environment meets all requirements and that you have root user privileges.

Hardware requirements

The Wazuh server can be installed as a single-node or as a multi-node cluster.

  • Hardware recommendations

    Minimum

    Recommended

    Component

    RAM (GB)

    CPU (cores)

    RAM (GB)

    CPU (cores)

    Wazuh server

    2

    2

    4

    8

  • Disk space requirements

    The amount of data depends on the generated alerts per second (APS). This table details the estimated disk space needed per agent to store 90 days of alerts on a Wazuh server, depending on the type of monitored endpoints.

    Monitored endpoints

    APS

    Storage in Wazuh Manager
    (GB/90 days)

    Servers

    0.25

    0.1

    Workstations

    0.1

    0.04

    Network devices

    0.5

    0.2

    For example, for an environment with 80 workstations, 10 servers, and 10 network devices, the storage needed on the Wazuh server for 90 days of alerts is 6 GB.

Scaling

To determine if a Wazuh server requires more resources, monitor these files:

  • /var/ossec/var/run/wazuh-analysisd.state: the variable events_dropped indicates whether events are being dropped due to lack of resources.

  • /var/ossec/var/run/wazuh-remoted.state: the variable discarded_count indicates if messages from the agents were discarded.

These two variables should be zero if the environment is working properly. If it is not the case, additional nodes can be added to the cluster.