Planning a Wazuh deployment: endpoints, retention, and architecture

Plan Wazuh agents, server and indexer components, certificates, enrollment, ingestion, retention, and operating ownership.

On this page

Start with monitored use cases

Wazuh can collect endpoint security telemetry through agents and process it through its documented central components. Start with a bounded use case: endpoint inventory, file-integrity events, authentication monitoring, vulnerability visibility, or a small detection workflow. A long agent list without an analyst question creates ingestion cost and alert noise.

Inventory endpoint populations, operating systems, network paths, owner teams, and whether an agent can be installed. Include servers, workstations, cloud workloads, and exceptions. The result drives enrollment, certificate, capacity, and support planning.

Map the Wazuh architecture

Use the current Wazuh architecture guidance to map agents, manager services, indexer storage, dashboard access, enrollment, certificates, and monitoring. Show which network paths are permitted and where persistent data lives. Keep administrative dashboard access separate from agent-to-manager traffic.

Plan version compatibility and certificate lifecycle before rollout. Enrollment is an access boundary: decide who may introduce an endpoint, how it is identified, and how a lost or retired device is removed.

Measure ingestion and set retention

Retention should follow use cases, expected query windows, compliance needs, storage capacity, and the sensitivity of events. Measure representative endpoint volume and peak bursts. Endpoint telemetry may include usernames, paths, command lines, and network details, so decide who can search it and how long it remains available.

Test query behaviour at the time ranges analysts will use. A policy that keeps data but makes incident queries unusable has not met its operational goal.

Roll out in small cohorts

Begin with a controlled cohort that represents key operating systems and network zones. Verify agent enrollment, time synchronisation, expected events, indexing, dashboard roles, alert delivery, and removal. Fix rules and labels before expanding.

For an illustrative server cohort, create one safe file change and one controlled login event, then show that an authorised analyst can find both while a viewer account cannot change rules or agent settings.

Deployment decisions

Record the evidence alongside the rollout plan.

AreaDecisionEvidence
EndpointsWhich populations and exceptions are in scope?Owner-approved inventory.
EnrollmentHow are agents authenticated and retired?Cohort enrollment and removal test.
RetentionWhich event classes stay searchable and for how long?Measured volume and query test.
AccessWho may administer, investigate, or export data?Role test and network review.

Practical questions

Can every endpoint use the same configuration?

Not necessarily. Operating systems, roles, network zones, and event volume vary. Use a common baseline plus documented profiles.

What proves enrollment is safe?

A named endpoint enrolls through the intended path, sends expected telemetry, and can be revoked without disrupting others.

What belongs in a recovery test?

Test the documented persistence boundary, dashboard and role access, and a representative search after restoration.

Plan, prove, operate

Inventory endpoints, use cases, architecture, certificates, access, storage, and owners.

Handover checks

Keep operating evidence with the platform.

Cohort test

Representative endpoints have passed enrollment and telemetry checks.

Role review

Analyst and administrator paths are tested separately.

Retention record

Measured volume, search expectations, and storage ownership are documented.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.