Wazuh

Deploy Wazuh for endpoint monitoring, security analytics, vulnerability detection, and incident response in infrastructure you control.

On this page

Scope and fit

Wazuh combines endpoint agents with central analysis and search components to help teams monitor servers, workstations, containers, and cloud workloads. DeployOpen can help plan and operate a Wazuh environment around your fleet, log sources, and response processes.

How the platform fits together

Wazuh agents collect security data from monitored endpoints and send it to the Wazuh server for analysis. The server works with the Wazuh indexer and dashboard to store, search, and present alerts and related data.

Where teams use Wazuh

Security and IT teams use Wazuh to investigate endpoint activity, review configuration and vulnerability findings, and support detection and response workflows. Its data can contribute to a broader security monitoring program when coverage and ownership are clearly defined.

Plan the deployment around your fleet

Sizing starts with the number and type of endpoints, event volume, retention needs, and expected query load. Agent enrollment, network access, indexer storage, alert tuning, backups, and upgrade procedures should be designed together.

Decisions and tradeoffs

Use this table as a working review record. Replace assumptions with evidence from the target environment.

Decision areaWorking guidance
How the platform fits togetherWazuh agents collect security data from monitored endpoints and send it to the Wazuh server for analysis. The server works with the Wazuh indexer and dashboard to store, search, and present alerts and related data.
Where teams use WazuhSecurity and IT teams use Wazuh to investigate endpoint activity, review configuration and vulnerability findings, and support detection and response workflows. Its data can contribute to a broader security monitoring program when coverage and ownership are clearly defined.
Plan the deployment around your fleetSizing starts with the number and type of endpoints, event volume, retention needs, and expected query load. Agent enrollment, network access, indexer storage, alert tuning, backups, and upgrade procedures should be designed together.

Implementation questions

What should the team decide about how the platform fits together?

Wazuh agents collect security data from monitored endpoints and send it to the Wazuh server for analysis. The server works with the Wazuh indexer and dashboard to store, search, and present alerts and related data. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

What should the team decide about where teams use wazuh?

Security and IT teams use Wazuh to investigate endpoint activity, review configuration and vulnerability findings, and support detection and response workflows. Its data can contribute to a broader security monitoring program when coverage and ownership are clearly defined. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

What should the team decide about plan the deployment around your fleet?

Sizing starts with the number and type of endpoints, event volume, retention needs, and expected query load. Agent enrollment, network access, indexer storage, alert tuning, backups, and upgrade procedures should be designed together. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

Plan, build, verify, operate

How the platform fits together: Wazuh agents collect security data from monitored endpoints and send it to the Wazuh server for analysis. The server works with the Wazuh indexer and dashboard to store, search, and present alerts and related data. Record the result and the next owner before changing the next boundary.

Deployment checks

Turn the page into a reviewable handover by assigning each check to a person and retaining its result.

Endpoint and workload monitoring

How the platform fits together: Endpoint and workload monitoring. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Rules-based alert analysis

How the platform fits together: Rules-based alert analysis. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Central search and dashboards

How the platform fits together: Central search and dashboards. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

File integrity and configuration monitoring

Where teams use Wazuh: File integrity and configuration monitoring. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Vulnerability and malware detection

Where teams use Wazuh: Vulnerability and malware detection. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Security event investigation

Where teams use Wazuh: Security event investigation. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Coverage and operating boundaries

Start with an inventory, not an agent roll-out target. Group endpoints by operating system, business owner, network reachability, and the events they are expected to provide. A Wazuh agent on a laptop that is often off-network presents a different collection and update problem from an agent on a server. Record exclusions too: unsupported appliances, ephemeral workloads, or systems where an agent cannot be installed need another evidence source or an explicit accepted gap.

The Wazuh server analyses data from agents. The indexer stores and searches it, while the dashboard is the analyst-facing interface. That split gives the deployment several health signals to watch: agent connection state, manager queues and rule processing, index health and disk watermarks, and dashboard access. A green dashboard alone does not prove that expected endpoint telemetry is arriving.

Configuration assessment, file integrity monitoring, log collection, inventory, and vulnerability detection each add data and follow-up work. Turn them on against representative endpoint groups first. For every alert family, decide whether it creates a ticket, an investigation queue, an exception record, or no action. Untuned detections turn into background noise quickly; a small owned set is more useful than a large unattended rule set.

Keep the agent enrolment path separate from general analyst access. Protect manager and indexer credentials, restrict administrative interfaces, and document certificate rotation. Test a restore with the same version and configuration expected in production. Backups without the relevant configuration, keys, and a restoration runbook are not a recovery plan.

During handover, provide a coverage report, endpoint-group map, retention decision, alert-routing list, and an upgrade test record. The operating team should be able to answer three practical questions: which systems stopped reporting, which detections are acted on, and how a failed manager, indexer, or upgrade is recovered.

Handover and ownership

Before handover, name the system owner, support path, access boundary, backup or recovery responsibility, and the condition that pauses a change.

Keep a short record of what was tested, what remains outside scope, and when the review should happen again.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.