Scope and fit
Wazuh combines endpoint agents with central analysis and search components to help teams monitor servers, workstations, containers, and cloud workloads. DeployOpen can help plan and operate a Wazuh environment around your fleet, log sources, and response processes.
How the platform fits together
Wazuh agents collect security data from monitored endpoints and send it to the Wazuh server for analysis. The server works with the Wazuh indexer and dashboard to store, search, and present alerts and related data.
Where teams use Wazuh
Security and IT teams use Wazuh to investigate endpoint activity, review configuration and vulnerability findings, and support detection and response workflows. Its data can contribute to a broader security monitoring program when coverage and ownership are clearly defined.
Plan the deployment around your fleet
Sizing starts with the number and type of endpoints, event volume, retention needs, and expected query load. Agent enrollment, network access, indexer storage, alert tuning, backups, and upgrade procedures should be designed together.
Decisions and tradeoffs
Use this table as a working review record. Replace assumptions with evidence from the target environment.
| Decision area | Working guidance |
|---|---|
| How the platform fits together | Wazuh agents collect security data from monitored endpoints and send it to the Wazuh server for analysis. The server works with the Wazuh indexer and dashboard to store, search, and present alerts and related data. |
| Where teams use Wazuh | Security and IT teams use Wazuh to investigate endpoint activity, review configuration and vulnerability findings, and support detection and response workflows. Its data can contribute to a broader security monitoring program when coverage and ownership are clearly defined. |
| Plan the deployment around your fleet | Sizing starts with the number and type of endpoints, event volume, retention needs, and expected query load. Agent enrollment, network access, indexer storage, alert tuning, backups, and upgrade procedures should be designed together. |
Implementation questions
What should the team decide about how the platform fits together?
Wazuh agents collect security data from monitored endpoints and send it to the Wazuh server for analysis. The server works with the Wazuh indexer and dashboard to store, search, and present alerts and related data. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
What should the team decide about where teams use wazuh?
Security and IT teams use Wazuh to investigate endpoint activity, review configuration and vulnerability findings, and support detection and response workflows. Its data can contribute to a broader security monitoring program when coverage and ownership are clearly defined. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
What should the team decide about plan the deployment around your fleet?
Sizing starts with the number and type of endpoints, event volume, retention needs, and expected query load. Agent enrollment, network access, indexer storage, alert tuning, backups, and upgrade procedures should be designed together. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
Plan, build, verify, operate
How the platform fits together: Wazuh agents collect security data from monitored endpoints and send it to the Wazuh server for analysis. The server works with the Wazuh indexer and dashboard to store, search, and present alerts and related data. Record the result and the next owner before changing the next boundary.
Where teams use Wazuh: Security and IT teams use Wazuh to investigate endpoint activity, review configuration and vulnerability findings, and support detection and response workflows. Its data can contribute to a broader security monitoring program when coverage and ownership are clearly defined. Record the result and the next owner before changing the next boundary.
Plan the deployment around your fleet: Sizing starts with the number and type of endpoints, event volume, retention needs, and expected query load. Agent enrollment, network access, indexer storage, alert tuning, backups, and upgrade procedures should be designed together. Record the result and the next owner before changing the next boundary.
Deployment checks
Turn the page into a reviewable handover by assigning each check to a person and retaining its result.
Endpoint and workload monitoring
How the platform fits together: Endpoint and workload monitoring. Confirm the owner, input, evidence, and acceptance check before this work moves into production.
Rules-based alert analysis
How the platform fits together: Rules-based alert analysis. Confirm the owner, input, evidence, and acceptance check before this work moves into production.
Central search and dashboards
How the platform fits together: Central search and dashboards. Confirm the owner, input, evidence, and acceptance check before this work moves into production.
File integrity and configuration monitoring
Where teams use Wazuh: File integrity and configuration monitoring. Confirm the owner, input, evidence, and acceptance check before this work moves into production.
Vulnerability and malware detection
Where teams use Wazuh: Vulnerability and malware detection. Confirm the owner, input, evidence, and acceptance check before this work moves into production.
Security event investigation
Where teams use Wazuh: Security event investigation. Confirm the owner, input, evidence, and acceptance check before this work moves into production.
Coverage and operating boundaries
Start with an inventory, not an agent roll-out target. Group endpoints by operating system, business owner, network reachability, and the events they are expected to provide. A Wazuh agent on a laptop that is often off-network presents a different collection and update problem from an agent on a server. Record exclusions too: unsupported appliances, ephemeral workloads, or systems where an agent cannot be installed need another evidence source or an explicit accepted gap.
The Wazuh server analyses data from agents. The indexer stores and searches it, while the dashboard is the analyst-facing interface. That split gives the deployment several health signals to watch: agent connection state, manager queues and rule processing, index health and disk watermarks, and dashboard access. A green dashboard alone does not prove that expected endpoint telemetry is arriving.
Configuration assessment, file integrity monitoring, log collection, inventory, and vulnerability detection each add data and follow-up work. Turn them on against representative endpoint groups first. For every alert family, decide whether it creates a ticket, an investigation queue, an exception record, or no action. Untuned detections turn into background noise quickly; a small owned set is more useful than a large unattended rule set.
Keep the agent enrolment path separate from general analyst access. Protect manager and indexer credentials, restrict administrative interfaces, and document certificate rotation. Test a restore with the same version and configuration expected in production. Backups without the relevant configuration, keys, and a restoration runbook are not a recovery plan.
During handover, provide a coverage report, endpoint-group map, retention decision, alert-routing list, and an upgrade test record. The operating team should be able to answer three practical questions: which systems stopped reporting, which detections are acted on, and how a failed manager, indexer, or upgrade is recovered.
Handover and ownership
Before handover, name the system owner, support path, access boundary, backup or recovery responsibility, and the condition that pauses a change.
Keep a short record of what was tested, what remains outside scope, and when the review should happen again.

