Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Wazuh’s all-in-one deployment is a practical starting point for a small security lab: install the server, indexer, and dashboard on one host, then enroll agents on the endpoints you want to monitor. The server analyzes their data and raises alerts, the indexer stores and searches those alerts, and the dashboard gives you a place to examine security and operational information. A working installation gives you collection and visibility—not guaranteed detection of every threat or a substitute for investigation.

How Wazuh fits together

A Wazuh deployment has three central components plus agents on monitored systems. The components have separate jobs, even when a small installation places them on the same host.

  • Wazuh agent: Runs on a monitored endpoint and sends collected data to the server. The installation guide covers systems including Linux, Windows, macOS, Solaris, AIX, and HP-UX, as well as endpoint types such as servers, laptops, cloud instances, containers, and virtual machines. Choose an agent and setup instructions for each operating system in scope.
  • Wazuh server: Receives and analyzes agent data, manages agent configuration and status, and triggers alerts when its rules identify threats or anomalies. Filebeat forwards alerts and archived events to the indexer.
  • Wazuh indexer: Stores and indexes alerts so they can be searched and analyzed.
  • Wazuh dashboard: Provides the web interface for exploring security events and related data.

Wazuh describes the platform as free and open source. Its Quickstart identifies GNU General Public License, version 2, and Apache License, Version 2.0 among the component licenses. See the official Quickstart for the current description.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose all-in-one, distributed, or hosted deployment

Option What it means Best fit and trade-off
All-in-one, self-managed Server, indexer, and dashboard run on one host. Simpler to set up and operate for a small evaluation or environment. Wazuh says this is usually enough for up to 100 endpoints and 90 days of queryable/indexed alert data; workload and retention still affect actual capacity.
Distributed, self-managed Central components run on separate hosts; server and indexer clusters can be configured. Consider for larger deployments or when scalability, availability, or load distribution matters. It requires more coordination, including node configuration and certificates.
Wazuh Cloud Wazuh provides a ready-to-use SaaS service for the central components. Consider if you do not want to provide and operate that infrastructure yourself. It changes infrastructure responsibility and control; the official material cited here does not establish a price comparison.

For a first self-managed deployment, the all-in-one option avoids the additional certificate and node setup of a distributed installation. If you later separate components, follow Wazuh’s live installation guide, including the current procedures for certificates and cluster initialization. Wazuh says certificates encrypt communication among central components. Its indexer installation procedure describes certificate creation, node installation, and cluster initialization; its server guide covers single- and multi-node deployments.

What hardware does a first Wazuh deployment need?

Wazuh’s current Quickstart publishes the following all-in-one recommendations for its 90-day queryable/indexed alert-data scenario. Treat them as starting points, not guarantees: event rates, endpoint types, enabled data sources, and retention affect resource use.

Agents CPU Memory Storage Scenario
1–25 4 vCPU 8 GiB RAM 50 GB Wazuh Quickstart recommendation for 90 days
26–50 8 vCPU 8 GiB RAM 100 GB Wazuh Quickstart recommendation for 90 days
51–100 8 vCPU 8 GiB RAM 200 GB Wazuh Quickstart recommendation for 90 days

These figures come from Wazuh’s Quickstart documentation, accessed in 2026. They are vendor recommendations for the stated scenario, not independent benchmark results. For a larger environment, Wazuh recommends considering a distributed deployment.

Wazuh’s component pages also publish per-node reference figures, which are more relevant when sizing separated hosts than when sizing an all-in-one installation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Component Minimum per node Recommended per node
Wazuh server 2 CPU cores, 2 GB RAM 8 CPU cores, 4 GB RAM
Wazuh indexer 2 cores, 4 GB RAM 8 cores, 16 GB RAM
Wazuh dashboard 2 cores, 4 GB RAM 4 cores, 8 GB RAM

Check the live server, indexer, and dashboard installation requirements for the release you plan to install. Architecture and supported Linux distributions can change; confirm that your chosen host and operating system are supported before building it.

How to install Wazuh and bring endpoints online

For an all-in-one deployment, use the official Wazuh Quickstart. It describes using the installation assistant and then opening the dashboard with generated credentials. Follow the live page for the current commands and package versions rather than relying on copied commands that may have become stale.

  1. Prepare the host. Match its CPU, memory, storage, architecture, and Linux distribution to the current Quickstart requirements and your expected agent count and retention.
  2. Install the central components. Follow the Quickstart’s current installation-assistant procedure. Keep the generated dashboard credentials secure.
  3. Open the dashboard. Use the address and credentials provided by the installer. If the browser reports that the certificate is not trusted, follow Wazuh’s guidance to import the generated root CA or configure a certificate from a trusted authority. Do not treat bypassing a certificate warning as the normal setup.
  4. Install agents on endpoints. Use the agent installation instructions for each operating system you intend to monitor. Plan the scope deliberately: an endpoint cannot report telemetry through an agent that has not been installed and connected.
  5. Verify reporting. Confirm that agents connect and that data is arriving before relying on dashboard views or alerts. Use the relevant endpoint-specific setup instructions and the dashboard.

Wazuh’s installation guide covers alternatives such as separated hosts and distributed deployments. The dashboard’s setup details are in the dashboard installation guide.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What you can see in the dashboard—and what an alert means

Wazuh says its dashboard can visualize security events, detected vulnerabilities, file integrity monitoring data, configuration assessment results, cloud infrastructure monitoring events, and regulatory compliance standards. These views help you examine information collected and processed by the platform.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not equate an empty alert view with proof that a system is safe, or an alert with proof that an intrusion succeeded. Detection depends on which endpoints and data sources are covered, how they are configured, and which rules apply. Alerts and dashboard results need to be interpreted and investigated in context; Wazuh provides visibility and analysis, not an automatic guarantee of comprehensive threat detection. See the Wazuh dashboard documentation for its capabilities.

Check for dropped events as you operate the deployment

A dashboard that loads is not the only sign to monitor. Wazuh documents state files that expose event loss indicators on the server:

  • /var/ossec/var/run/wazuh-analysisd.state: events_dropped indicates events dropped because of resource limits.
  • /var/ossec/var/run/wazuh-remoted.state: discarded_count indicates discarded agent messages.

Wazuh says these values should be zero in a properly functioning environment. Nonzero values are a capacity or processing warning to investigate; its server documentation suggests adding cluster nodes if they are not zero. Check the current server monitoring guidance and assess workload and capacity before deciding how to scale.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.