How to Install Wazuh SIEM on Ubuntu Server (Bare-Metal) & Enroll Linux and Windows Agents
If you self-host services at home or manage small business infrastructure, collecting system logs isn't enough—you need to correlate those logs, monitor file integrity, detect vulnerabilities, and respond to threats automatically. That is where a SIEM (Security Information and Event Management) platform comes in.
Wazuh is arguably the best open-source SIEM and XDR (Extended Detection and Response) platform available. It provides real-time security monitoring, regulatory compliance checks, file integrity monitoring (FIM), and incident response capabilities—completely free. (If you want a deeper look at the core concepts and capabilities before installing, read our guide on What is a SIEM? Introduction to Wazuh).
While many homelabbers deploy software inside Docker containers, running Wazuh natively on bare-metal Ubuntu Server gives you superior performance for disk-heavy indexing, avoids network stack abstraction issues, and allows for precise resource tuning.
In this guide, we will cover:
- System prerequisites and architecture.
- Installing the full Wazuh Stack (Indexer, Manager, Dashboard) on Ubuntu Server.
- Deploying and enrolling a Linux Agent (Ubuntu/Debian).
- Deploying and enrolling a Windows Agent (Windows 10/11 or Windows Server).
- Verifying telemetry and log flow inside the dashboard.
1. Prerequisites & Architecture Overview
Before firing up the terminal, it helps to understand what happens under the hood. Wazuh consists of three main underlying services:
- Wazuh Indexer: A highly scalable, OpenSearch-based search and analytics engine that stores alerts and logs.
- Wazuh Manager: The brain of the operation. It receives events from agents, runs logs through detection rules, generates security alerts, and triggers active responses.
- Wazuh Dashboard: The web interface used to query data, visualize threats, monitor agent health, and manage rulesets.
┌─────────────────────────────────────────────────────────┐
│ Wazuh Server │
│ ┌─────────────────┐ ┌───────────────┐ ┌─────────────┐ │
│ │ Wazuh Indexer │ │ Wazuh Manager │ │ Dashboard │ │
│ │ (OpenSearch Engine)│ │ (Engine) │ │ (Web UI) │ │
│ └─────────▲───────┘ └───────▲───────┘ └─────────────┘ │
└────────────┼─────────────────┼──────────────────────────┘
│ │ Ports: 1514/1515 TCP
│ │
┌───────┴───────┐ ┌─────┴─────────┐
│ Linux Endpoint│ │ Windows Host │
│ wazuh-agent │ │ wazuh-agent │
└───────────────┘ └───────────────┘
System Requirements (Single-Node Server)
- OS: Ubuntu Server 22.04 LTS or 24.04 LTS (Fresh install recommended).
- CPU: 4 Cores minimum.
- RAM: 8 GB minimum (16 GB recommended if monitoring 10+ endpoints).
- Disk: 50 GB+ SSD space (SSDs are critical due to heavy OpenSearch indexing operations).
- Static IP: Ensure your Ubuntu server has a static LAN IP assigned (e.g.,
192.168.1.50).
2. Installing the Wazuh Stack on Ubuntu Server
We will use the official Wazuh all-in-one assistant. This script handles installing the custom repositories, configuring system limits, generating self-signed SSL certificates, and building the Indexer, Manager, and Dashboard on a single host.
Step 1: Update System Packages
SSH into your clean Ubuntu server and make sure everything is up to date:
sudo apt update && sudo apt upgrade -y sudo apt install -y curl apt-transport-https gnupg tar
Step 2: Run the Official Installation Assistant
Download and execute the official installer using the all-in-one (-a) flag:
curl -sO https://packages.wazuh.com/4.10/wazuh-install.sh sudo bash ./wazuh-install.sh -a
(Note: The process takes 5 to 15 minutes depending on your internet connection and CPU speed.)
Step 3: Save Your Credentials
When the script finishes, it will output a summary block in your terminal containing your unique admin credentials:
INFO: --- Summary --- INFO: You can access the web interface https://<YOUR_SERVER_IP> INFO: User: admin INFO: Password: <RANDOM_GENERATED_PASSWORD>
IMPORTANT: Copy and save this password to your password manager immediately. It will not be shown again.
Step 4: Verify Services
Confirm that all essential services are active and running natively:
sudo systemctl status wazuh-indexer wazuh-manager wazuh-dashboard
You can now open a browser, navigate to https://<YOUR_SERVER_IP>, accept the self-signed SSL certificate warning, and log in with your admin credentials.
3. Enrolling a Linux Endpoint (Ubuntu/Debian)
Now that our core SIEM is online, let's start sending logs from another Linux server or desktop on your network.
Step 1: Generate the Deployment Command
- Open the Wazuh Dashboard in your browser.
- Click the Navigation Menu (☰) in the top left > Agent Management > Summary.
- Click the Deploy new agent button in the top right.
- Select your endpoint options:
- Operating System: Linux
- Architecture: x86_64 or arm64
- Distribution: DEB (Ubuntu/Debian)
- Server Address: The static IP of your Wazuh Manager (e.g.,
192.168.1.50). - Agent Name: (Optional) Give it a recognizable hostname like
debian-nasorubuntu-web-server.
Step 2: Install and Start the Agent on the Linux Machine
The dashboard will auto-generate a single-line command. SSH into the Linux client machine you want to monitor and run it:
wget https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_4.10.0-1_amd64.deb && sudo WAZUH_MANAGER='192.168.1.50' dpkg -i ./wazuh-agent_4.10.0-1_amd64.deb
Once installed, reload systemd, enable the service on boot, and start it:
sudo systemctl daemon-reload sudo systemctl enable wazuh-agent sudo systemctl start wazuh-agent
Check the log on the client machine to verify connection:
sudo tail -f /var/ossec/logs/ossec.log | grep -i "connected"
You should see: INFO: Connected to the server (192.168.1.50:1514/tcp).
4. Enrolling a Windows Endpoint
Windows endpoint security is where SIEMs shine—Wazuh natively collects Windows Event Logs, monitors privilege escalation, tracks system changes, and monitors Windows Defender events out of the box.
Option A: Via PowerShell (Fastest)
Open PowerShell as Administrator on your Windows target system and execute:
Invoke-WebRequest -Uri https://packages.wazuh.com/4.x/windows/wazuh-agent-4.10.0-1.msi -OutFile ${env:TEMP}\wazuh-agent.msi; msiexec.exe /i ${env:TEMP}\wazuh-agent.msi /q WAZUH_MANAGER="192.168.1.50" WAZUH_REGISTRATION_SERVER="192.168.1.50"
Start the agent service:
NET START Wazuh
Option B: Via Graphical Installer (GUI)
- Download the latest MSI installer directly from the official Wazuh Windows Agent Download Page.
- Run the
.msifile. - When prompted, check the box to specify manager details, enter your Wazuh Server IP (
192.168.1.50), and complete the wizard. - Open the Windows Services app (
services.msc), find Wazuh, right-click, and select Start.
5. Verifying Telemetry & Testing SIEM Detection
Head back to your Wazuh Dashboard. Click Agent Management > Summary. You should now see your newly enrolled Linux and Windows hosts listed with an Active status.
Status | Agent ID | Name | IP Address | OS ─────────┼──────────┼────────────────────┼──────────────┼───────────────────── Active | 001 | debian-nas | 192.168.1.60 | Linux / Ubuntu Active | 002 | win11-desktop | 192.168.1.75 | Windows 11 Pro
Smoke Test: Triggering an Alert
To confirm that event ingestion and rule triggers are functional:
On your Linux Endpoint: Attempt to trigger an authentication failure by SSHing with a non-existent user:
ssh fakeuser@localhost
On your Windows Endpoint: Open PowerShell as Administrator and attempt to create a fake local test user:
net user wazuh_test_user Password123! /add
In the Dashboard: Navigate to Security Events > Events and refresh the live stream. You will see real-time alerts generated:
- Level 5 Alert:
sshd: Attempt to login using non-existent user - Level 7 Alert:
Windows: A user account was created
Critical Firewall Ports Cheat-Sheet
If your server or client endpoints run local firewalls (like ufw or Windows Firewall), ensure these network ports are open:
| Port | Protocol | Direction | Purpose |
|---|---|---|---|
| 1514 | TCP | Inbound to Server | Agent Communication (Log Ingestion) |
| 1515 | TCP | Inbound to Server | Agent Auto-Enrollment Service |
| 443 | TCP | Inbound to Server | Accessing the Wazuh Dashboard Web Interface |
| 55000 | TCP | Inbound to Server | Wazuh REST API calls |
On your Wazuh server running ufw, enable them using:
sudo ufw allow 1514/tcp sudo ufw allow 1515/tcp sudo ufw allow 443/tcp sudo ufw enable
Summary
You now have an enterprise-grade SIEM platform running on your own hardware without container overhead. Your centralized server is ingesting, indexing, and analyzing system events across both Linux and Windows workloads, providing total operational visibility and security auditing across your network.