How to Install Wazuh SIEM on Ubuntu Server (Bare-Metal) & Enroll Linux and Windows Agents

By Seth Sanders | 12-Year IT Systems Engineer & Systems Administrator Veteran

If you self-host services at home or manage small business infrastructure, collecting system logs isn't enough—you need to correlate those logs, monitor file integrity, detect vulnerabilities, and respond to threats automatically. That is where a SIEM (Security Information and Event Management) platform comes in.

Wazuh is arguably the best open-source SIEM and XDR (Extended Detection and Response) platform available. It provides real-time security monitoring, regulatory compliance checks, file integrity monitoring (FIM), and incident response capabilities—completely free. (If you want a deeper look at the core concepts and capabilities before installing, read our guide on What is a SIEM? Introduction to Wazuh).

While many homelabbers deploy software inside Docker containers, running Wazuh natively on bare-metal Ubuntu Server gives you superior performance for disk-heavy indexing, avoids network stack abstraction issues, and allows for precise resource tuning.

In this guide, we will cover:

1. Prerequisites & Architecture Overview

Before firing up the terminal, it helps to understand what happens under the hood. Wazuh consists of three main underlying services:

┌─────────────────────────────────────────────────────────┐
│                      Wazuh Server                       │
│  ┌─────────────────┐ ┌───────────────┐ ┌─────────────┐  │
│  │  Wazuh Indexer  │ │ Wazuh Manager │ │  Dashboard  │  │
│  │ (OpenSearch Engine)│ │  (Engine)     │ │  (Web UI)   │  │
│  └─────────▲───────┘ └───────▲───────┘ └─────────────┘  │
└────────────┼─────────────────┼──────────────────────────┘
             │                 │ Ports: 1514/1515 TCP
             │                 │
     ┌───────┴───────┐   ┌─────┴─────────┐
     │ Linux Endpoint│   │ Windows Host  │
     │  wazuh-agent  │   │  wazuh-agent  │
     └───────────────┘   └───────────────┘

System Requirements (Single-Node Server)

2. Installing the Wazuh Stack on Ubuntu Server

We will use the official Wazuh all-in-one assistant. This script handles installing the custom repositories, configuring system limits, generating self-signed SSL certificates, and building the Indexer, Manager, and Dashboard on a single host.

Step 1: Update System Packages

SSH into your clean Ubuntu server and make sure everything is up to date:

sudo apt update && sudo apt upgrade -y
sudo apt install -y curl apt-transport-https gnupg tar

Step 2: Run the Official Installation Assistant

Download and execute the official installer using the all-in-one (-a) flag:

curl -sO https://packages.wazuh.com/4.10/wazuh-install.sh
sudo bash ./wazuh-install.sh -a

(Note: The process takes 5 to 15 minutes depending on your internet connection and CPU speed.)

Step 3: Save Your Credentials

When the script finishes, it will output a summary block in your terminal containing your unique admin credentials:

INFO: --- Summary ---
INFO: You can access the web interface https://<YOUR_SERVER_IP>
INFO: User: admin
INFO: Password: <RANDOM_GENERATED_PASSWORD>

IMPORTANT: Copy and save this password to your password manager immediately. It will not be shown again.

Step 4: Verify Services

Confirm that all essential services are active and running natively:

sudo systemctl status wazuh-indexer wazuh-manager wazuh-dashboard

You can now open a browser, navigate to https://<YOUR_SERVER_IP>, accept the self-signed SSL certificate warning, and log in with your admin credentials.

3. Enrolling a Linux Endpoint (Ubuntu/Debian)

Now that our core SIEM is online, let's start sending logs from another Linux server or desktop on your network.

Step 1: Generate the Deployment Command

  1. Open the Wazuh Dashboard in your browser.
  2. Click the Navigation Menu (☰) in the top left > Agent Management > Summary.
  3. Click the Deploy new agent button in the top right.
  4. Select your endpoint options:
    • Operating System: Linux
    • Architecture: x86_64 or arm64
    • Distribution: DEB (Ubuntu/Debian)
    • Server Address: The static IP of your Wazuh Manager (e.g., 192.168.1.50).
    • Agent Name: (Optional) Give it a recognizable hostname like debian-nas or ubuntu-web-server.

Step 2: Install and Start the Agent on the Linux Machine

The dashboard will auto-generate a single-line command. SSH into the Linux client machine you want to monitor and run it:

wget https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_4.10.0-1_amd64.deb && sudo WAZUH_MANAGER='192.168.1.50' dpkg -i ./wazuh-agent_4.10.0-1_amd64.deb

Once installed, reload systemd, enable the service on boot, and start it:

sudo systemctl daemon-reload
sudo systemctl enable wazuh-agent
sudo systemctl start wazuh-agent

Check the log on the client machine to verify connection:

sudo tail -f /var/ossec/logs/ossec.log | grep -i "connected"

You should see: INFO: Connected to the server (192.168.1.50:1514/tcp).

4. Enrolling a Windows Endpoint

Windows endpoint security is where SIEMs shine—Wazuh natively collects Windows Event Logs, monitors privilege escalation, tracks system changes, and monitors Windows Defender events out of the box.

Option A: Via PowerShell (Fastest)

Open PowerShell as Administrator on your Windows target system and execute:

Invoke-WebRequest -Uri https://packages.wazuh.com/4.x/windows/wazuh-agent-4.10.0-1.msi -OutFile ${env:TEMP}\wazuh-agent.msi; msiexec.exe /i ${env:TEMP}\wazuh-agent.msi /q WAZUH_MANAGER="192.168.1.50" WAZUH_REGISTRATION_SERVER="192.168.1.50"

Start the agent service:

NET START Wazuh

Option B: Via Graphical Installer (GUI)

  1. Download the latest MSI installer directly from the official Wazuh Windows Agent Download Page.
  2. Run the .msi file.
  3. When prompted, check the box to specify manager details, enter your Wazuh Server IP (192.168.1.50), and complete the wizard.
  4. Open the Windows Services app (services.msc), find Wazuh, right-click, and select Start.

5. Verifying Telemetry & Testing SIEM Detection

Head back to your Wazuh Dashboard. Click Agent Management > Summary. You should now see your newly enrolled Linux and Windows hosts listed with an Active status.

Status   | Agent ID | Name               | IP Address   | OS
─────────┼──────────┼────────────────────┼──────────────┼─────────────────────
Active   | 001      | debian-nas         | 192.168.1.60 | Linux / Ubuntu
Active   | 002      | win11-desktop      | 192.168.1.75 | Windows 11 Pro

Smoke Test: Triggering an Alert

To confirm that event ingestion and rule triggers are functional:

On your Linux Endpoint: Attempt to trigger an authentication failure by SSHing with a non-existent user:

ssh fakeuser@localhost

On your Windows Endpoint: Open PowerShell as Administrator and attempt to create a fake local test user:

net user wazuh_test_user Password123! /add

In the Dashboard: Navigate to Security Events > Events and refresh the live stream. You will see real-time alerts generated:

Critical Firewall Ports Cheat-Sheet

If your server or client endpoints run local firewalls (like ufw or Windows Firewall), ensure these network ports are open:

Port Protocol Direction Purpose
1514 TCP Inbound to Server Agent Communication (Log Ingestion)
1515 TCP Inbound to Server Agent Auto-Enrollment Service
443 TCP Inbound to Server Accessing the Wazuh Dashboard Web Interface
55000 TCP Inbound to Server Wazuh REST API calls

On your Wazuh server running ufw, enable them using:

sudo ufw allow 1514/tcp
sudo ufw allow 1515/tcp
sudo ufw allow 443/tcp
sudo ufw enable

Summary

You now have an enterprise-grade SIEM platform running on your own hardware without container overhead. Your centralized server is ingesting, indexing, and analyzing system events across both Linux and Windows workloads, providing total operational visibility and security auditing across your network.