Project Overview
This project demonstrates the deployment of Wazuh, an open-source, industry-recognized SIEM and host-based intrusion detection platform, in a virtualized lab environment. Wazuh was selected for this project due to its wide adoption in security operations, strong community support, and alignment with real-world SOC practices.
A Wazuh Manager was installed on an Ubuntu system and configured to centrally monitor three endpoints: Windows, Kali Linux, and Ubuntu. Each endpoint was successfully enrolled as a Wazuh agent and configured to forward system logs and security events to the manager for analysis.
The project validates end-to-end log collection and visibility through the Wazuh web dashboard, demonstrating how security events from multiple operating systems can be centrally analyzed. This setup reflects a realistic enterprise monitoring scenario and highlights the effectiveness of Wazuh as a cost-effective, open-source security monitoring solution used across modern SOC environments.
Tools Used
- Wazuh SIEM (Open Source): Centralized security monitoring, log collection, and host-based intrusion detection platform
- Ubuntu Server: Hosting the Wazuh Manager, Indexer, and Web Dashboard
- Windows : Endpoint monitored using the Wazuh agent (Agent 1)
- Kali Linux: Linux endpoint monitored using the Wazuh agent (Agent 2)
- Ubuntu: Linux endpoint monitored using the Wazuh agent (Agent 3)
- VMware Workstation: Virtualization platform used to host all systems
- Web Browser (Windows): Used to access the Wazuh web dashboard over HTTPS
Wazuh Deployment
Wazuh was deployed on Ubuntu Server using the official all-in-one installation script, following the Wazuh deployment guide. 🫡
on Medium, where people are continuing the conversation by highlighting and responding to this story.
SOCIAL SHARE CARD GENERATOR