Wazuh
Security
Wazuh is an open source security platform (SIEM and XDR) that collects agent events, raises alerts and tracks vulnerabilities.
The Wazuh integration powers the Wazuh agents, Wazuh alerts and Wazuh security summary widgets.
Wazuh stores data in two places, and each uses its own users:
- The server API (default port
55000) answers agent status and manager version. - The indexer (OpenSearch, default port
9200) holds alerts (wazuh-alerts-*), agent snapshots (wazuh-monitoring-*) and vulnerabilities (wazuh-states-vulnerabilities-*).
Alerts and severity counts need the indexer. Without server API credentials, agent counts come from the latest wazuh-monitoring-* snapshot, which the Wazuh dashboard writes every 15 minutes.
Adding the integration
Create the connection under Management → Integrations. See Managing integrations.
Pick the credential option that matches what you can reach:
| Option | URL field | Widgets |
|---|---|---|
| Username & Password | Server API, e.g. https://wazuh:55000 | Agents, manager version |
| Username & Password & Indexer … | Server API, indexer URL as a secret | All |
| Indexer username & Indexer password | Indexer, e.g. https://wazuh:9200 | All (agents from snapshots) |
Secrets
| Name | Description |
|---|---|
Username | Account username for authentication. |
Password | Account password for authentication. |
Steps to retrieve the credentials:
- Use a Wazuh API user, for example one with the built-in readonly role
Notes
- Wazuh ships with self-signed certificates. The server API certificate can be trusted from the test connection dialog. The indexer certificate is signed by the Wazuh root CA (
/etc/wazuh-indexer/certs/root-ca.pem), which has to be uploaded under Settings → Certificates. - A default all-in-one install binds the indexer to
127.0.0.1. Setnetwork.hostin/etc/wazuh-indexer/opensearch.ymlif Homarr runs on another host.