Homarr
Wazuh logo

Wazuh

Security

Wazuh is an open source security platform (SIEM and XDR) that collects agent events, raises alerts and tracks vulnerabilities.

The Wazuh integration powers the Wazuh agents, Wazuh alerts and Wazuh security summary widgets.

Wazuh stores data in two places, and each uses its own users:

  • The server API (default port 55000) answers agent status and manager version.
  • The indexer (OpenSearch, default port 9200) holds alerts (wazuh-alerts-*), agent snapshots (wazuh-monitoring-*) and vulnerabilities (wazuh-states-vulnerabilities-*).

Alerts and severity counts need the indexer. Without server API credentials, agent counts come from the latest wazuh-monitoring-* snapshot, which the Wazuh dashboard writes every 15 minutes.

Adding the integration

Create the connection under Management → Integrations. See Managing integrations.

Pick the credential option that matches what you can reach:

OptionURL fieldWidgets
Username & PasswordServer API, e.g. https://wazuh:55000Agents, manager version
Username & Password & Indexer …Server API, indexer URL as a secretAll
Indexer username & Indexer passwordIndexer, e.g. https://wazuh:9200All (agents from snapshots)

Secrets

NameDescription
Username
Account username for authentication.
Password
Account password for authentication.

Steps to retrieve the credentials:

  1. Use a Wazuh API user, for example one with the built-in readonly role

Notes

  • Wazuh ships with self-signed certificates. The server API certificate can be trusted from the test connection dialog. The indexer certificate is signed by the Wazuh root CA (/etc/wazuh-indexer/certs/root-ca.pem), which has to be uploaded under Settings → Certificates.
  • A default all-in-one install binds the indexer to 127.0.0.1. Set network.host in /etc/wazuh-indexer/opensearch.yml if Homarr runs on another host.

On this page