Installing Wazuh SIEM
Deploy and configure Wazuh SIEM on Ubuntu to monitor, detect, and respond to security events in real-time.
Overview
Installing Wazuh SIEM
This project walks you through the installation and setup of Wazuh SIEM on an Ubuntu system. You'll learn how to deploy the Wazuh server, configure agents, and start monitoring endpoints for security events and compliance.
- Open-source Security Information and Event Management (SIEM)
- Real-time threat detection, file integrity monitoring, and log analysis
- Built-in rules and decoders for alerting and correlation
- Web-based Wazuh Dashboard for visualization and alert triage
- Integrates with Elasticsearch and Kibana
- Step-by-step setup on Ubuntu 20.04 / 22.04 for lab environments
What You'll Learn
-
Wazuh Server Installation & Configuration
You'll learn how to install and set up the Wazuh server on Ubuntu for centralized monitoring and analysis.
-
Agent Deployment & Registration
You'll understand how to install Wazuh agents on other machines and connect them to the server for security event collection.
-
Real-time Threat Detection
You'll explore how Wazuh uses rules and decoders to detect file changes, suspicious activity, and policy violations in real-time.
-
Security Dashboard & Visualization
You'll access and use the Wazuh web dashboard to visualize alerts, monitor system health, and track compliance.
About Trainer
Rajneesh Gupta
Rajneesh Gupta is a seasoned cybersecurity professional with over 11 years of industry experience. With a remarkable career focused on incident response, penetration testing, security compliance, and risk management, Rajneesh has established himself as a leading expert in the field. He is also an accomplished author, having penned the book "Hands-on with Blockchain and Cybersecurity". As a dedicated educator, Rajneesh has made a significant impact on the cybersecurity community by training over 60,000 students globally.
Related Projects
Apache Server Log Analysis using Splunk
Detecting Brute Force, SQL Injection, XSS, and Suspicious Web Activity from Apache Access Logs with Splunk SIEM
Practical AWS Cloud Security Posture Assessment Using Scout Suite
Identify real-world AWS attack surfaces through visual security posture analysis.
Wazuh + n8n + Anyrun: Automated Malware Analysis
Automate malware analysis by sending Wazuh-detected suspicious files into ANY.RUN, retrieving detailed reports and IOCs, and integrating results back into your SOC workflow.