Now that you have deployed your Wazuh server, we can get onto deploying agents to our endpoints (Windows servers, workstations, Linux boxes etc).
For housekeeping, we can create groups within the Wazuh management console, these will be used to logically group our devices.
Begin by navigating to the Wazuh drop down menu, Select Management and then Groups
Cool! Now the groups are done, we can begin deploying our agent. I'm starting with my windows workstation that sits in the bottom of my rack.
Select the Wazuh Menu again and select "agents" as this is our first agent deployment, we are taken directly to the add agent screen.
Fill in the appropriate details.
Once we have filled in all the details, you'll be presented with a PS script to run, make sure you launch PS as an administrator to install the agent.
Copy the PS script and run it! (make sure your endpoint device can reach the Wazuh Server by FQDN or IP Address BTW)
and clicking on the device will take you to detailed results - as you can see i fail haha. Thats all for now, next we'll explore either log forwarding for devices such as VCenter OR agentless monitoring for devices like my fortigate firewall :)
Comments
Post a Comment