Wazuh is a powerful free and open source SIEM Solution, it has a massive community backing and can collate and analyse logs, vulnerabilities and has the ability to create monitors on files, folders and even the registry.
I havent seen much in the way of deployment online, so why not start now. This will be a multi-part series on the base deployment (all-in-one VM), monitoring windows and linux endpoints and host endpoints (ESXI).
Lets Dive in!
For this deployment, i will be deploying on my Synology NAS - this is because my NAS stays on 24/7 and doesn't consume anywhere near the amount of power that my lab hosts consume.
Begin by going to the Wazuh VM Installation Page and download the OVA File.
Once downloaded, We'll navigate to the Syno and bring up Virtual Machine Manager, Select VMs > Create > OVA > Next
We'll then select Upload from PC, Find the OVA and select Next
Select a storage volume for the VM, i'm lazy and have a single volume so that'll do
Fill in whatever VM Details you like, The default is 4vCPU and 8GB of RAM with VMM, but depending on your usage, you may want to adjust these (see the Wazuh recommendations below)
You can also keep the disk size default, according to my requirements, 50GB is plenty!
aaaaannnndd thats all folks, navigate to the web interface IP and you're done. See you in part 2, We'll run through setting up some agents and devices to be monitored
Comments
Post a Comment