Deploy Wazuh SIEM for centralized security monitoring #35
Labels
No labels
area:documentation
area:infrastructure
area:network
area:security
priority:critical
priority:high
priority:low
priority:medium
status:blocked
type:bug
type:deployment
type:enhancement
type:investigation
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
reinitialized.net/infrastructure#35
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Overview
Deploy Wazuh as the centralized security monitoring and intrusion detection platform for the entire Reinitialized Infrastructure fleet.
Why Wazuh
Phase 1: Wazuh Manager Deployment
Phase 2: Agent Deployment
Phase 3: Detection Rules
Phase 4: Alerting and Response
Architecture
Wazuh Manager -> Wazuh Indexer (OpenSearch) -> Wazuh Dashboard (Web UI)
|
| Agent protocol (port 1514/1515)
|
+-- rp1 agent
+-- apps1 agent
+-- apps2 agent
+-- ai1 agent
+-- db1 agent
+-- ... all NixOS hosts
Acceptance Criteria
References