Map the components to jobs
The endpoint agent collects configured events and other information. The Wazuh server analyses received data using rules and decoders. The indexer stores indexed event data. The dashboard provides the investigation interface. A single-node deployment can combine central components, but they still have different responsibilities.
An agent installed on Windows is not a complete standalone SIEM. It needs a reachable, correctly configured manager for central analysis.
Keep cost and hosting honest
Wazuh software is free and open source. Servers, storage, electricity and backup capacity are still real resources. You can use suitable existing hardware to avoid a new hosting subscription. Cloudflare Pages Free serves static websites; it cannot run the complete Wazuh manager and indexer stack as a static site.
Design a small lab
- Identify a central machine that meets the current documented requirements and has room for event retention.
- Choose one non-critical endpoint first.
- Plan how the agent reaches the manager, how enrollment is protected and who can use the dashboard.
- Decide which events you want to collect and how you will prove they arrive.
Do not expose every component to the internet. A protected HTTPS dashboard route is not automatically a transport route for native agent traffic. Ports, protocols, certificates and any VPN or relay need their own design.
Verify data flow with a harmless event
After your documented deployment, enrol a test endpoint and confirm it appears active. Generate a benign event that your collection configuration supports. Check that the manager receives it and the dashboard displays it within the expected time range.
Seeing the agent service running proves less than seeing fresh correctly attributed data centrally. Similarly, a dashboard login proves less than a working ingestion path.
Plan ownership and retention
Use descriptive groups and labels to distinguish sites without putting patient or customer information into labels. Limit access to those responsible for investigation. Decide how long events are kept and how central configuration and essential data are backed up.
Common mistakes
Treating every alert as a confirmed incident creates noise. Expecting Wazuh to prevent every threat overstates monitoring capabilities. Installing agents without a working central route produces inactive endpoints. Adding many clients before verifying one good path makes faults harder to isolate.
A useful next step
Start with agent enrollment and one collection requirement, then expand deliberately. Measure data arrival, alert quality and storage use before adding more event sources.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.