Wazuh SIEM and XDR Platform - Ready-to-Run Security

AWS Security

Unified security monitoring, threat detection and compliance from a single console

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

Wazuh is a free and open source security platform that unifies SIEM and XDR capabilities. Agents on Linux, Windows and macOS endpoints collect logs, file integrity events and software inventories, the Wazuh server correlates them against thousands of detection rules, and the Wazuh dashboard presents log data analysis, intrusion detection, file integrity monitoring, vulnerability detection, security configuration assessment, compliance reporting and MITRE ATT&CK mapping in one console. This image ships the complete platform: the Wazuh indexer, the Wazuh server and the Wazuh dashboard, installed with the project's own all-in-one deployment and managed by systemd.

Why the cloudimg image

Nothing shared ships in the image. Every documented Wazuh default login and every build time password is removed before capture, and on the first boot of each instance the appliance regenerates the whole TLS certificate chain, including a fresh root certificate authority, and rotates every indexer account and both server API accounts to random per instance passwords written to a root only file. Security event indices and the server's queue, alerts and archives each get their own independently resizable data volume, the management API is bound to loopback, an unauthenticated liveness endpoint is served for load balancer health checks, and a paired deploy guide walks through enrollment and sizing. 24/7 support is included.

Common uses

  • Centralise security telemetry from a fleet of servers, workstations and cloud workloads
  • Detect intrusions, malware and unauthorised file changes across enrolled endpoints
  • Evidence regulatory compliance with built in policy assessment and reporting dashboards

Key features

  • Complete Wazuh SIEM and XDR platform in one appliance - indexer, server, and dashboard preconfigured for log analysis, file integrity monitoring, intrusion detection, vulnerability detection, security configuration assessment, and MITRE ATT&CK mapping, ready to receive agents immediately after launch.
  • Zero shared secrets - every default password is removed from the image and on first boot all indexer accounts, server API accounts, and the full TLS certificate chain including the root CA are regenerated uniquely for your instance, so no credential or private key is ever reused across deployments.
  • Production-ready infrastructure from first boot - security indices and server data each reside on dedicated, independently resizable EBS volumes, the management API is bound to loopback by default, and a built-in unauthenticated health endpoint supports Elastic Load Balancing and Auto Scaling checks.

See it running

Real screenshots taken while testing this image against its deployment guide.

Wazuh SIEM and XDR Platform - Ready-to-Run Security screenshot 1 Wazuh SIEM and XDR Platform - Ready-to-Run Security screenshot 2 Wazuh SIEM and XDR Platform - Ready-to-Run Security screenshot 3 Wazuh SIEM and XDR Platform - Ready-to-Run Security screenshot 4

Description

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

## Wazuh - Unified SIEM and XDR on AWS

This image delivers the complete Wazuh security platform as a single, ready-to-run appliance: the Wazuh indexer, the Wazuh server, and the Wazuh dashboard, installed with the project's official all-in-one deployment, fully patched, and managed by systemd. Point your agents at it and you have log analysis, file integrity monitoring, intrusion detection, vulnerability detection, configuration assessment, and MITRE ATT&CK mapping in one console.

## Why This Image Instead of a Manual Install

A manual Wazuh deployment means installing three interdependent components, generating and distributing a TLS certificate chain, wiring the dashboard to the indexer and the server API, and hardening every default credential. This image removes all of it:

  • Every credential is unique to your instance. Wazuh's documented default logins and the installer's build-time passwords are both eliminated from the image. On first boot the appliance rotates every indexer account and both server API accounts to freshly generated random passwords, then writes them to a root-only file. No shared or default credential ever ships.
  • Every TLS certificate is unique to your instance. The entire certificate chain - root certificate authority, indexer, filebeat, and dashboard certificates - is regenerated on first boot using the project's own certificate tool, so no private key is ever shared between deployments.
  • Dedicated data volumes. Security event indices and the server's queue, alerts and archives live on their own independently resizable disks rather than competing with the operating system for space.
  • Server API bound to loopback. The management API is reachable only from the instance itself by default, never exposed to the internet unless you deliberately publish it.
  • Health endpoint for load balancers. An unauthenticated liveness endpoint is served for Elastic Load Balancing and Auto Scaling health checks without handing out credentials.
  • Fully patched at build. The operating system is brought to a complete security baseline at build time.

## What You Can Do With It

  • Endpoint detection and response - deploy Wazuh agents to Linux, Windows, and macOS hosts and collect their telemetry centrally.
  • Log data analysis - collect, parse, and correlate logs from operating systems, applications, and cloud services against thousands of detection rules.
  • File integrity monitoring - detect changes to critical files and registry keys, with who-data attribution.
  • Vulnerability detection - correlate installed software inventories against vulnerability feeds.
  • Security configuration assessment - continuously score endpoints against hardening policies.
  • Regulatory compliance reporting - built-in dashboards map findings to common compliance frameworks.
  • MITRE ATT&CK mapping - see which techniques your alerts correspond to.

## Example Deployment

A platform team consolidating security telemetry from a fleet of EC2 instances launches this image, opens the agent enrollment ports to their VPC, and enrolls agents from each host. Within minutes the dashboard shows live security events, agent inventory, file integrity changes, and vulnerability findings across the fleet, with no separate log pipeline to build or maintain.

## Quick Start

1. Launch the image with a security group allowing inbound TCP 443 from your administrators and TCP 1514 and 1515 from the hosts you will enroll.

2. Wait a few minutes for first boot to generate this instance's certificates and credentials.

3. Connect over SSH and read the per-instance dashboard password from the root-only credentials file.

4. Open the dashboard in your browser over HTTPS and sign in.

5. Use the dashboard's agent deployment wizard to enroll your first endpoint.

## 24/7 Support Included

cloudimg provides around-the-clock technical support covering deployment, upgrades, agent enrollment, rule and decoder tuning, storage sizing, and integration questions.

---

Wazuh is a trademark of Wazuh Inc. Wazuh is distributed under the GNU General Public License version 2. All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

Related technologies

wazuhsiemxdrsecurity monitoringintrusion detectionlog analysisfile integrity monitoringvulnerability detectioncomplianceendpoint detectionthreat detectionsecurity analyticswazuh agents