Wazuh on a VPS: Open-Source SIEM for Security Monitoring and Threat Detection
Wazuh is a free, open-source SIEM (Security Information and Event Management) platform — it collects logs from all your servers via lightweight agents, detects intrusions, monitors file integrity, checks for vulnerabilities, and provides compliance reporting (PCI-DSS, HIPAA, GDPR). It replaces commercial SIEM tools costing $10,000+/year with a self-hosted platform on a single VPS.
What Wazuh Monitors
- Log analysis: SSH auth, sudo, application errors, firewall events
- File Integrity Monitoring (FIM): Alerts when critical files change (SSH keys, cron, sudoers)
- Rootkit detection: Scans for known rootkit signatures
- Vulnerability assessment: Compares installed packages against CVE database
- Active response: Automatically blocks IPs that trigger alerts
- Compliance: Maps events to PCI-DSS, HIPAA, GDPR, NIST frameworks
Step 1: Install Wazuh (Docker)
<code"># Wazuh requires 4+ GB RAM — use a dedicated monitoring VPS # System requirements: 4 GB RAM, 2 vCPU, 50+ GB disk mkdir -p /opt/wazuh && cd /opt/wazuh # Download official Docker Compose git clone https://github.com/wazuh/wazuh-docker.git -b v4.9.0 cd wazuh-docker/single-node # Generate certificates (required for Wazuh) docker compose -f generate-indexer-certs.yml run --rm generator # Start the stack docker compose up -d # Wazuh stack includes: # - wazuh-manager: core SIEM engine # - wazuh-indexer: OpenSearch (log storage) # - wazuh-dashboard: Kibana-like UI # Check all containers are healthy: docker compose ps
Step 2: Nginx Reverse Proxy for Dashboard
<code">sudo nano /etc/nginx/sites-available/wazuh
<code">server {
listen 443 ssl http2;
server_name wazuh.yourdomain.com;
ssl_certificate /etc/letsencrypt/live/wazuh.yourdomain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/wazuh.yourdomain.com/privkey.pem;
location / {
proxy_pass https://127.0.0.1:5601;
proxy_http_version 1.1;
proxy_ssl_verify off; # Wazuh dashboard uses self-signed cert
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_read_timeout 300s;
}
}
<code">sudo certbot --nginx -d wazuh.yourdomain.com sudo systemctl reload nginx # Default credentials: admin / SecretPassword (change immediately) # Located in config/wazuh_indexer_ssl_certs/
Step 3: Install Wazuh Agent on Monitored VPS
<code"># On each VPS you want to monitor (run as root):
# This installs the lightweight Wazuh agent that ships data to the manager
curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | \
gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg \
--import && chmod 644 /usr/share/keyrings/wazuh.gpg
echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] \
https://packages.wazuh.com/4.x/apt/ stable main" | \
tee /etc/apt/sources.list.d/wazuh.list
sudo apt update
sudo apt install -y wazuh-agent
# Configure the agent to connect to your Wazuh manager VPS:
sudo nano /var/ossec/etc/ossec.conf
<code"><ossec_config>
<client>
<server>
<address>YOUR_WAZUH_MANAGER_IP</address>
<port>1514</port>
<protocol>tcp</protocol>
</server>
</client>
</ossec_config>
<code">sudo systemctl daemon-reload sudo systemctl enable wazuh-agent sudo systemctl start wazuh-agent # On the Wazuh manager — enroll the new agent: # Dashboard → Agents → Deploy new agent → follow wizard # Or CLI: docker exec wazuh-manager /var/ossec/bin/manage_agents -a
Step 4: Configure File Integrity Monitoring
<code"># On the monitored VPS — configure FIM rules: sudo nano /var/ossec/etc/ossec.conf
<code"><syscheck> <disabled>no</disabled> <frequency>43200</frequency> <!-- Check every 12 hours --> <scan_on_start>yes</scan_on_start> <!-- Monitor critical system files --> <directories check_all="yes">/etc/ssh</directories> <directories check_all="yes">/etc/sudoers.d</directories> <directories check_all="yes">/etc/cron.d</directories> <directories check_all="yes" report_changes="yes">/etc/nginx/sites-enabled</directories> <!-- Monitor web root --> <directories check_all="yes" report_changes="yes">/var/www</directories> <!-- Ignore log and dynamic files --> <ignore>/etc/mtab</ignore> <ignore>/etc/hosts.deny</ignore> <ignore type="sregex">.log$|.swp$</ignore> </syscheck>
<code">sudo systemctl restart wazuh-agent
Step 5: Set Up Active Response
<code"># Active response automatically blocks IPs that trigger security alerts # On Wazuh manager: wazuh-docker/config/wazuh_cluster/wazuh_manager.conf <active-response> <command>firewall-drop</command> <location>local</location> <rules_id>5763,5764</rules_id> <!-- SSH brute force rules --> <timeout>600</timeout> <!-- Block for 10 minutes --> </active-response> <!-- Also block on multiple failed logins --> <active-response> <command>firewall-drop</command> <location>local</location> <rules_group>authentication_failures</rules_group> <timeout>3600</timeout> <!-- Block for 1 hour --> </active-response>
Step 6: Vulnerability Assessment
<code"># Wazuh agents scan installed packages against the CVE database automatically # View in Dashboard: Vulnerability Detection → select agent # Manual scan trigger: docker exec wazuh-manager /var/ossec/bin/wazuh-db query 1 "syscollector_packages select * from sys_packages" # High-severity CVE alert configuration: # Dashboard → Management → Configuration → Vulnerability Detection # Alert on: critical (CVSS >= 9.0) vulnerabilities
Getting Started
Wazuh’s Docker stack needs 4 GB RAM — deploy on a dedicated monitoring VPS separate from production. A 4 GB Ubuntu VPS at VPS.DO runs the Wazuh manager, indexer, and dashboard while monitoring 5–10 agents. Each agent uses only 50 MB RAM on the monitored VPS. For compliance purposes, Wazuh’s built-in PCI-DSS and HIPAA reports provide evidence of security controls at no additional cost.
Conclusion
Wazuh provides enterprise-grade SIEM capabilities — log analysis, file integrity monitoring, vulnerability detection, active threat response, and compliance reporting — at open-source pricing. For VPS operators running multiple servers, Wazuh’s centralized visibility catches security incidents that individual server logs miss: coordinated attacks across servers, lateral movement, privilege escalation, and configuration drift. The compliance frameworks are particularly valuable for teams seeking SOC2 or PCI-DSS certification.