Menu
ls111's Cybersecurity Blog
  • Home
  • Contact
ls111's Cybersecurity Blog

Wazuh SIEM & XDR Agent Installation – Virtual Lab Building Series: Ep9

Posted on June 9, 2022September 19, 2023 by wp_writer

In Episode 9 of our cyber security virtual lab building series, we are going to install and explore the Wazuh Security Platform which is a SIEM (Security Incident & Event Management) platform, as well as its Linux and Windows XDR/EDR agents.

In this lab we will look at how to deploy the prebuilt Wazuh OVA image into Virtualbox, VMWare and Hyper-V and configure its static IP address connecting it to our lab network. We will then deploy Wazuh agents to our Ubuntu 20.04 server as well as our Windows 10 Pro desktop.

This video is the first addition to our Security Operations Center (SOC ) building series, so please don’t forget to turn on notifications so you can be immediately notified of future videos I will be publishing, next up is the installation of TheHive, MISP and Cortex so don’t miss it! If you have been enjoying this series so far, please don’t forget to like and subscribe!

Links used in this lab:

  • https://wazuh.com/
  • https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.hostclient.doc/GUID-8ABDB2E1-DDBF-40E3-8ED6-DC857783E3E3.html
  • https://documentation.wazuh.com/current/deployment-options/virtual-machine/virtual-machine.html

Commands used in this lab:

ip add
sudo vi /etc/sysconfig/network-scripts/ifcfg-eth0
Shift+ :wq (save and quit)
Sudo systemctl restart network 

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Welcome to my blog! I discuss and showcase various cybersecurity topics. If you prefer to learn through watching video, please check out my YouTube channel, most of the content here also has a video version.

YouTube Channel
GitHub

ls111 [0xC][Guru]

trophy 24741 door 129 target 19

tryhackme.com

Search by Category

  • Active Directory
  • Blue Team/Defensive
  • Cyber Security Lab Building Series
  • datadog
  • docker
  • Elasticsearch
  • General Cybersecurity
  • Kibana
  • Logstash
  • Network Security
  • OPNSense Firewall
  • Red Team/Pen Testing
  • SASE
  • Security Compliance
  • SIEM
  • Splunk Enterprise
  • TryHackMe Labs
  • Ubuntu Linux
  • Virtualization
  • Wazuh SIEM & XDR
  • Zenarmor NGFW

Search by Date

  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • December 2022
  • October 2022
  • September 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
©2025 ls111's Cybersecurity Blog | Powered by Superb Themes
Menu
ls111's Cybersecurity Blog
  • Home
  • Contact