Host-based IDS
Wazuh is a free, open-source cybersecurity platform that unifies Extended Detection and Response (XDR) and Security Information and Event Management (SIEM). Cloudaware uses Wazuh for host-based intrusion detection, security event monitoring, file integrity monitoring, and endpoint security telemetry.
Host-based IDS is a Cloudaware-managed integration. If you subscribe to the Cloudaware Intrusion Detection module, Cloudaware configures the integration automatically.
- Audience: Cloudaware administrators, security operations teams, cloud security teams
- Outcome: Host-based IDS credentials are configured and Wazuh security telemetry is available for Cloudaware Intrusion Detection workflows
Capabilities
The integration supports:
- Connection from Cloudaware to the managed Wazuh indexer
- Host-based IDS telemetry ingestion for Cloudaware Intrusion Detection
- Security event and file integrity visibility for monitored hosts
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage integrations.
- An active Cloudaware Intrusion Detection subscription, if using the Cloudaware-managed Host-based IDS service.
- Wazuh API URL, username, and password when configuring credentials manually.
Add Wazuh Credentials
To add Wazuh credentials to Cloudaware:
- In Cloudaware, go to Admin.
- Find Host-based IDS in Security integrations, then click + ADD.
- Enter the following values:
- API URL: Enter the server URL in the format
https://<WAZUH_INDEXER_HOST>, whereWAZUH_INDEXER_HOSTisWAZUH_INDEXER_HOST_NAMEplusWAZUH_INDEXER_PORT. - Username: Enter the username.
- Password: Enter the password associated with the username.
- Minimal Dangerous Level: Select the level from the drop-down list.
- Trust certificate: Check this box as the destination server’s SSL certificate does not match the domain name in the request URL (Cloudaware uses a self-signed certificate for this managed integration, this checkbox must be selected).
- API URL: Enter the server URL in the format
- Click SAVE.
- Verify the integration status.
A green status indicator means the integration is configured successfully. If the status indicator is red, contact Cloudaware Support at support@cloudaware.com.
View Host-based IDS Data
Host-based IDS data is surfaced through the Cloudaware Intrusion Detection module and related CMDB records.
To review IDS data:
- Open Intrusion Detection to review IDS workflows, dashboards, and findings.
- Open CMDB Navigator to review monitored host records and IDS status.
- Use Wazuh views for detailed event search and investigation when available from Cloudaware Control Hub.
Troubleshooting
Host-based IDS is usually configured automatically for Cloudaware-managed Intrusion Detection subscriptions.
Integration Shows Red Status
- Confirm that the API URL uses the correct
https://<WAZUH_INDEXER_HOST>format. - Confirm that the indexer host name and port are correct.
- Verify that the username and password are correct.
- Confirm that Trust certificate is selected for the Cloudaware-managed self-signed certificate.
- Check whether the selected Minimal Dangerous Level matches the intended alert threshold.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
For Cloudaware-managed Host-based IDS, coordinate credential or certificate changes with Cloudaware Support before editing or deleting the integration.
Update the Integration Details
- Go to Admin.
- Select Host-based IDS.
- Select the specific integration.
- Open the three-dot menu, then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Host-based IDS.
- Select the specific integration.
- Open the three-dot menu, then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Treat Wazuh credentials as sensitive administrative credentials.
- Store credentials only in approved credential stores.
- Rotate credentials according to your organization's credential-rotation policy.
- Limit manual changes for Cloudaware-managed Host-based IDS integrations unless directed by Cloudaware Support.