Skip to main content

Dashboards & Reporting

Use this guide to learn how to monitor IDS activity, investigate alerts in Wazuh dashboards, track IDS coverage in CMDB, and prepare reports for compliance and management reviews.

Wazuh uses a Kibana-based interface for raw data exploration and dashboards.

Wazuh Dashboards

Using Cloudaware Control Hub (Launcher), you can access Wazuh dashboards that provide:

  • Overview of alerts by severity, rule, and source.
  • Agent status views such as connected, disconnected, outdated, or misconfigured agents.
  • Specialized dashboards for file integrity, authentication events, and policy compliance.

Use these dashboards for deep security analysis and investigating specific incidents.

Wazuh Searches and Saved Views

Raw Intrusion Detection events are also available in Wazuh:

  • Build saved searches for common investigations, such as high-severity IDS alerts in production in the last 24 hours.
  • Correlate IDS alerts with other log sources such as cloud-native audit logs, application logs, and network telemetry.
  • Create team-specific views for SecOps, application owners, and auditors.

CMDB List Views and KPIs

At the CMDB level, you can:

  • Display IDS status and key metrics on CI layouts and service views.
  • Use default CMDB list views (HIDS) to track coverage and trends, for example, the percentage of critical CIs monitored by IDS.
  • Combine IDS metrics with vulnerability and patch status for a more complete risk picture.

Reporting for Compliance and Management

  • Prepare regular reports showing IDS coverage, high and critical alerts, and response times.
  • Use mappings from Findings & Rules to demonstrate adherence to frameworks such as PCI DSS, HIPAA, and CIS.
  • Include examples of how IDS findings triggered remediation via tickets or automation.

Where possible, standardize dashboards and reports so that they can be reused across audits and recurring reviews.