Skip to main content

Intrusion Detection FAQ

This FAQ answers common questions about Cloudaware Intrusion Detection (IDS).

What Is the Relationship Between Breeze Agent, Wazuh, and Cloudaware CMDB?

Cloudaware Intrusion Detection uses Wazuh as the underlying host-based intrusion detection engine. Breeze Agent runs on your servers or VMs and helps deploy, register, and manage the Wazuh agent lifecycle.Cloudaware CMDB then enriches IDS events with ownership, application, and environment context so alerts are routed to the right teams.

How Is Host-Based IDS Different from CSPM or Vulnerability Scanning?

  • Host-based IDS focuses on runtime behavior and changes on individual hosts, such as log events, file integrity, processes, and configuration changes.
  • Cloud Security Posture Management focuses on cloud resource configurations and misconfigurations at the control plane, for example, S3 bucket policies and security groups.
  • Vulnerability scanning identifies missing patches and known vulnerabilities in software and services.

Cloudaware combines these views so you can see, for example, that a vulnerable host in production is also generating suspicious IDS alerts.

Where Do I View IDS Alerts in Cloudaware?

  • Access Wazuh via Cloudaware Control Hub (Launcher) and use Wazuh dashboards for detailed, rule-centric views of alerts and agent health.
  • Pivot from a CI in CMDB to see related IDS findings, status, and, where configured, linked tickets.
  • Set up IDS alerts to your issue management system of choice, using Cloudaware incident webhooks.

How Are Severities, Rules, and Exceptions Managed?

Cloudaware provides a curated ruleset and default severity mapping based on Wazuh rules and Cloudaware best practices. Customers can:

  • Propose or implement custom rules.
  • Tune severities or suppress noisy rules to fit their environment.
  • Add exceptions for known, acceptable behavior.

For complex tuning, coordinate with Cloudaware support so that rules remain maintainable and upgrades remain safe.

How Does IDS Licensing Relate to Other Cloudaware Modules?

Licensing and pricing for IDS typically depend on the number of monitored endpoints. IDS may be bundled with other security capabilities, for example, as part of a broader threat or security package. Refer to your Cloudaware order form or contact your technical account manager for precise details.

Which Environments and Platforms Are Supported?

Cloudaware IDS is designed for hybrid and multi-cloud environments:

  • Cloud workloads on AWS, Microsoft Azure, Google Cloud, and other providers where agents can be installed.
  • On-premises data centers and virtualized environments such as VMware.

See Requirements for platform and network prerequisites.

What Happens If an Agent Is Removed or Stops Sending Data?

If Breeze or Wazuh agents are uninstalled or stop sending data:

  • The CI’s IDS status may change to Instance is not monitored or show health issues.
  • You can use CMDB and dashboards to identify gaps in coverage.
  • In many environments, Breeze can help detect and remediate missing agents. Discuss remediation options with Cloudaware Support.