Operations
Use this guide to operate Intrusion Detection at scale with clear governance, health monitoring, triage, maintenance, and change control.
Day-To-Day Monitoring and Triage
- Watch Wazuh dashboards for spikes in high and critical alerts.
- Use Cloudaware CMDB to pivot from a CI to its IDS alerts and findings, focusing on assets tagged as production or high criticality.
- Refer to Playbooks to learn how investigate and remediate incidents.
- Close the loop by updating tickets or change records when issues are resolved.
Health and Coverage
- Track overall agent health: missing heartbeats, outdated agents, or hosts that should be monitored but are not.
- Use CMDB KPI tiles such as IDS status (for example,
Monitored,Not monitored,Under attack) to validate coverage against key services and environments. - Configure alerts for gaps, such as CIs that moved into production without IDS enabled.
Maintenance and Upgrades
Cloudaware manages much of the underlying Wazuh lifecycle, including:
- Rolling upgrades of Wazuh components.
- Application of security patches and configuration hardening.
- Capacity adjustments for indexers and storage.
Access Control
- Grant least-privilege access to IDS data and management functions: separate operational access (triage, dashboards) from configuration access (rules, exceptions).
- Use Cloudaware RBAC to control who can view IDS alerts, modify rules, or trigger actions. See RBAC & Access Controls for patterns.
- Ensure audit logs are retained for access and administrative actions on IDS components.