Skip to main content

Operations

Use this guide to operate Intrusion Detection at scale with clear governance, health monitoring, triage, maintenance, and change control.

Day-To-Day Monitoring and Triage

  • Watch Wazuh dashboards for spikes in high and critical alerts.
  • Use Cloudaware CMDB to pivot from a CI to its IDS alerts and findings, focusing on assets tagged as production or high criticality.
  • Refer to Playbooks to learn how investigate and remediate incidents.
  • Close the loop by updating tickets or change records when issues are resolved.

Health and Coverage

  • Track overall agent health: missing heartbeats, outdated agents, or hosts that should be monitored but are not.
  • Use CMDB KPI tiles such as IDS status (for example, Monitored, Not monitored, Under attack) to validate coverage against key services and environments.
  • Configure alerts for gaps, such as CIs that moved into production without IDS enabled.

Maintenance and Upgrades

Cloudaware manages much of the underlying Wazuh lifecycle, including:

  • Rolling upgrades of Wazuh components.
  • Application of security patches and configuration hardening.
  • Capacity adjustments for indexers and storage.

Access Control

  • Grant least-privilege access to IDS data and management functions: separate operational access (triage, dashboards) from configuration access (rules, exceptions).
  • Use Cloudaware RBAC to control who can view IDS alerts, modify rules, or trigger actions. See RBAC & Access Controls for patterns.
  • Ensure audit logs are retained for access and administrative actions on IDS components.