Skip to main content

Reference

This guide contains reference information for Cloudaware Intrusion Detection: Wazuh version details, network ports and protocols, log retention, and supported signals.

Wazuh Version

As of March 2026, Cloudaware-managed IDS environments run Wazuh 4.14.4, which includes security and stability improvements for the manager, agents, and Docker integration. Cloudaware may upgrade Wazuh over time.

See also: Wazuh 4.14.4 Release Notes

Ports and Protocols

Exact endpoints and ports are environment-specific and may change over time. Treat the table below as a pattern.

DirectionComponentsProtocols and PortsNotes
Agent to Wazuh/IDS serverBreeze/Wazuh agentsHTTPS; TCP 80/443 or environment-specific portsAgents send events and heartbeats to Wazuh endpoints.
Wazuh components internalManager, indexer, dashboardsWazuh defaults, such as 1514/1515 and 9200Internal to the Wazuh stack; usually not exposed externally.

Cloudaware operates the Wazuh stack and provides the necessary endpoints and CIDR ranges during implementation.

Log Retention and Indexing

Intrusion Detection events are stored in Wazuh, which uses the Kibana-based UI:

  • Events are indexed for fast search and dashboarding for a recent time window.
  • Older logs are archived automatically for cost-efficient, long-term retention.
  • IDS data follows the default 3-month retention policy; however, data retention periods may vary by tenant and may be extended as agreed with the tenant.

For investigation and compliance, you can combine IDS events with other logs (cloud-native, application, network) in a single search.

Supported Signals

Cloudaware IDS builds on Wazuh’s host-based capabilities. Depending on your configuration, supported signals can include:

  • File Integrity Monitoring (FIM) and change tracking for critical paths and registries.
  • Log inspection for system, security, and application logs.
  • Authentication and authorization activity, including sudo and role changes.
  • Process, service, and kernel-level events indicative of malware or intrusion attempts.
  • Configuration and policy checks aligned with security benchmarks and standards.

Additional checks can be enabled through custom Wazuh rules and decoders. For advanced use cases, contact Cloudaware Support at support@cloudaware.com.