Reference
This guide contains reference information for Cloudaware Intrusion Detection: Wazuh version details, network ports and protocols, log retention, and supported signals.
Wazuh Version
As of March 2026, Cloudaware-managed IDS environments run Wazuh 4.14.4, which includes security and stability improvements for the manager, agents, and Docker integration. Cloudaware may upgrade Wazuh over time.
See also: Wazuh 4.14.4 Release Notes
Ports and Protocols
Exact endpoints and ports are environment-specific and may change over time. Treat the table below as a pattern.
| Direction | Components | Protocols and Ports | Notes |
|---|---|---|---|
| Agent to Wazuh/IDS server | Breeze/Wazuh agents | HTTPS; TCP 80/443 or environment-specific ports | Agents send events and heartbeats to Wazuh endpoints. |
| Wazuh components internal | Manager, indexer, dashboards | Wazuh defaults, such as 1514/1515 and 9200 | Internal to the Wazuh stack; usually not exposed externally. |
Cloudaware operates the Wazuh stack and provides the necessary endpoints and CIDR ranges during implementation.
Log Retention and Indexing
Intrusion Detection events are stored in Wazuh, which uses the Kibana-based UI:
- Events are indexed for fast search and dashboarding for a recent time window.
- Older logs are archived automatically for cost-efficient, long-term retention.
- IDS data follows the default 3-month retention policy; however, data retention periods may vary by tenant and may be extended as agreed with the tenant.
For investigation and compliance, you can combine IDS events with other logs (cloud-native, application, network) in a single search.
Supported Signals
Cloudaware IDS builds on Wazuh’s host-based capabilities. Depending on your configuration, supported signals can include:
- File Integrity Monitoring (FIM) and change tracking for critical paths and registries.
- Log inspection for system, security, and application logs.
- Authentication and authorization activity, including sudo and role changes.
- Process, service, and kernel-level events indicative of malware or intrusion attempts.
- Configuration and policy checks aligned with security benchmarks and standards.
Additional checks can be enabled through custom Wazuh rules and decoders. For advanced use cases, contact Cloudaware Support at support@cloudaware.com.