Skip to main content

Intrusion Detection Requirements

This guide summarizes the main prerequisites for planning a Cloudaware Intrusion Detection rollout and evaluating whether your environments are ready for agent deployment.

Prerequisites

Before deploying Intrusion Detection, confirm that:

  • Cloudaware CMDB is configured with your cloud accounts and key on‑prem platforms.
  • Breeze Agent is installed on the servers and VMs where Intrusion Detection will run.

Supported Platforms

Cloudaware Intrusion Detection is designed for common enterprise operating systems and infrastructure platforms:

  • Linux – major distributions such as Red Hat Enterprise Linux, CentOS, Amazon Linux, Ubuntu, and Debian.
  • Windows – current, supported Windows Server releases.
  • Other UNIX-like systems – platforms supported by the Wazuh agent (for example, AIX, Solaris, HP‑UX, BSD).
  • Virtualization & cloud platforms – workloads running on AWS, Azure, GCP, VMware, and on‑prem hypervisors are supported as long as required agents can be installed.
tip

The Wazuh agent is designed to monitor a wide range of endpoints with low resource overhead. It is supported on the most popular operating systems and requires an average of 35 MB of RAM.

Network and Connectivity

  • Agents must reach Cloudaware-managed Wazuh endpoints over HTTPS.
  • Exact hostnames, ports, and IP ranges are provided by the Cloudaware implementation team.

Ensure firewalls, security groups, and proxies allow outbound connections from agents to the appropriate Wazuh endpoints and, where applicable, inbound traffic from Cloudaware.

Permissions and Roles

Breeze Agent

Breeze Agent requires OS-level privileges to read logs, monitor file integrity, and manage Wazuh agent lifecycle. See Breeze Requirements for details.

Cloudaware CMDB and Launcher (Control Hub)

Grant appropriate roles to security teams, operations teams, and auditors so that they can view Cloudaware Intrusion Detection data, tune rules, and run reports.

See Intrusion Detection Operations for access-control patterns.