Skip to main content

Navigation in Wazuh

Cloudaware Intrusion Detection (IDS) uses the Wazuh platform. This guide explains how to navigate in Wazuh and use its dashboards and raw data views.

Access Wazuh

Before accessing Wazuh, make sure Breeze Agent is installed on the hosts you want to monitor. You can check host status from the IDS tile in CMDB.

To open Wazuh:

  1. Contact Cloudaware Support at support@cloudaware.com to request access to the Wazuh app.
  2. Open the Cloudaware Control Hub (Launcher).
  3. Start the Wazuh app.
  • Install Breeze Agent on the hosts you want to monitor.
  • Contact Cloudaware support at support@cloudaware.com to ensure that IDS is enabled for those hosts and that agents are healthy (see the IDS tile in CMDB).
  • Open the Cloudaware Control Hub (Launcher) and start the Wazuh app.

Once in Wazuh, work in three areas:

  • Wazuh (Overview) – summarized security views such as Security Events and File Integrity Monitoring.
  • Discover (Raw data) – detailed event lists for deep investigation.
  • Management > Watcher - threshold alerts and watchers that can be set up for alerting.

Wazuh Tab

Security Events Dashboard

From the Wazuh (Overview) tab, go to Security Information Management and open Security Events.

Common widgets in the Security Events dashboard include:

  • Alert level evolution – shows how many IDS events occurred at each severity across the selected period. Use it to spot spikes in high or critical activity.
  • Alerts over time – displays the overall alert volume trend.
  • Top agents – highlights hosts with the highest alert counts. Selecting an agent filters the dashboard to that host.
  • Top rule groups – shows which rule groups generate the most alerts.
  • Agent status – summarizes agent connectivity and health.
  • Alerts summary – a tabular view of rules (rule ID, description, level, count) for sorting and inspection.
  • Groups summary – a tabular view of rule groups and counts.

Use this dashboard as a starting point for understanding where Intrusion Detection noise and risk are concentrated.

File Integrity Monitoring Dashboard

From the Wazuh (Overview) tab, open the Integrity Monitoring section to focus on File Integrity Monitoring (FIM):

  • View changes to critical files, binaries, configuration paths, and registries.
  • Correlate file-change activity with agents and rules.
  • Distinguish expected changes, such as patches and deployments, from suspicious activity.

Use FIM dashboard when you are investigating change‑driven incidents or verifying FIM coverage.

Time Range, Search, and Filters

You can refine the views in Wazuh with:

  • Time picker – in the top‑right corner, choose relative or absolute ranges (for example, last 15 minutes or a specific incident window).
  • Fields and columns – expand fields in the sidebar to see top values and add them as columns to the event table.
  • Filters from charts – click a bar, slice, or table value to add it as a filter; use the filter bar to enable, pin, or exclude filters.
  • Zoom controls – zoom in/out on specific values or time slices to focus on a host, rule, or short time window.

Discover (Raw Data)

The Discover view provides low‑level access to individual events:

  • See a time‑ordered list of events matching your selected index and time range.
  • Expand an event row to inspect all fields captured by Wazuh (host, rule IDs, paths, users, etc.).
  • Add fields as columns to the table to build an event view tailored to your investigation.
  • Drag over the time histogram to zoom into a specific period; reset with the time picker.
  • Apply filters by clicking field values or using the filter bar to keep only events that match a host, rule, path, or user.

Use the Discover view when you need to reconstruct a timeline, validate that rules are firing correctly, or export detailed event slices.

Watcher

Use Management > Watcher to create threshold alerts and advanced watchers for alerting workflows.

See Wazuh Alerts & Watchers for watcher configuration guidance.