How to enable HIDS in wazuh

1,361 views
Skip to first unread message

s v yashwanth

unread,
Dec 3, 2020, 4:46:23 AM12/3/20
to wa...@googlegroups.com
Hello Team, 

Could you please help me with how to enable HIDS in wazuh with a procedure. 

Thanks
Yashwanth S V

Jose Luis Carreras Marin

unread,
Dec 4, 2020, 5:30:51 AM12/4/20
to Wazuh mailing list
Hello Yashwanth, 
Could you be a little more specific about what you are looking for?
Wazuh is already a default HIDS system:

Host-based Intrusion Detection System (HIDS)
Wazuh agent runs at a host-level, combining anomaly and signature based technologies to detect intrusions or software misuse. It can also be used to monitor user activities, assess system configuration and detect vulnerabilities.


Do you mean how to install or configure Wazuh agents?

Greetings, Jose

s v yashwanth

unread,
Dec 9, 2020, 11:47:32 PM12/9/20
to Wazuh mailing list
Hello Jose,
We have already installed wazuh in our environment, but we need to know that, what specific features of HIDS are there in wazuh.
If available, please send me each configuration process

Jose Luis Carreras Marin

unread,
Jan 4, 2021, 5:09:04 AM1/4/21
to Wazuh mailing list
Hello Yashwanth

Here you can see a list of the Wazuh's intrusion detection capabilities:

Each and every one of them can be configured directly through the configuration file of each agent (ossec.conf), or in a centralized way from the manager (agent.conf).
In the link of the previous documentation, you can see a section "configuration" in each of the capacities. If you are interested in knowing more about the centralized configuration mode, you can read about it here:


The configuration process is based on the preferences of each system and is highly customizable. If you wish, you can ask any question you may have about the process.

Greetings, Jose
Reply all
Reply to author
Forward
0 new messages