2.3 KiB
Wazuh Docker Deployment
Deploying Wazuh Docker in a Single-Node Configuration
This deployment uses the single-node/docker-compose.yml file, which defines a setup with one Wazuh Manager, one Wazuh Indexer, and one Wazuh Dashboard container. Follow these steps to deploy it:
-
Increase
vm.max_map_counton each Docker host that will run a Wazuh Indexer container (Linux). This setting is crucial for Wazuh Indexer to operate correctly. This command requires root permissions:sudo sysctl -w vm.max_map_count=262144Note: This change is temporary and will revert upon reboot. To make it permanent, you'll need to edit the
/etc/sysctl.conffile and addvm.max_map_count=262144, then apply withsudo sysctl -p. -
Navigate to the
single-nodedirectory within your repository:cd single-node -
Download the certificate creation script and
config.ymlfile:curl -o wazuh-certs-tool.sh https://packages.wazuh.com/5.0/wazuh-certs-tool-5.0.0-1.sh curl -o config.yml https://packages.wazuh.com/5.0/config-5.0.0-1.yml -
Edit the config.yml file with the configuration of the Wazuh components to be deployed
nodes: # Wazuh indexer server nodes indexer: - name: wazuh.indexer ip: wazuh.indexer # Wazuh server nodes # Use node_type only with more than one Wazuh manager server: - name: wazuh.manager ip: wazuh.manager # Wazuh dashboard node dashboard: - name: wazuh.dashboard ip: wazuh.dashboard -
Run the certificate creation script:
bash ./wazuh-certs-tool.sh -A -
Start the Wazuh environment using
docker compose:-
To run in the foreground (logs will be displayed in your current terminal; press
Ctrl+Cto stop):docker compose up -
To run in the background (detached mode, allowing the containers to run independently of your terminal):
docker compose up -d
-
Please allow some time for the environment to initialize, especially on the first run. It can take approximately a minute or two (depending on your host's resources) as the Wazuh Indexer starts up and generates the necessary indexes and index patterns.