Prerequisites
- A Wazuh server API (port
55000) and Wazuh indexer (port9200) that CloudThinker can reach over HTTPS. - Admin access to the Wazuh dashboard.
Setup
Create a Wazuh server API user
readonly role, which can read all information in Wazuh. If you want agents to make changes, create a role with only the policies you allow, such as rules_all_*, decoders_all_*, agents_all_*, agents_commands_*, and cluster_all_*. Avoid administrator: it also manages Wazuh users and roles. See Wazuh’s RBAC configuration for the steps.Create a Wazuh indexer user
- Cluster permissions:
cluster_composite_ops_ro - Index:
wazuh-* - Index permissions:
read
Add the connection in CloudThinker
Connection details
Required permissions
Agent capabilities
Verify the connection
Example prompts
Troubleshooting
Manager rejected the username or password.
Manager rejected the username or password.
Indexer rejected the username or password.
Indexer rejected the username or password.
Manager account has no API access.
Manager account has no API access.
readonly role, or include cluster_all_* in your custom role, and connect again.Indexer account cannot read wazuh-alerts-4.x-*.
Indexer account cannot read wazuh-alerts-4.x-*.
read on wazuh-*. Update the role and connect again.Indexer has no wazuh-alerts-4.x-* index.
Indexer has no wazuh-alerts-4.x-* index.
The Manager URL must start with https://.
The Manager URL must start with https://.
https://. The same applies to the Indexer URL.Enter the Manager URL without a path, for example https://wazuh.example.com.
Enter the Manager URL without a path, for example https://wazuh.example.com.
/api. The same applies to the Indexer URL.Manager certificate is not trusted. Choose Allow self-signed.
Manager certificate is not trusted. Choose Allow self-signed.
Manager URL is unreachable. Check the URL and port 55000.
Manager URL is unreachable. Check the URL and port 55000.
9200.Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Use dedicated users — create both accounts only for CloudThinker, so you can remove them without affecting anyone else.