Skip to main content
Connect Wazuh to let CloudThinker agents investigate alerts and agents, and change rules, decoders, and agents after you approve. Wazuh uses two accounts: a Wazuh server API user and a Wazuh indexer user.

Prerequisites

  • A Wazuh server API (port 55000) and Wazuh indexer (port 9200) that CloudThinker can reach over HTTPS.
  • Admin access to the Wazuh dashboard.

Setup

1

Create a Wazuh server API user

Create an API user for CloudThinker and give it the readonly role, which can read all information in Wazuh. If you want agents to make changes, create a role with only the policies you allow, such as rules_all_*, decoders_all_*, agents_all_*, agents_commands_*, and cluster_all_*. Avoid administrator: it also manages Wazuh users and roles. See Wazuh’s RBAC configuration for the steps.
2

Create a Wazuh indexer user

In the Wazuh dashboard, go to Indexer management → Security → Internal users and click Create internal user.Then open Roles, click Create role, and set:
  • Cluster permissions: cluster_composite_ops_ro
  • Index: wazuh-*
  • Index permissions: read
Open Mapped users, click Manage mapping, add the user, and click Map.
3

Add the connection in CloudThinker

Navigate to Connections → Wazuh and enter both accounts. Click Connect. CloudThinker signs in to both and shows a Connected status with your Wazuh version.

Connection details

Wazuh uses self-signed certificates by default. Choose Verify only if both endpoints have trusted certificates.

Required permissions

Start with readonly. The write tool is on by default; turn it off to keep the connection read-only. Every change still follows your approval settings.

Agent capabilities

Deleting an agent removes it from Wazuh, and an active response such as firewall-drop adds an IP address to the agent’s firewall deny list. Check the exact change before you approve it.

Verify the connection

Example prompts


Troubleshooting

Check the server API user’s password. This user is separate from your dashboard login.
Check the indexer user’s password in Indexer management → Security → Internal users.
The server API user signed in, but its role cannot read manager information. Give it the readonly role, or include cluster_all_* in your custom role, and connect again.
The indexer user’s role is missing read on wazuh-*. Update the role and connect again.
The Indexer URL points to an indexer without Wazuh alert data. Check that it is the indexer your Wazuh server writes alerts to.
Enter the address with https://. The same applies to the Indexer URL.
Remove anything after the port, such as /api. The same applies to the Indexer URL.
TLS certificate is set to Verify, but the endpoint uses a self-signed certificate. Choose Allow self-signed, or install a trusted certificate. The same applies to the indexer.
CloudThinker cannot reach the address. Check the URL and port, and that Wazuh accepts connections from CloudThinker. The same applies to the indexer on port 9200.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Use dedicated users — create both accounts only for CloudThinker, so you can remove them without affecting anyone else.

Graylog Connection

Log search and alert investigation

Okta Connection

Identity access reviews and sign-in investigation