> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Wazuh

> Connect Wazuh to CloudThinker to investigate alerts and agents, and manage rules, decoders, and agents with approval

Connect Wazuh to let CloudThinker agents investigate alerts and agents, and change rules, decoders, and agents after you approve. Wazuh uses **two accounts**: a Wazuh server API user and a Wazuh indexer user.

***

## Prerequisites

* A Wazuh server API (port `55000`) and Wazuh indexer (port `9200`) that CloudThinker can reach over HTTPS.
* Admin access to the Wazuh dashboard.

***

## Setup

<Steps>
  <Step title="Create a Wazuh server API user">
    Create an API user for CloudThinker and give it the `readonly` role, which can read all information in Wazuh. If you want agents to make changes, create a role with only the policies you allow, such as `rules_all_*`, `decoders_all_*`, `agents_all_*`, `agents_commands_*`, and `cluster_all_*`. Avoid `administrator`: it also manages Wazuh users and roles. See Wazuh's [RBAC configuration](https://documentation.wazuh.com/current/user-manual/api/rbac/configuration.html) for the steps.
  </Step>

  <Step title="Create a Wazuh indexer user">
    In the Wazuh dashboard, go to **Indexer management → Security → Internal users** and click **Create internal user**.

    Then open **Roles**, click **Create role**, and set:

    * **Cluster permissions**: `cluster_composite_ops_ro`
    * **Index**: `wazuh-*`
    * **Index permissions**: `read`

    Open **Mapped users**, click **Manage mapping**, add the user, and click **Map**.
  </Step>

  <Step title="Add the connection in CloudThinker">
    Navigate to **Connections → Wazuh** and enter both accounts. Click **Connect**. CloudThinker signs in to both and shows a **Connected** status with your Wazuh version.
  </Step>
</Steps>

***

## Connection details

| Field | Description | Example |
| - | - | - |
| **Manager URL** | Wazuh server API address, without a path | `https://manager.example.com:55000` |
| **Manager username** | Wazuh server API user | `cloudthinker` |
| **Manager password** | Password of that user | — |
| **Indexer URL** | Wazuh indexer address, without a path | `https://indexer.example.com:9200` |
| **Indexer username** | Wazuh indexer user | `cloudthinker` |
| **Indexer password** | Password of that user | — |
| **TLS certificate** | **Allow self-signed** (default) or **Verify** | **Verify** |

Wazuh uses self-signed certificates by default. Choose **Verify** only if both endpoints have trusted certificates.

***

## Required permissions

| Account | Read only | With changes |
| - | - | - |
| **Server API user** | `readonly` role, plus the `logtest_all_*` policy to test log lines | A role with only the policies you allow (see Setup) |
| **Indexer user** | `read` on `wazuh-*` | Same |

<Tip>
  Start with `readonly`. The write tool is on by default; turn it off to keep the connection read-only. Every change still follows your [approval](/guide/approval) settings.
</Tip>

***

## Agent capabilities

| Capability | Description |
| - | - |
| **Alerts** | Search alerts by time, agent, rule, level, or text |
| **Agents** | Agent status, inventory, file integrity, configuration checks, and vulnerabilities |
| **Rules and decoders** | Read rules and decoders, and test a log line against them |
| **Changes** | Edit or delete custom rule and decoder files, restart the Wazuh manager to apply them, restart, group, or delete agents, and run active responses, each with approval |

<Warning>
  Deleting an agent removes it from Wazuh, and an active response such as `firewall-drop` adds an IP address to the agent's firewall deny list. Check the exact change before you approve it.
</Warning>

### Verify the connection

```text theme={null}
Summarize my Wazuh: version, agents by status, and alerts from the last 24 hours
```

### Example prompts

```text theme={null}
Which Wazuh rules fired most on agent 003 in the last 48 hours?
Test this log line against my Wazuh rules and tell me which rule matches
Show file integrity changes and failed configuration checks for Wazuh agent 003
```

***

## Troubleshooting

<Accordion title="Manager rejected the username or password.">
  Check the server API user's password. This user is separate from your dashboard login.
</Accordion>

<Accordion title="Indexer rejected the username or password.">
  Check the indexer user's password in **Indexer management → Security → Internal users**.
</Accordion>

<Accordion title="Manager account has no API access.">
  The server API user signed in, but its role cannot read manager information. Give it the `readonly` role, or include `cluster_all_*` in your custom role, and connect again.
</Accordion>

<Accordion title="Indexer account cannot read wazuh-alerts-4.x-*.">
  The indexer user's role is missing `read` on `wazuh-*`. Update the role and connect again.
</Accordion>

<Accordion title="Indexer has no wazuh-alerts-4.x-* index.">
  The **Indexer URL** points to an indexer without Wazuh alert data. Check that it is the indexer your Wazuh server writes alerts to.
</Accordion>

<Accordion title="The Manager URL must start with https://.">
  Enter the address with `https://`. The same applies to the Indexer URL.
</Accordion>

<Accordion title="Enter the Manager URL without a path, for example https://wazuh.example.com.">
  Remove anything after the port, such as `/api`. The same applies to the Indexer URL.
</Accordion>

<Accordion title="Manager certificate is not trusted. Choose Allow self-signed.">
  **TLS certificate** is set to **Verify**, but the endpoint uses a self-signed certificate. Choose **Allow self-signed**, or install a trusted certificate. The same applies to the indexer.
</Accordion>

<Accordion title="Manager URL is unreachable. Check the URL and port 55000.">
  CloudThinker cannot reach the address. Check the URL and port, and that Wazuh accepts connections from CloudThinker. The same applies to the indexer on port `9200`.
</Accordion>

***

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Use dedicated users** — create both accounts only for CloudThinker, so you can remove them without affecting anyone else.

***

## Related

<CardGroup cols={2}>
  <Card title="Graylog Connection" icon="https://mintcdn.com/cloudthinker/PAPf7dQXz6G9xwkG/images/icons/graylog.svg?fit=max&auto=format&n=PAPf7dQXz6G9xwkG&q=85&s=11bac41a029ed27ed4c8a6a988847722" href="/guide/connections/graylog" width="256" height="256" data-path="images/icons/graylog.svg">
    Log search and alert investigation
  </Card>

  <Card title="Okta Connection" icon="https://mintcdn.com/cloudthinker/6kGAil0P51KlEpCK/images/icons/okta.svg?fit=max&auto=format&n=6kGAil0P51KlEpCK&q=85&s=e5523c86a9750a1f56631ddc2e781aeb" href="/guide/connections/okta" width="24" height="24" data-path="images/icons/okta.svg">
    Identity access reviews and sign-in investigation
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.