Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Wazuh All-in-One on Ubuntu 24.04 LTS

Wazuh All-in-One on Ubuntu 24.04 LTS — Support & Quick Start

Wazuh 4.12 open-source SIEM/XDR — manager, indexer, and dashboard in one VM on Ubuntu 24.04 LTS.

At a glance

Application ports443 (dashboard, HTTPS self-signed); agent ports 1514/tcp and 1515/tcp are NOT opened in the in-image firewall — run `sudo ufw allow 1514/tcp` and `sudo ufw allow 1515/tcp` plus NSG rules when enrolling agents
Open in browserhttps://<VM-IP>/
Admin credential filesudo cat /var/ossec/etc/wazuh-admin-password
Sign in asadmin
Service(s)wazuh-manager, wazuh-indexer, wazuh-dashboard
Configuration/var/ossec/etc/ossec.conf (manager); /etc/wazuh-indexer/opensearch.yml; /etc/wazuh-dashboard/opensearch_dashboards.yml
Logs/var/ossec/logs/ossec.log; journalctl -u wazuh-dashboard -f; /var/log/wazuh-indexer/
VersionWazuh 4.14.7 all-in-one (manager + indexer + dashboard; fixes CVE-2026-30893) in image 2026.917.1654 and later; Wazuh 4.12.0 in earlier images
PlatformUbuntu 24.04 LTS

Quick start

  1. Deploy from the Azure Marketplace (Get It Now → Create), choosing your SSH key at the Administration step.
  2. Allow inbound SSH (22) for yourself plus the application port(s): 443 (dashboard) to your IP; 1514/1515 to your agents after opening them in ufw — restrict to your own IP where possible. The in-image firewall already allows them; only the Network Security Group (NSG) keeps them closed.
  3. Open https://<VM-IP>/ (self-signed certificate) and sign in as admin (see First login below).
  4. Deploy Wazuh agents to your fleet from the dashboard's agent-enrollment wizard (open 1514/1515 in ufw and the NSG first).

First login / credentials

This image generates its admin credential on the VM at first boot — nothing is pre-set. SSH into the VM with the username + key you chose at deploy, then print the generated credential:

ssh <your-username>@<VM-IP>
sudo cat /var/ossec/etc/wazuh-admin-password

Sign in as admin.

  1. Print the generated admin password (WAZUH_ADMIN_PASSWORD) from the file — first boot rotates the build-time credentials and deletes the installer password bundles.
  2. Open https://<VM-IP>/ (accept the self-signed certificate) and sign in as admin.
  3. Change the password (Security → Internal users) and replace the certificates before production. Enroll agents from the dashboard after opening 1514/1515 in ufw and the NSG.

Sign in as admin with the password in /var/ossec/etc/wazuh-admin-password. The installer's wazuh-passwords.tar.gz bundle is removed at first boot (it no longer exists on the VM).

Troubleshooting

SymptomCheckFix
`sudo apt upgrade` does not update Wazuh`cat /etc/apt/sources.list.d/wazuh.list` shows the `deb` line commented outBy design on images 2026.917.1654 and later: Wazuh recommends disabling its repository after installing, so the indexer, server and dashboard cannot be upgraded out of step. To upgrade, re-enable the line and follow https://documentation.wazuh.com/current/upgrade-guide/upgrading-central-components.html (indexer, then server, then dashboard).

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or send a message via the contact form. Include the offer name, VM size, region, and any log output — sudo journalctl -u <service> -n 100 usually tells the story.