---
title: "Wazuh"
description: "Wazuh SIEM/XDR read and control. Queries alerts, vulnerabilities, and top rule aggregations from the Wazuh Indexer (OpenSearch) over HTTP Basic auth, and exchanges Basic credentials for a short-lived JWT at /security/user/authenticate to drive the Wazuh Server API. Read actions: search_alerts, search_vulnerabilities, top_alert_rules, cluster_health, list_indices, list_agents, agent_summary. Control actions: restart_agent, add_agent, remove_agent, move_agent_to_group, trigger_active_response (push commands like firewall-drop to one agent or the entire fleet), restart_manager, update_cdb_list (push to CDB block/allow lists that drive the rule engine). Default hostnames assume the operator places `wazuh-indexer.local` and `wazuh-api.local` in /etc/hosts (or behind a local TLS reverse proxy with an mkcert certificate)."
canonical: "https://hub.ironclaw.com/marketplace/wazuh"
markdown: "https://hub.ironclaw.com/marketplace/wazuh.md"
type: "tool"
version: "0.1.0"
author: "IronHub"
category: "Dev Tools"
tags: ["WASM tool","HTTP allowlist"]
---

# Wazuh

> Wazuh SIEM/XDR read and control. Queries alerts, vulnerabilities, and top rule aggregations from the Wazuh Indexer (OpenSearch) over HTTP Basic auth, and exchanges Basic credentials for a short-lived JWT at /security/user/authenticate to drive the Wazuh Server API. Read actions: search_alerts, search_vulnerabilities, top_alert_rules, cluster_health, list_indices, list_agents, agent_summary. Control actions: restart_agent, add_agent, remove_agent, move_agent_to_group, trigger_active_response (push commands like firewall-drop to one agent or the entire fleet), restart_manager, update_cdb_list (push to CDB block/allow lists that drive the rule engine). Default hostnames assume the operator places `wazuh-indexer.local` and `wazuh-api.local` in /etc/hosts (or behind a local TLS reverse proxy with an mkcert certificate).

## Details

- **Type:** Tool
- **Version:** 0.1.0
- **Author:** IronHub
- **Category:** Dev Tools
- **Status:** live
- **Tags:** WASM tool, HTTP allowlist


## Documentation

Wazuh SIEM/XDR read and control. Queries alerts, vulnerabilities, and top rule aggregations from the Wazuh Indexer (OpenSearch) over HTTP Basic auth, and exchanges Basic credentials for a short-lived JWT at /security/user/authenticate to drive the Wazuh Server API. Read actions: search_alerts, search_vulnerabilities, top_alert_rules, cluster_health, list_indices, list_agents, agent_summary. Control actions: restart_agent, add_agent, remove_agent, move_agent_to_group, trigger_active_response (push commands like firewall-drop to one agent or the entire fleet), restart_manager, update_cdb_list (push to CDB block/allow lists that drive the rule engine). Default hostnames assume the operator places `wazuh-indexer.local` and `wazuh-api.local` in /etc/hosts (or behind a local TLS reverse proxy with an mkcert certificate).

## Links

- [HTML page](https://hub.ironclaw.com/marketplace/wazuh)
- [Source](https://github.com/nearai/ironhub/blob/main/tools/wazuh)
- [Documentation](https://github.com/nearai/ironhub/blob/main/tools/wazuh/wazuh-tool.capabilities.json)
