Building a Centralized Intrusion Detection System (IDS/IPS) and SIEM with Wazuh
Building a Centralized Intrusion Detection System (IDS/IPS) and SIEM with Wazuh on VPS 2026
In the context of increasingly sophisticated cyberattacks, simply equipping a basic Firewall is no longer enough to protect a business's VPS infrastructure. A modern security system needs the capability to automatically detect, analyze logs in real-time, and respond quickly to intrusive behaviors. Wazuh—an open-source security platform combining EDR (Endpoint Detection and Response), IDS (Intrusion Detection System), and SIEM (Security Information and Event Management)—is the most comprehensive "shield" available today.
1. What is Wazuh? Why do you need SIEM for VPS systems?
Wazuh is more than just antivirus software; it is a centralized security data analysis system. When you have 10 or 100 VPS instances, logging into each machine to check logs is impossible. Wazuh collects logs from all servers (Endpoints) and pushes them to a single processing center (Wazuh Manager) for analysis using intelligent Rulesets.
- HIDS (Host-based IDS): Monitors system file changes, detects Rootkits, and identifies abnormal background processes.
- SIEM: Aggregates logs from SSH, Web Servers, Databases, and Firewalls into a holistic view of infrastructure security.
- Vulnerability Detection: Automatically scans and lists software vulnerabilities (CVEs) existing on your VPS so you can patch them promptly.
// Simulating the structure of a security alert in the Wazuh SIEM system
interface WazuhAlert {
timestamp: string;
agentName: string;
level: number; // Severity level from 1-15
ruleDescription: string;
sourceIp: string;
actionTaken: "logged" | "blocked" | "quarantined";
}
const bruteForceAlert: WazuhAlert = {
timestamp: "2026-04-17T10:30:00Z",
agentName: "vps-prod-01",
level: 12,
ruleDescription: "SSH Brute Force attack detected",
sourceIp: "1.2.3.4",
actionTaken: "blocked"
};
console.log(`Alert: ${bruteForceAlert.ruleDescription} from IP ${bruteForceAlert.sourceIp}`);
2. Centralized Wazuh Deployment Architecture
To build this system effectively, you need a VPS with enough power to act as the "Brain" (Wazuh Manager) and the target servers (Wazuh Agents).
2.1. Core Components
- Wazuh Indexer: A search and data analysis engine (based on OpenSearch) that optimally stores billions of log records.
- Wazuh Server: Contains Decoders and Rulesets to make alerting decisions.
- Wazuh Dashboard: A data visualization interface to help you track attack patterns in real-time.
2.2. Minimum Hardware Requirements for Wazuh Manager
| Number of Agents | CPU (Cores) | RAM (GB) | Storage (NVMe) |
|---|---|---|---|
| 1 - 25 Agents | 4 Cores | 8 GB | 50 GB |
| 25 - 100 Agents | 8 Cores | 16 GB | 200 GB+ |
3. Monitoring Intrusive Behavior and Brute Force Attacks
One of the most powerful features of Wazuh is Active Response. When an IP is detected trying to guess an SSH password too many times (Brute Force), the Wazuh Manager commands the Agent to execute a script to block that IP immediately at the target VPS's firewall level.
// Example logic for executing an automatic Active Response
interface ActiveResponseConfig {
ruleId: number;
timeoutSeconds: number;
command: string;
}
function triggerBlock(ip: string, config: ActiveResponseConfig): void {
console.log(`Executing command: ${config.command} block ${ip} for ${config.timeoutSeconds}s`);
// Logic to call firewall-cmd or iptables APIs
}
const sshBruteForceRule: ActiveResponseConfig = {
ruleId: 5712, // Default Wazuh rule ID for SSH brute force
timeoutSeconds: 3600, // Block for 1 hour
command: "firewall-drop.sh"
};
triggerBlock("1.2.3.4", sshBruteForceRule);
4. File Integrity Monitoring (FIM)
How do you know if a hacker has breached your system and injected malicious code into your index.php file? FIM solves this by creating hashes for critical files and continuously comparing them.
If any change occurs (file added, modified, or deleted), the SIEM system records: who modified it, when, and exactly what content was changed. This is key to detecting Deface attacks (changing website interfaces).
5. Centralized Log Management from Multiple VPS
Instead of storing logs in scattered locations, the Wazuh Agent pushes all data to the Manager via an AES-encrypted channel. This allows you to query the access history of the entire system with just a few clicks on the Dashboard.
// Configuration structure for an Agent sending logs to the Server
interface AgentLogConfig {
serverIp: string;
protocol: "tcp" | "udp";
port: number;
logPaths: string[];
}
const vpsAgent: AgentLogConfig = {
serverIp: "10.0.0.1", // IP of the Wazuh Manager
protocol: "tcp",
port: 1514,
logPaths: [
"/var/log/auth.log",
"/var/log/nginx/access.log",
"/var/log/mysql/error.log"
]
};
console.log(`Connecting agent to ${vpsAgent.serverIp}:${vpsAgent.port}...`);
6. Upgrading to Security Compliance Standards
Wazuh provides ready-made rulesets based on international standards like PCI DSS (for card payments), GDPR, or CIS Benchmarks. The system automatically scores your VPS security and provides recommendations for kernel reconfiguration and disabling unnecessary services to minimize attack risk (Hardening).
7. Practical SIEM Wazuh Deployment Workflow
To build a successful system, you should follow these steps:
- Initialize Central VPS: Install Wazuh Indexer and Manager using Docker or automated installation scripts.
- Configure HTTPS and SSL: Protect the Dashboard with SSL certificates to prevent hackers from intercepting administrative information.
- Install Agents on Satellite VPS: Use the
Wazuh-Agentcommand to register servers into the SIEM system. - Tune Rulesets: Eliminate False Positives from valid business processes.
- Configure Telegram/Slack Alerts: Ensure technical teams receive instant notifications when critical incidents occur.
// Example of sending a security alert to Telegram via Webhook
async function sendTelegramAlert(alert: WazuhAlert) {
const message = `🚨 Security Alert Level ${alert.level}!\nServer: ${alert.agentName}\nContent: ${alert.ruleDescription}`;
const botToken = "YOUR_BOT_TOKEN";
const chatId = "YOUR_CHAT_ID";
// Simulate sending request
console.log(`Sending notification to Telegram: ${message}`);
}
sendTelegramAlert(bruteForceAlert);
8. Conclusion: The Importance of Proactive Defense
Building an IDS/IPS and SIEM system with Wazuh not only helps you detect attacks but also provides a clear understanding of your system's security "health." In an era where data is the most valuable asset, investing in a centralized monitoring system is a smart move to optimize resources and protect your business's reputation.
Remember: Security is not a destination, but a continuous journey. Good luck building a safe and robust VPS system!
