Back to articles
Technology Insight

Centralized Security Management: Deploying Wazuh SIEM on Dedicated Cloud VPS for 50+ Client Servers

June 1, 2026

Introduction: The Growing Challenge of Multi-Server Security

In today's interconnected digital ecosystem, managing infrastructure securely has become exponentially complex. For managed service providers (MSPs), system integrators, and enterprise IT departments, overseeing a fleet of 50+ client servers scattered across various environments is a daunting task. Traditional decentralized log management and fragmented monitoring tools no longer suffice against sophisticated cyber threats.

To achieve comprehensive visibility, real-time threat detection, and regulatory compliance, organizations require a centralized security architecture. This blog post provides an in-depth technical roadmap for establishing a centralized security management system for 50+ client servers using Wazuh SIEM hosted on a high-performance, dedicated Cloud VPS. By consolidating security telemetry into a single pane of glass, businesses can proactively defend their assets while optimizing operational efficiency.

Why Choose Wazuh SIEM for Client Infrastructure Monitoring?

Wazuh is a powerful, open-source security monitoring platform that combines Endpoint Detection and Response (EDR) capabilities with traditional Security Information and Event Management (SIEM) functionalities. It is uniquely suited for scaling across diverse client environments for several reasons:

  • Comprehensive Protection: Wazuh monitors system log data, file integrity, cloud infrastructure, and running processes to detect anomalies, rootkits, and malware.
  • Multi-Tenant Capabilities: Through customizable agent grouping, RBAC (Role-Based Access Control), and index management, Wazuh allows administrators to securely monitor distinct clients within a unified architecture.
  • Active Response: Wazuh does not merely alert; it can execute automated scripts on endpoints to block malicious IPs, terminate unauthorized processes, or isolate compromised hosts.
  • Cost Effectiveness: Being open-source, Wazuh eliminates the prohibitive licensing fees associated with commercial SIEM tools like Splunk or QRadar, allowing businesses to scale up to 50+ servers seamlessly.

Sizing the Foundation: Dedicated Cloud VPS Architecture

Deploying a SIEM capable of handling continuous telemetry from over 50 active client endpoints requires a robust, predictable infrastructure backend. A shared hosting environment is fundamentally inadequate. A dedicated Cloud VPS ensures that resources like CPU, RAM, and I/O throughput are strictly isolated, avoiding performance degradation during high-traffic security incidents or log bursts.

Recommended Hardware Specifications

For a baseline environment supporting 50 to 100 endpoints with standard log generation rates, the dedicated Cloud VPS should meet or exceed the following specifications:

  • vCPU: 8 Cores (High-frequency processors preferred for heavy indexing).
  • RAM: 16 GB to 32 GB (Wazuh and its underlying Indexer are memory-intensive applications).
  • Storage: 200 GB to 500 GB NVMe SSD configured for high IOPS. Storage requirements vary directly with log retention policies.
  • Network: 1 Gbps unmetered port to ingest continuous data streams reliably.
Note: Implementing a solid data retention policy—such as archiving raw logs to cost-effective cold storage after 30 days while keeping hot indices on NVMe for immediate analysis—is crucial for maximizing storage efficiency.

Step-by-Step Deployment Strategy

Phase 1: Setting Up the Central Wazuh Server

The modern Wazuh architecture consists of three primary components that can be installed on your dedicated Cloud VPS: the Wazuh Indexer (highly-scalable full-text search engine), the Wazuh Server (manager analyzing data and triggering alerts), and the Wazuh Dashboard (the web UI).

  1. OS Preparation: Deploy a clean installation of a stable Linux distribution, such as Ubuntu Server 22.04 LTS or Rocky Linux 9, on your dedicated Cloud VPS. Ensure the OS is updated and non-essential services are disabled.
  2. Installation via the Wazuh Assistant: For standard high-performance single-node deployments, utilize the official, secure installation script provided by Wazuh. This automates the generation of certificates, configures elastic search configurations, and secures communication between components using TLS 1.3.
  3. Hardening the SIEM Dashboard: Immediately change default administrative passwords, restrict access to the dashboard via a reverse proxy (e.g., Nginx) secured with Let's Encrypt SSL, and implement Multi-Factor Authentication (MFA).

Phase 2: Network Configuration and Secure Log Ingestion

Connecting 50+ external client servers requires precise network planning to prevent exposure to unauthorized traffic while guaranteeing uninterrupted log shipping.

By default, the Wazuh Manager communicates over specific ports. You must configure the Cloud VPS firewall (such as UFW or cloud security groups) to strictly regulate incoming traffic:

  • Port 1514 (TCP/UDP): Used for secure agent communication and log collection. Encrypted natively by Wazuh.
  • Port 1515 (TCP): Used for agent enrollment and certificate distribution. Access to this port should be tightly controlled or restricted behind a VPN/IP whitelist where possible.
  • Port 443 (TCP): Used exclusively for administrative access to the Wazuh Web Dashboard. Access should be restricted to company VPN IPs.

Phase 3: Deploying and Mass-Configuring Client Agents

Manually configuring 50+ individual client servers is inefficient and prone to human error. Automation is paramount during this stage.

Utilize configuration management tools such as Ansible, Puppet, or Chef to orchestrate the deployment. An Ansible playbook can automate the following process across all target client nodes:

  1. Import the official Wazuh repository key onto the client OS.
  2. Install the lightweight wazuh-agent package.
  3. Configure the agent configuration file (ossec.conf) to point to the public static IP or domain name of your dedicated Cloud VPS.
  4. Register the agent securely using an enrollment token and start the service.

Optimizing Performance for 50+ Multi-Tenant Environments

Once your 50+ client servers start transmitting data simultaneously, the Wazuh Manager will process hundreds of events per second (EPS). Optimization prevents bottlenecks, data loss, and UI latency.

1. Agent Grouping and Centralized Configuration

Do not manage configurations locally on each client server. Use Wazuh's Centralized Configuration (agent.conf) feature. Group your clients based on their operational profiles (e.g., "Web-Servers", "Database-Servers", "Windows-Domain-Controllers"). This allows you to push targeted file integrity monitoring (FIM) intervals and specific log collection policies to subsets of servers simultaneously from the central dashboard.

2. Tuning Indexer JVM Memory Heap

The Wazuh Indexer runs on Java. By default, it may not utilize the full capabilities of your dedicated Cloud VPS. Adjust the JVM heap sizes in the jvm.options configuration file. A golden rule for dedicated instances is to allocate 50% of your total available RAM to the indexer heap (e.g., allocate 8 GB of heap for a 16 GB RAM VPS), leaving the remaining memory for the OS page cache and the Wazuh manager daemon.

3. Refining Rulesets and Suppressing False Positives

An influx of 50+ servers will initially generate a high volume of alerts. Left unmanaged, "alert fatigue" will diminish your security posture. Dedicate the first two weeks of deployment to refining rulesets. Identify frequent benign logs—such as predictable internal cron jobs or health check probes—and write custom rules to suppress or lower their alert levels.

Conclusion: Proactive Security at Scale

Centralizing the monitoring of 50+ client servers onto a single Wazuh SIEM platform hosted on a dedicated Cloud VPS strikes the perfect balance between robust security enterprise capabilities, cost predictability, and operational agility. It empowers IT administrators to move away from a reactive, firefighting mindset toward structured, proactive incident response.

By leveraging dedicated cloud resources, automated deployments, and precise performance tuning, your organization can successfully mitigate risks, ensure continuous compliance, and maintain an unyielding defense line against modern cyber threats.

Centralized Security Management: Deploying Wazuh SIEM on Dedicated Cloud VPS for 50+ Client Servers | DPTCloud