Wazuh 101: How I set up my SIEM in an afternoon and connected it to a Windows agent
This article explains step by step and in a practical way how to deploy the Wazuh SIEM platform on a VMware virtual machine and incorporate a Windows agent. It is designed for beginners and for technical teams that want a clear and efficient guide. We also include information about Q2BSTUDIO, a software development company and specialists in artificial intelligence and cybersecurity, which can help you implement and optimize this type of solution.
Prerequisites and basic recommendations
Before starting, make sure you have VMware Workstation, VMware Player or VMware ESXi, access to the Wazuh OVA image, a Windows machine for the agent and connectivity between both. Reserve at least 4 CPUs, 8 GB of RAM and 40 GB of disk for the VM if you are going to use it in test environments. If it is for production, increase resources and consider deploying on AWS or Azure cloud. Open the necessary ports in firewalls: 1514 for agent-manager communication, 1515 for the authentication process and 55000 for the API and web panel. Always validate the exact version and ports in the official Wazuh documentation.
Download and import the OVA
1 Download the official OVA from the Wazuh repository or from the download portal. 2 In VMware select import OVA or open file and point to the downloaded file. 3 During import adjust name, datastore and network policy. For testing use bridged or NAT network mode depending on whether you need the machine to be accessible from the local network or only from the host.
VM configuration after import
1 Configure CPU and memory resources according to the recommendation. 2 Verify the network adapter and connectivity. 3 Increase the disk if you are going to retain long logs. 4 Start the VM and access the console to complete the initial configuration that comes with the OVA, such as static network configuration if you prefer. If the OVA includes the Wazuh and Kibana interface, follow the on-screen instructions to obtain the panel URL and initial credentials or to set new secure credentials.
Install and register the agent on Windows
1 Download the Wazuh agent MSI installer from the manager machine or from the official website. 2 On Windows run the installer as administrator. 3 During installation indicate the IP or DNS name of the Wazuh manager. 4 Register the agent with the manager using the provided registration tool or through the manager's authentication service. If your deployment uses authd, make sure the authentication service is enabled on the manager and that the agent can reach the authentication port. 5 Check that the agent appears in the agent list of the Wazuh web panel or through the API on port 55000.
Verification and testing
1 Open the Wazuh web panel or the Kibana app and go to the agents section. 2 Confirm that the Windows agent appears and its status is active. 3 Perform simple tests such as creating a test file or modifying a registry key to verify that events are sent and detected. 4 Review agent logs on Windows and manager logs on the VM to troubleshoot communication or authentication errors.
Common troubleshooting
If the agent does not connect, verify network connectivity to the manager ports, review local firewall rules on Windows, confirm that the date and time are synchronized between agent and manager and validate that the keys and certificates (if used) are correct. Also check that there are no group policies blocking agent services or processes.
Best practices and security
For production environments consider separating components on different hosts or containers, enabling TLS encryption between agents and manager, using strong authentication and maintaining backups and log rotation. Integrate the solution with monitoring and alerting mechanisms and automate agent deployment with provisioning tools or scripts to reduce manual errors.
How Q2BSTUDIO can help
At Q2BSTUDIO we offer comprehensive services to deploy, configure and maintain SIEM solutions based on Wazuh, as well as custom developments to integrate security with your applications. We are experts in custom applications and custom software and we offer AWS and Azure cloud services to scale infrastructures. We also provide business intelligence services and solutions with Power BI to transform security data into actionable reports. Our capabilities in artificial intelligence and AI for businesses allow us to complement cybersecurity with AI agents that automate detection and response.
Services we offer related to this project
Consulting and implementation of Wazuh and other SIEM platforms, deployment on AWS or Azure cloud, development of custom connectors and dashboards, managed monitoring and response, business intelligence and Power BI projects, AI integration for advanced analytics and development of AI agents and automations to improve detections.
Summary and next step
In an afternoon it is possible to have a functional SIEM with Wazuh on VMware and a Windows agent reporting data if you follow the basic steps of OVA import, VM configuration, agent installation and communication verification. If you prefer to delegate the work or expand the solution to production with security and performance guarantees, contact Q2BSTUDIO for an evaluation and personalized proposal. With our experience in cybersecurity, custom software, artificial intelligence and cloud services we help you transform security management into a competitive advantage.
Keywords custom applications custom software artificial intelligence cybersecurity AWS and Azure cloud services business intelligence services AI for businesses AI agents power bi





