Wazuh Security Monitoring Server is a ready to use security monitoring and threat detection platform with a web dashboard and agent enrollment. It analyzes security data across endpoints, clouds, and networks to detect threats, respond to incidents, and ensure compliance, helping organizations strengthen their security posture through continuous monitoring and automation. Launch the instance and sign in using the auto generated credentials created on first boot. Built on Ubuntu with Docker Compose for reliable startup and easy management. This product has charges associated with it for the provision and deployment of the application and AMI support.
Wazuh Security Monitoring Server provides security visibility, threat detection, and alerting for servers and endpoints through a centralized web dashboard. This AMI is designed for beginners who want a working system immediately, without manual setup.
After you launch the instance, a first boot wizard automatically completes the initial configuration and generates secure login credentials. The dashboard is available over HTTPS on port 443 using a self signed certificate by default.
Key capabilities include endpoint monitoring with Wazuh agents, centralized event collection, dashboards for security activity, and a scalable data store for search and investigations. The deployment runs in Docker containers managed by Docker Compose, making it simple to check status, view logs, and restart services.
Recommended network access is limited to the dashboard and agent ports, and you should keep backend ports private for best security. This product is packaged and maintained by Code Creator and is intended for customers who want a fast, guided path to deploying Wazuh on AWS.
Highlights
One click launch with first boot wizard that auto configures the system and generates secure login credentials
Web based security dashboard for monitoring alerts and investigating events from your servers and endpoints
Built on Ubuntu with Docker Compose for reliable startup easy upgrades and simple container management
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour based on the EC2 instance size you pick for this pre-built Wazuh threat detection server. Each dimension maps to one instance type, so pricing scales with the compute you choose. General-purpose options include the t2, t3, and t3a families and the m6i family, ranging from medium sizes up to 8xlarge. Storage-focused i3 and i3en options are also available. Larger instances give you more CPU, memory, or storage capacity. You are billed only for the hours each instance runs.
Top-of-mind questions for buyers
What does one hour of billing cover for this Wazuh server?
One hour covers the software running on a single EC2 instance of the size you select. Billing counts each clock hour the instance runs. You pick one instance type, and its hourly rate applies for every hour that instance stays active.
Am I charged when the instance is stopped or powered off?
The hourly software charge applies only while the instance runs. A fully stopped instance stops accruing software charges. You may still pay separate AWS fees for attached storage or other resources, but the software meters running time only.
How do the general-purpose and storage-focused instance types differ for my bill?
Each dimension is one instance type, billed independently by the hour. You run one at a time, so only its rate applies. General-purpose t2, t3, t3a, and m6i types favor balanced CPU and memory. The i3 and i3en types add local storage capacity for data-heavy detection workloads.
www.codecreator.com
Helpful?
Vendor refund policy
No contracts. We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This release delivers a clean rebuild of Wazuh Threat Detection Server by Code Creator on Ubuntu 26.04 LTS with Wazuh 4.14.5, including automatic first-boot setup with unique dashboard credentials and certificates, simplified status and access commands, secure default network exposure, and complete removal of prior credentials, test data, agents, SSH keys, and system history. Fresh dashboard access, service health, and Linux agent enrollment were validated for a safer, faster path to endpoint visibility.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Deploy a production-ready Wazuh security monitoring and SIEM stack on AWS in minutes. Includes Wazuh, OpenSearch, Filebeat, and Grafana for log management, threat detection, and compliance.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.