Listing Thumbnail

    Perimattic Managed Wazuh - SIEM and Security Monitoring on AWS

     Info
    Deployed on AWS
    Production-ready Wazuh SIEM with full root access, automated configuration, and security hardening - an open-source alternative to commercial SIEM solutions for threat detection on AWS.

    Overview

    This fully managed Wazuh solution delivers a production-ready SIEM and security monitoring platform on AWS, built on Ubuntu 24.04 LTS. Every instance is pre-configured with security best practices, optimized indexing, and automated operations.

    Why Choose Wazuh on AWS?

    Wazuh provides enterprise-grade security monitoring without commercial SIEM licensing costs. This AMI gives you full root and OS-level access to configure custom rules, decoders, integrations, and compliance modules. Deploy a complete security operations center with intrusion detection, vulnerability scanning, and compliance reporting.

    Key Features

    Complete SIEM Platform Wazuh Manager, Indexer, and Dashboard pre-configured and ready to receive agent data. Monitor file integrity, detect intrusions, assess vulnerabilities, and generate compliance reports.

    Automated Setup On first login, an interactive setup script configures all Wazuh components, sets up certificates, and applies firewall rules - all within minutes.

    Security Hardened TLS encryption between all components, UFW firewall pre-configured, secure API authentication, and latest security patches applied.

    Compliance Ready Pre-built rules and dashboards for PCI DSS, HIPAA, GDPR, NIST 800-53, and CIS benchmarks. Generate audit-ready compliance reports out of the box.

    Use Cases Security information and event management (SIEM) Intrusion detection and threat hunting File integrity monitoring across servers Vulnerability detection and assessment Regulatory compliance monitoring and reporting Cloud security posture management for AWS environments

    Getting Started Launch the AMI from AWS Marketplace on your preferred instance type SSH into your instance and follow the interactive setup wizard Install Wazuh agents on your endpoints and start monitoring

    Book a free setup consultation at https://cal.com/gaurav-pareek-perimattic/marketplace-setup-consultations  or email us at aws-support@perimattic.com .

    Support Managed and supported by Perimattic, a cloud infrastructure company with 13+ years of experience serving global clients. We offer free setup assistance, custom integrations, infrastructure consulting, and 24/7 support.

    Highlights

    • Enterprise SIEM Without Licensing Costs: Complete Wazuh stack with Manager, Indexer, and Dashboard pre-configured for intrusion detection, vulnerability scanning, and compliance reporting.
    • Compliance Ready Out of the Box: Pre-built rules and dashboards for PCI DSS, HIPAA, GDPR, NIST 800-53, and CIS benchmarks with audit-ready report generation.
    • 24/7 Expert Support by Perimattic: 13+ years of cloud infrastructure expertise with free setup assistance, SIEM configuration, and dedicated support at aws-support@perimattic.com.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Perimattic Managed Wazuh - SIEM and Security Monitoring on AWS

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (8)

     Info
    Dimension
    Cost/hour
    t2.medium
    Recommended
    $0.05
    t2.large
    $0.05
    t2.xlarge
    $0.05
    t3.medium
    $0.05
    t3.large
    $0.05
    t3.xlarge
    $0.05
    m5.large
    $0.05
    m5.xlarge
    $0.05

    AI Insights

     Info

    Dimensions summary

    You pay by the hour based on the EC2 instance size you run. The eight options split into three families. The t2 line (medium, large, xlarge) and t3 line (medium, large, xlarge) are burstable general-purpose instances. The m5 line (large, xlarge) offers steady general-purpose compute. Within each family, moving from medium to large to xlarge adds more CPU and memory, so the hourly rate rises with instance capacity. You choose one instance to match your workload, and billing accrues only while it runs.

    Top-of-mind questions for buyers

    Billing accrues per instance-hour only while the instance runs. A fully stopped instance stops the software hourly charge. You may still owe underlying AWS storage fees for the attached volumes, but the managed software meter counts running time only.
    The rate covers a managed Wazuh security monitoring deployment on the chosen instance. This includes provisioning, monitoring, backups, updates, and security patches handled by the vendor. You do not staff DevOps to run the software; the vendor operates the deployment on your cloud.
    You select a single instance size to match your workload. Moving to a larger size within a family adds CPU and memory and raises the hourly rate. To change capacity, you switch the instance you run rather than combining several sizes on one bill.
    perimattic.com
    Helpful?

    Vendor refund policy

    For any questions or concerns, please contact: Perimattic.com Email: aws-support@perimattic.com 

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes
    1. Added automated first-boot provisioning using failsafe.sh to ensure successful Wazuh SIEM installation.
    2. Implemented secure Wazuh setup with auto-generated strong admin credentials stored in .env and admin_password.txt
    3. Added mandatory domain validation and HTTPS configuration for secure remote dashboard access.
    4. Fully automated SSL certificate issuing and renewal using Certbot + Apache integration with WebSocket support.
    5. Enabled Wazuh Dashboard on port 15573 with secure Apache reverse proxy and security headers.
    6. Provided Docker Compose-based deployment for consistent Wazuh stack (Manager, Indexer, Dashboard) runtime.
    7. Configured persistent data volumes for security events, logs, configurations, and agent communications.
    8. Added auto-restart policy for all Wazuh containers to improve reliability and system uptime.
    9. Improved DNS validation logic to avoid SSL failures during domain mapping and certificate provisioning.
    10. Integrated self-healing setup that retries scripts on failure to guarantee successful provisioning and deployment.

    Additional details

    Usage instructions

    1. Launch an Instance

    From AWS Marketplace, click Continue to Subscribe, then Continue to Configuration, and launch the AMI.

    1. Choose the Recommended Instance Type

    Select t2.medium or higher for optimal Wazuh SIEM performance. Larger instance types improve indexing, dashboard responsiveness, and agent capacity.

    1. Configure Security Group

    Allow inbound traffic on the following ports:

    • 22 (SSH) - For secure terminal access
    • 80 (HTTP) - Required temporarily for SSL validation
    • 443 (HTTPS) - Secure access to Wazuh Dashboard

    For monitoring external endpoints (agents):

    • 1514-1515 (TCP) - Agent communication

    Optional (can add later):

    • 514 (UDP) - Syslog collection
    • 55000 (TCP) - API access
    1. Connect to the Instance

    Use SSH to connect: ssh -i <your-key.pem> ubuntu@<public-ip>

    1. First-Boot Setup (Guided)

    On first login, an interactive guided setup will automatically start:

    • Detects public IP
    • Prompts for domain name
    • Validates DNS A-record if domain provided
    • Asks for admin email for SSL certificate
    • Generates secure admin password (stored in /opt/app/admin_password.txt and /opt/app/.env)
    • Configures Apache reverse proxy with SSL
    • Deploys Wazuh stack using Docker Compose
    • Displays access URL & credentials (~5-7 minutes)
    1. DNS Configuration

    Before setup, add this DNS A-record if using custom domain:

    yourdomain.com <your-instance-public-IP>

    1. Automatic SSL Setup

    After DNS validation:

    • Enables HTTPS access via Let's Encrypt certificate
    • Redirects HTTP to HTTPS automatically
    • Configures security headers
    1. Start / Restart Wazuh Manually (if needed)

    cd /opt/app docker compose ps docker compose restart

    Persistent volumes preserve security events, logs, and configurations across restarts.

    1. Access the Wazuh Dashboard

    Open your browser and visit: https://<your-domain> (or) https://<public-ip>

    Credentials are printed after setup and saved in:

    /opt/app/admin_password.txt /opt/app/.env

    Default user:

    Username: admin Password: <auto-generated-password>

    1. Retrieve Credentials Anytime

    cat /opt/app/admin_password.txt cat /opt/app/.env

    Files contain: password, domain, email, and version information.

    1. Deploy Wazuh Agents

    From Dashboard: Agents > Deploy new agent Select OS (Windows/Linux/macOS) and follow installation commands. Agents connect to ports 1514/1515.

    1. Troubleshooting

    View logs: docker compose logs wazuh.dashboard

    Check status: docker compose ps

    Reset installation: sudo rm /var/log/wazuh-first-login-done bash /opt/app/failsafe.sh

    Thank you for subscribing. Your instance is ready to go!

    Need Support or Customization? Whether you're facing setup issues or need custom features, Perimattic's expert team is here to help:

    Email us: aws-support@perimattic.com  WhatsApp: +91-92142 66896 Learn more: <www.perimattic.com >

    We offer: Free setup assistance Custom development & integrations Infrastructure consulting Automation & AI solutions With 13+ years of experience serving global clients, we ensure your deployment runs smoothly and scales with your needs.

    Let's build something great together!

    Support

    Vendor support

    Support by Perimattic

    Perimattic provides 24/7 support for all AWS Marketplace products. Our team has 13+ years of cloud infrastructure expertise serving global clients.

    Contact Channels: Email: aws-support@perimattic.com  WhatsApp: +91-92142 66896 Website: <www.perimattic.com >

    What We Help With: Initial setup and configuration assistance (free) Troubleshooting connectivity, performance, and backup issues Custom development and integrations Infrastructure consulting and architecture review Migration planning from other solutions Automation solutions and scaling guidance

    Instance Sizing Guidance: t2.medium or t3.medium: Development environments, small applications m5.large: Production workloads with moderate traffic m5.xlarge: High-traffic production deployments and larger datasets

    For workload-specific sizing recommendations, contact our team for a free consultation.

    Refunds and Issues: If you experience any issues or need to request a refund, contact us at aws-support@perimattic.com  and we will respond promptly.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.