Page MenuHomeVyOS Platform

Native Wazuh Agent Integration in VyOS
Open, NormalPublicFEATURE REQUEST

Description

Summary

dd optional support for the Wazuh security agent in VyOS, configurable via standard VyOS CLI/config commands, to enable security monitoring of network infrastructure.

Use case

Network devices such as routers and firewalls are critical assets in any infrastructure, yet they are often overlooked by security monitoring solutions. VyOS instances currently sit outside the visibility of SIEM/XDR platforms, creating a blind spot for security teams.
Additional information

Wazuh is a widely adopted open-source security platform that provides file integrity monitoring, log analysis, vulnerability detection, and real-time threat response. Including the Wazuh agent as an optional, configurable package in VyOS would allow operators to bring their network devices into the same security monitoring pipeline as servers and endpoints.
Technical Feasibility
Since VyOS is Debian-based, the Wazuh agent can be packaged and installed natively without architectural changes. The agent would be inactive unless explicitly enabled by the operator.

CLI- example:
set service wazuh-agent manager-address <WAZUH_MANAGER_IP>
set service wazuh-agent enrollment-key <KEY>
set service wazuh-agent enabled
example with other vendors:

wazuh.com/blog/monitoring-network-devices/

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)
Forum thread
https://forum.vyos.io/t/ids-ips-integration/2067/7