Wazuh & Suricata & Gatekeeper Ubuntu Deployment

Job ID: 39965953

Budget: $10 – $11 USD

I’m building a security stack on Ubuntu machines and need someone to set up the full pipeline for me. Nothing is installed yet, so the work starts from a clean slate.

First, install the Wazuh server with its web dashboard on an Ubuntu host, making sure the Elastic components come up healthy and ready for custom indexes. Then deploy Wazuh agents on the remaining Ubuntu endpoints.

Next, install Suricata IDS/IPS on those same agents, configure the correct rule sets, and ensure its alerts are forwarded into Wazuh so I can view and search them inside the Wazuh dashboard in near-real time. Please expose at least one sample dashboard or index pattern showing that Suricata events are mapping correctly.

Finally, clone and build Gatekeeper from https://github.com/AltraMayor/gatekeeper, integrate it with Suricata, and demonstrate that the blocking logic is operational (for example, by triggering a test rule and confirming the host blocks the traffic).

Deliverables
• Wazuh server and dashboard fully running on Ubuntu
• Wazuh agents installed on each Ubuntu endpoint
• Suricata installed, tuned, and sending alerts into Wazuh
• Gatekeeper compiled, configured, and verified in action
• Short runbook or commands to reproduce key steps

I’ll validate the setup by logging into the dashboard, seeing live Suricata alerts, and running a Gatekeeper block test. Let me know if you need SSH access details or preferred ports before we begin.