Lab: stand up your analyst workstation

Practical

~60 min

This week's first lab confirms your working environment. If you took the Beginners course, you are reactivating and extending your existing lab and Wazuh stack. If you arrived with equivalent experience, you build it now. Either way, you finish ready to work as an analyst.

1. Confirm or build the lab (20 minutes)

You need three machines on an isolated network:

  • Wazuh manager — the single-node stack (4 GB RAM).
  • Ubuntu agent — a Linux target.
  • Windows agent — a Windows target.

If you have them from the Beginners course: start all three, confirm the manager's dashboard loads, and confirm both agents show Active. Do not assume — verify. A stack that worked in Week 12 of another course may need its agents restarted or its clock corrected.

If you are building fresh: follow the Beginners course's Week 8 deployment — deploy the Wazuh single-node stack, then enrol a Linux and a Windows agent. Your instructor has the condensed build steps. Budget real time; this is the friction the Beginners course warned about, and it is unavoidable.

2. Verify the whole pipeline (15 minutes)

Confirm data flows end to end, because everything this course does depends on it.

On the Ubuntu agent, generate an event:

sudo tail -f /var/log/auth.log &
ssh wronguser@localhost   # wrong password, then Ctrl+C

In the dashboard, Security Events, filter to the Ubuntu agent. Your failed login should appear within a minute, decoded into fields. If it does not, the pipeline is broken and nothing else this week works — debug it now (agent status, manager status, network, clocks) rather than proceeding.

Do the same on Windows: fail a logon, confirm the 4625 arrives.

3. Check the clocks (10 minutes)

Time correctness is not optional for an analyst — correlation and timelines depend on it, and skewed clocks silently corrupt every investigation.

On each machine:

# Ubuntu
timedatectl
# Windows (PowerShell)
Get-Date; w32tm /query /status

All three machines should agree on the time (allowing for timezone). If they drift, fix it now:

sudo timedatectl set-ntp true   # Ubuntu

A SOC with wrong clocks produces timelines that cannot be trusted — you will build many timelines in this course, and every one assumes the clocks are right.

4. Learn the dashboard as an analyst (20 minutes)

You have seen the dashboard. Now use it the way you will all term. Practise the moves you will make hundreds of times:

  1. Filter Security Events by agent, by rule level, by time range. Find the highest-level events across both machines in the last 24 hours.
  2. Open an alert fully. Read every decoded field — rule id, level, source, the raw log. Get fast at reading these; it is your primary instrument.
  3. Search. Find every event involving a specific user or source address. This is the core investigative move — pivoting on an indicator.
  4. Sort by level. See the ratio of low-level noise to high-level signal. That ratio is the health metric from the lecture, in front of you.

5. Build your working notes (10 minutes)

Set up how you will document all term. Create a git repository — your analyst notebook and detection portfolio — with a structure like:

/investigations   — one file per investigation, with timelines
/detections       — custom rules you write, documented
/notes            — reference: event IDs, useful queries, lessons

This repository is your portfolio. By Week 12 it holds a body of real detection and investigation work, and it is worth more in a job interview than any certificate — it is evidence you can actually do the work. Start it properly now.

Extension, if you finish early

  • Explore the dashboard's saved searches and how to build a filtered view you could return to each shift.
  • Find where alerts can be assigned or annotated, if your Wazuh version supports it — the beginnings of case management.
  • Note your current total event volume and the true-signal ratio. It is your first data point for the metrics from this week's lecture.

Done?

Show your instructor:

  1. All three machines up, both agents Active.
  2. A generated event from each agent appearing in the dashboard, decoded.
  3. Clocks agreeing across all three.
  4. Your analyst-notebook git repository, initialised.

Sign in to submit your work.