Changes for page Wazuh SIEM
Last modified by Jarvis on 2026/02/05 08:32
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -4,7 +4,7 @@ 4 4 5 5 |=Eigenschaft|=Wert 6 6 |Software|Wazuh SIEM 7 -|Version|<VERSION> (z.B. 4.14.2)7 +|Version|<VERSION> 8 8 |Server|<HOSTNAME> (<IP-ADRESSE>) 9 9 |Dashboard|https://<WAZUH-FQDN> 10 10 |API|https://<WAZUH-FQDN>:55000 ... ... @@ -35,12 +35,10 @@ 35 35 == 3.2 All-in-One Installation == 36 36 37 37 {{code language="bash"}} 38 -# Wazuh Installation Script 39 39 curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh 40 40 curl -sO https://packages.wazuh.com/4.14/config.yml 41 41 42 42 # config.yml anpassen (Hostnamen setzen) 43 -# Dann ausfuehren: 44 44 bash wazuh-install.sh -a 45 45 {{/code}} 46 46 ... ... @@ -54,8 +54,6 @@ 54 54 55 55 Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}} 56 56 57 -Wichtige Sektionen: 58 - 59 59 {{code language="xml"}} 60 60 <!-- Vulnerability Detection --> 61 61 <vulnerability-detector> ... ... @@ -74,13 +74,9 @@ 74 74 <os>bookworm</os> 75 75 <update_interval>1h</update_interval> 76 76 </provider> 77 - <provider name="nvd"> 78 - <enabled>yes</enabled> 79 - <update_interval>1h</update_interval> 80 - </provider> 81 81 </vulnerability-detector> 82 82 83 -<!-- Active Response (z.B. Brute-Force Block)-->75 +<!-- Active Response --> 84 84 <active-response> 85 85 <command>firewall-drop</command> 86 86 <location>local</location> ... ... @@ -89,7 +89,7 @@ 89 89 </active-response> 90 90 {{/code}} 91 91 92 -== 4.2 Dashboard (opensearch_dashboards.yml)==84 +== 4.2 Dashboard == 93 93 94 94 Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}} 95 95 ... ... @@ -105,7 +105,7 @@ 105 105 {{/code}} 106 106 107 107 {{warning}} 108 -Bei einemUpgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von{{code}}/app/wazuh{{/code}}zu{{code}}/app/wz-home{{/code}}.Ausserdem koennen sich dieCert-Dateinamenaendern!DieneueConfig liegtals{{code}}.dpkg-dist{{/code}} — Pfadevergleichenundanpassen.100 +Bei Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von /app/wazuh zu /app/wz-home. Cert-Dateinamen koennen sich ebenfalls aendern! 109 109 {{/warning}} 110 110 111 111 ---- ... ... @@ -115,10 +115,11 @@ 115 115 == 5.1 Agent installieren == 116 116 117 117 {{code language="bash"}} 118 - # AufdemZiel-System:119 - curl-shttps://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring--keyringgnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg110 +curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring \ 111 + --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg 120 120 121 -echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list 113 +echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \ 114 + | tee /etc/apt/sources.list.d/wazuh.list 122 122 123 123 apt-get update 124 124 WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent ... ... @@ -130,39 +130,33 @@ 130 130 131 131 == 5.2 Agent-Gruppen == 132 132 133 -Gruppen ermoelichen unterschiedliche Konfigurationen pro Server-Typ: 126 +|=Gruppe|=Beschreibung 127 +|default|Standard-Gruppe 128 +|Server|Produktiv-Server 129 +|Linux|Alle Linux-Hosts 134 134 135 -|=Gruppe|=Beschreibung|=Agents 136 -|default|Standard-Gruppe|Allgemeine Hosts 137 -|Server|Produktiv-Server|Anwendungs-Server 138 -|Linux|Alle Linux-Hosts|Alle Linux-Agents 139 - 140 140 {{code language="bash"}} 141 141 # Gruppen auflisten 142 142 /var/ossec/bin/agent_groups -l 143 143 144 -# Agent einer Gruppezuweisen145 -/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE NNAME>135 +# Agent zuweisen 136 +/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE> 146 146 147 -# Agent-Info anzeigen138 +# Agent-Info 148 148 /var/ossec/bin/agent_control -i <AGENT-ID> 149 149 {{/code}} 150 150 151 -== 5.3 Shared Agent Config (Remote-Befehle)==142 +== 5.3 Shared Agent Config == 152 152 153 -Ueber Gruppen-Configs koennen Befehle auf Agents ausgefuehrt werden: 154 - 155 155 Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}} 156 156 157 157 {{code language="xml"}} 158 158 <agent_config> 159 - <!-- System Update per Wodle Command --> 160 160 <wodle name="command"> 161 161 <disabled>no</disabled> 162 162 <tag>system-update</tag> 163 163 <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command> 164 164 <interval>1w</interval> 165 - <ignore_output>no</ignore_output> 166 166 <run_on_start>yes</run_on_start> 167 167 <timeout>600</timeout> 168 168 </wodle> ... ... @@ -170,7 +170,7 @@ 170 170 {{/code}} 171 171 172 172 {{info}} 173 -Nach Aenderungen an der Agent-Config: Agents per API neustartendamit dieConfigsofortuebernommen wird.160 +Nach Config-Aenderungen: Agents per API neustarten fuer sofortige Uebernahme. 174 174 {{/info}} 175 175 176 176 ---- ... ... @@ -177,28 +177,30 @@ 177 177 178 178 = 6. API = 179 179 180 -== 6.1 Authentifizierung == 181 - 182 182 {{code language="bash"}} 183 183 # Token holen 184 -TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])") 169 +TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \ 170 + "https://<WAZUH-FQDN>:55000/security/user/authenticate" \ 171 + | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])") 185 185 186 186 # Agents auflisten 187 -curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true" 174 +curl -sk -H "Authorization: Bearer $TOKEN" \ 175 + "https://<WAZUH-FQDN>:55000/agents?pretty=true" 176 + 177 +# Agent neustarten 178 +curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \ 179 + "https://<WAZUH-FQDN>:55000/agents/<ID>/restart" 188 188 {{/code}} 189 189 190 -== 6.2 Nuetzliche API-Aufrufe == 191 - 192 192 |=Aktion|=Methode|=Endpunkt 193 193 |Alle Agents|GET|/agents 194 194 |Agent-Info|GET|/agents/<ID> 195 -|Agent neustarten|PUT|/agents/<ID>/restart185 +|Agent restart|PUT|/agents/<ID>/restart 196 196 |Vulnerabilities|GET|/vulnerability/<ID> 197 -|Active Response|PUT|/active-response 198 198 199 199 ---- 200 200 201 -= 7. Alert s und Severity-Levels =190 += 7. Alert-Levels = 202 202 203 203 |=Level|=Bedeutung|=Aktion 204 204 |0-3|Info/Debug|Keine ... ... @@ -207,26 +207,23 @@ 207 207 |10-12|Hoch|Zeitnah handeln 208 208 |13-15|Kritisch|**Sofort handeln** 209 209 210 -Alert-Logdateien: 199 +Log-Pfade: 200 +* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} 201 +* {{code}}/var/ossec/logs/archives/archives.json{{/code}} 202 +* {{code}}/var/ossec/logs/ossec.log{{/code}} 211 211 212 -* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} — Alle Alerts 213 -* {{code}}/var/ossec/logs/archives/archives.json{{/code}} — Alle Events (wenn aktiviert) 214 -* {{code}}/var/ossec/logs/ossec.log{{/code}} — Manager-Log 215 - 216 216 ---- 217 217 218 218 = 8. Service-Management = 219 219 220 220 {{code language="bash"}} 221 -# Status pruefen 222 -systemctl status wazuh-manager 223 -systemctl status wazuh-indexer 224 -systemctl status wazuh-dashboard 209 +# Status 210 +systemctl status wazuh-manager wazuh-indexer wazuh-dashboard 225 225 226 226 # Neustarten 227 227 systemctl restart wazuh-manager 228 228 229 -# Version pruefen215 +# Version 230 230 /var/ossec/bin/wazuh-control info 231 231 232 232 # Agent-Liste ... ... @@ -238,7 +238,7 @@ 238 238 = 9. Upgrade = 239 239 240 240 {{warning}} 241 -**Vor jedem Upgrade:** Backup der Config-Dateien erstellen!227 +**Vor jedem Upgrade:** Backup der Config-Dateien! 242 242 {{/warning}} 243 243 244 244 {{code language="bash"}} ... ... @@ -251,11 +251,11 @@ 251 251 DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold" 252 252 {{/code}} 253 253 254 -=== Bekannte Probleme nach Upgrade===240 +=== Bekannte Upgrade-Probleme === 255 255 256 -* ** Dashboard zeigt"Application Not Found":** defaultRoutehatsich geaendert(sieheAbschnitt 4.2)257 -* **SSL- Zertifikat-Pfade:**Neue Configerwartet andere Dateinamen—mit Backup vergleichen258 -* **Agent Version-Mismatch:** Agents laufen weiter, sollten aberzeitnah auchaktualisiert werden242 +* **"Application Not Found"** im Dashboard: defaultRoute anpassen (Abschnitt 4.2) 243 +* **SSL-Cert-Pfade falsch:** .dpkg-dist mit Backup vergleichen 244 +* **Agent Version-Mismatch:** Agents zeitnah nachziehen 259 259 260 260 ---- 261 261 ... ... @@ -263,20 +263,16 @@ 263 263 264 264 {{code language="bash"}} 265 265 # Dashboard nicht erreichbar? 266 -systemctl status wazuh-dashboard 267 267 journalctl -u wazuh-dashboard -n 50 --no-pager 268 268 269 269 # Agent verbindet nicht? 270 270 /var/ossec/bin/agent_control -i <AGENT-ID> 256 + 271 271 # Auf dem Agent: 272 - cat /var/ossec/logs/ossec.log| tail -30258 +tail -30 /var/ossec/logs/ossec.log 273 273 274 -# API-Fehler? 275 -curl -sk -u <USER>:<PASS> https://localhost:55000/ 276 - 277 277 # Cert-Probleme? 278 278 ls -la /etc/wazuh-dashboard/certs/ 279 -# Pfade in opensearch_dashboards.yml pruefen! 280 280 {{/code}} 281 281 282 282 ----