Changes for page Wazuh SIEM

Last modified by Jarvis on 2026/02/05 08:32

From version 1.1 >
edited by Jarvis
on 2026/02/03 22:36
To version < 2.1 >
edited by Jarvis
on 2026/02/03 22:37
>
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -4,7 +4,7 @@
4 4  
5 5  |=Eigenschaft|=Wert
6 6  |Software|Wazuh SIEM
7 -|Version|<VERSION> (z.B. 4.14.2)
7 +|Version|<VERSION>
8 8  |Server|<HOSTNAME> (<IP-ADRESSE>)
9 9  |Dashboard|https://<WAZUH-FQDN>
10 10  |API|https://<WAZUH-FQDN>:55000
... ... @@ -35,12 +35,10 @@
35 35  == 3.2 All-in-One Installation ==
36 36  
37 37  {{code language="bash"}}
38 -# Wazuh Installation Script
39 39  curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
40 40  curl -sO https://packages.wazuh.com/4.14/config.yml
41 41  
42 42  # config.yml anpassen (Hostnamen setzen)
43 -# Dann ausfuehren:
44 44  bash wazuh-install.sh -a
45 45  {{/code}}
46 46  
... ... @@ -54,8 +54,6 @@
54 54  
55 55  Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}}
56 56  
57 -Wichtige Sektionen:
58 -
59 59  {{code language="xml"}}
60 60  <!-- Vulnerability Detection -->
61 61  <vulnerability-detector>
... ... @@ -74,13 +74,9 @@
74 74   <os>bookworm</os>
75 75   <update_interval>1h</update_interval>
76 76   </provider>
77 - <provider name="nvd">
78 - <enabled>yes</enabled>
79 - <update_interval>1h</update_interval>
80 - </provider>
81 81  </vulnerability-detector>
82 82  
83 -<!-- Active Response (z.B. Brute-Force Block) -->
75 +<!-- Active Response -->
84 84  <active-response>
85 85   <command>firewall-drop</command>
86 86   <location>local</location>
... ... @@ -89,7 +89,7 @@
89 89  </active-response>
90 90  {{/code}}
91 91  
92 -== 4.2 Dashboard (opensearch_dashboards.yml) ==
84 +== 4.2 Dashboard ==
93 93  
94 94  Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}}
95 95  
... ... @@ -105,7 +105,7 @@
105 105  {{/code}}
106 106  
107 107  {{warning}}
108 -Bei einem Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von {{code}}/app/wazuh{{/code}} zu {{code}}/app/wz-home{{/code}}. Ausserdem koennen sich die Cert-Dateinamen aendern! Die neue Config liegt als {{code}}.dpkg-dist{{/code}} — Pfade vergleichen und anpassen.
100 +Bei Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von /app/wazuh zu /app/wz-home. Cert-Dateinamen koennen sich ebenfalls aendern!
109 109  {{/warning}}
110 110  
111 111  ----
... ... @@ -115,10 +115,11 @@
115 115  == 5.1 Agent installieren ==
116 116  
117 117  {{code language="bash"}}
118 -# Auf dem Ziel-System:
119 -curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
110 +curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring \
111 + --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
120 120  
121 -echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list
113 +echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \
114 + | tee /etc/apt/sources.list.d/wazuh.list
122 122  
123 123  apt-get update
124 124  WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
... ... @@ -130,39 +130,33 @@
130 130  
131 131  == 5.2 Agent-Gruppen ==
132 132  
133 -Gruppen ermoelichen unterschiedliche Konfigurationen pro Server-Typ:
126 +|=Gruppe|=Beschreibung
127 +|default|Standard-Gruppe
128 +|Server|Produktiv-Server
129 +|Linux|Alle Linux-Hosts
134 134  
135 -|=Gruppe|=Beschreibung|=Agents
136 -|default|Standard-Gruppe|Allgemeine Hosts
137 -|Server|Produktiv-Server|Anwendungs-Server
138 -|Linux|Alle Linux-Hosts|Alle Linux-Agents
139 -
140 140  {{code language="bash"}}
141 141  # Gruppen auflisten
142 142  /var/ossec/bin/agent_groups -l
143 143  
144 -# Agent einer Gruppe zuweisen
145 -/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPENNAME>
135 +# Agent zuweisen
136 +/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE>
146 146  
147 -# Agent-Info anzeigen
138 +# Agent-Info
148 148  /var/ossec/bin/agent_control -i <AGENT-ID>
149 149  {{/code}}
150 150  
151 -== 5.3 Shared Agent Config (Remote-Befehle) ==
142 +== 5.3 Shared Agent Config ==
152 152  
153 -Ueber Gruppen-Configs koennen Befehle auf Agents ausgefuehrt werden:
154 -
155 155  Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}}
156 156  
157 157  {{code language="xml"}}
158 158  <agent_config>
159 - <!-- System Update per Wodle Command -->
160 160   <wodle name="command">
161 161   <disabled>no</disabled>
162 162   <tag>system-update</tag>
163 163   <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
164 164   <interval>1w</interval>
165 - <ignore_output>no</ignore_output>
166 166   <run_on_start>yes</run_on_start>
167 167   <timeout>600</timeout>
168 168   </wodle>
... ... @@ -170,7 +170,7 @@
170 170  {{/code}}
171 171  
172 172  {{info}}
173 -Nach Aenderungen an der Agent-Config: Agents per API neustarten damit die Config sofort uebernommen wird.
160 +Nach Config-Aenderungen: Agents per API neustarten fuer sofortige Uebernahme.
174 174  {{/info}}
175 175  
176 176  ----
... ... @@ -177,28 +177,30 @@
177 177  
178 178  = 6. API =
179 179  
180 -== 6.1 Authentifizierung ==
181 -
182 182  {{code language="bash"}}
183 183  # Token holen
184 -TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
169 +TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \
170 + "https://<WAZUH-FQDN>:55000/security/user/authenticate" \
171 + | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
185 185  
186 186  # Agents auflisten
187 -curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true"
174 +curl -sk -H "Authorization: Bearer $TOKEN" \
175 + "https://<WAZUH-FQDN>:55000/agents?pretty=true"
176 +
177 +# Agent neustarten
178 +curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \
179 + "https://<WAZUH-FQDN>:55000/agents/<ID>/restart"
188 188  {{/code}}
189 189  
190 -== 6.2 Nuetzliche API-Aufrufe ==
191 -
192 192  |=Aktion|=Methode|=Endpunkt
193 193  |Alle Agents|GET|/agents
194 194  |Agent-Info|GET|/agents/<ID>
195 -|Agent neustarten|PUT|/agents/<ID>/restart
185 +|Agent restart|PUT|/agents/<ID>/restart
196 196  |Vulnerabilities|GET|/vulnerability/<ID>
197 -|Active Response|PUT|/active-response
198 198  
199 199  ----
200 200  
201 -= 7. Alerts und Severity-Levels =
190 += 7. Alert-Levels =
202 202  
203 203  |=Level|=Bedeutung|=Aktion
204 204  |0-3|Info/Debug|Keine
... ... @@ -207,26 +207,23 @@
207 207  |10-12|Hoch|Zeitnah handeln
208 208  |13-15|Kritisch|**Sofort handeln**
209 209  
210 -Alert-Logdateien:
199 +Log-Pfade:
200 +* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}}
201 +* {{code}}/var/ossec/logs/archives/archives.json{{/code}}
202 +* {{code}}/var/ossec/logs/ossec.log{{/code}}
211 211  
212 -* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} — Alle Alerts
213 -* {{code}}/var/ossec/logs/archives/archives.json{{/code}} — Alle Events (wenn aktiviert)
214 -* {{code}}/var/ossec/logs/ossec.log{{/code}} — Manager-Log
215 -
216 216  ----
217 217  
218 218  = 8. Service-Management =
219 219  
220 220  {{code language="bash"}}
221 -# Status pruefen
222 -systemctl status wazuh-manager
223 -systemctl status wazuh-indexer
224 -systemctl status wazuh-dashboard
209 +# Status
210 +systemctl status wazuh-manager wazuh-indexer wazuh-dashboard
225 225  
226 226  # Neustarten
227 227  systemctl restart wazuh-manager
228 228  
229 -# Version pruefen
215 +# Version
230 230  /var/ossec/bin/wazuh-control info
231 231  
232 232  # Agent-Liste
... ... @@ -238,7 +238,7 @@
238 238  = 9. Upgrade =
239 239  
240 240  {{warning}}
241 -**Vor jedem Upgrade:** Backup der Config-Dateien erstellen!
227 +**Vor jedem Upgrade:** Backup der Config-Dateien!
242 242  {{/warning}}
243 243  
244 244  {{code language="bash"}}
... ... @@ -251,11 +251,11 @@
251 251  DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
252 252  {{/code}}
253 253  
254 -=== Bekannte Probleme nach Upgrade ===
240 +=== Bekannte Upgrade-Probleme ===
255 255  
256 -* **Dashboard zeigt "Application Not Found":** defaultRoute hat sich geaendert (siehe Abschnitt 4.2)
257 -* **SSL-Zertifikat-Pfade:** Neue Config erwartet andere Dateinamen — mit Backup vergleichen
258 -* **Agent Version-Mismatch:** Agents laufen weiter, sollten aber zeitnah auch aktualisiert werden
242 +* **"Application Not Found"** im Dashboard: defaultRoute anpassen (Abschnitt 4.2)
243 +* **SSL-Cert-Pfade falsch:** .dpkg-dist mit Backup vergleichen
244 +* **Agent Version-Mismatch:** Agents zeitnah nachziehen
259 259  
260 260  ----
261 261  
... ... @@ -263,20 +263,16 @@
263 263  
264 264  {{code language="bash"}}
265 265  # Dashboard nicht erreichbar?
266 -systemctl status wazuh-dashboard
267 267  journalctl -u wazuh-dashboard -n 50 --no-pager
268 268  
269 269  # Agent verbindet nicht?
270 270  /var/ossec/bin/agent_control -i <AGENT-ID>
256 +
271 271  # Auf dem Agent:
272 -cat /var/ossec/logs/ossec.log | tail -30
258 +tail -30 /var/ossec/logs/ossec.log
273 273  
274 -# API-Fehler?
275 -curl -sk -u <USER>:<PASS> https://localhost:55000/
276 -
277 277  # Cert-Probleme?
278 278  ls -la /etc/wazuh-dashboard/certs/
279 -# Pfade in opensearch_dashboards.yml pruefen!
280 280  {{/code}}
281 281  
282 282  ----

Applications

Need help?

If you need help with XWiki you can contact: