Changes for page Wazuh SIEM
Last modified by Jarvis on 2026/02/05 08:32
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -1,284 +1,17 @@ 1 - {{box title="Uebersicht"image="icon:shield"}}Wazuhist eine Open-Source SIEM/XDR-Plattformfuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}}1 += Wazuh SIEM = 2 2 3 - = 1.Systemuebersicht=3 +Security Information and Event Management System. 4 4 5 -|=Eigenschaft|=Wert 6 -|Software|Wazuh SIEM 7 -|Version|<VERSION> (z.B. 4.14.2) 8 -|Server|<HOSTNAME> (<IP-ADRESSE>) 9 -|Dashboard|https://<WAZUH-FQDN> 10 -|API|https://<WAZUH-FQDN>:55000 11 -|OS|Ubuntu 22.04 LTS 5 +== Zugangsdaten == 6 +* **URL:** https://wazuh.rs-servertech.com 7 +* **Server IP:** 192.168.10.47 8 +* **API Port:** 55000 9 +* **Version:** 4.7.5 12 12 13 ----- 11 +== Funktionen == 12 +* Log-Analyse 13 +* Intrusion Detection 14 +* File Integrity Monitoring 15 +* Vulnerability Detection 16 +* Security Analytics 14 14 15 -= 2. Komponenten = 16 - 17 -|=Komponente|=Port|=Beschreibung 18 -|Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation 19 -|Wazuh Authd|1515|Agent-Registrierung 20 -|Wazuh API|55000|REST API 21 -|Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards) 22 -|Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch) 23 - 24 ----- 25 - 26 -= 3. Installation = 27 - 28 -== 3.1 Voraussetzungen == 29 - 30 -* Ubuntu 22.04 LTS oder Debian 11/12 31 -* Mind. 4 GB RAM (8 GB empfohlen) 32 -* Mind. 50 GB Speicher 33 -* Root-Zugang 34 - 35 -== 3.2 All-in-One Installation == 36 - 37 -{{code language="bash"}} 38 -# Wazuh Installation Script 39 -curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh 40 -curl -sO https://packages.wazuh.com/4.14/config.yml 41 - 42 -# config.yml anpassen (Hostnamen setzen) 43 -# Dann ausfuehren: 44 -bash wazuh-install.sh -a 45 -{{/code}} 46 - 47 -Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!** 48 - 49 ----- 50 - 51 -= 4. Konfiguration = 52 - 53 -== 4.1 Manager (ossec.conf) == 54 - 55 -Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}} 56 - 57 -Wichtige Sektionen: 58 - 59 -{{code language="xml"}} 60 -<!-- Vulnerability Detection --> 61 -<vulnerability-detector> 62 - <enabled>yes</enabled> 63 - <interval>5m</interval> 64 - <run_on_start>yes</run_on_start> 65 - <provider name="canonical"> 66 - <enabled>yes</enabled> 67 - <os>jammy</os> 68 - <update_interval>1h</update_interval> 69 - </provider> 70 - <provider name="debian"> 71 - <enabled>yes</enabled> 72 - <os>buster</os> 73 - <os>bullseye</os> 74 - <os>bookworm</os> 75 - <update_interval>1h</update_interval> 76 - </provider> 77 - <provider name="nvd"> 78 - <enabled>yes</enabled> 79 - <update_interval>1h</update_interval> 80 - </provider> 81 -</vulnerability-detector> 82 - 83 -<!-- Active Response (z.B. Brute-Force Block) --> 84 -<active-response> 85 - <command>firewall-drop</command> 86 - <location>local</location> 87 - <rules_id>5763</rules_id> 88 - <timeout>1800</timeout> 89 -</active-response> 90 -{{/code}} 91 - 92 -== 4.2 Dashboard (opensearch_dashboards.yml) == 93 - 94 -Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}} 95 - 96 -{{code language="yaml"}} 97 -server.host: 0.0.0.0 98 -server.port: 443 99 -opensearch.hosts: https://localhost:9200 100 -server.ssl.enabled: true 101 -server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem" 102 -server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem" 103 -opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"] 104 -uiSettings.overrides.defaultRoute: /app/wz-home 105 -{{/code}} 106 - 107 -{{warning}} 108 -Bei einem Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von {{code}}/app/wazuh{{/code}} zu {{code}}/app/wz-home{{/code}}. Ausserdem koennen sich die Cert-Dateinamen aendern! Die neue Config liegt als {{code}}.dpkg-dist{{/code}} — Pfade vergleichen und anpassen. 109 -{{/warning}} 110 - 111 ----- 112 - 113 -= 5. Agent-Verwaltung = 114 - 115 -== 5.1 Agent installieren == 116 - 117 -{{code language="bash"}} 118 -# Auf dem Ziel-System: 119 -curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg 120 - 121 -echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list 122 - 123 -apt-get update 124 -WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent 125 - 126 -systemctl daemon-reload 127 -systemctl enable wazuh-agent 128 -systemctl start wazuh-agent 129 -{{/code}} 130 - 131 -== 5.2 Agent-Gruppen == 132 - 133 -Gruppen ermoelichen unterschiedliche Konfigurationen pro Server-Typ: 134 - 135 -|=Gruppe|=Beschreibung|=Agents 136 -|default|Standard-Gruppe|Allgemeine Hosts 137 -|Server|Produktiv-Server|Anwendungs-Server 138 -|Linux|Alle Linux-Hosts|Alle Linux-Agents 139 - 140 -{{code language="bash"}} 141 -# Gruppen auflisten 142 -/var/ossec/bin/agent_groups -l 143 - 144 -# Agent einer Gruppe zuweisen 145 -/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPENNAME> 146 - 147 -# Agent-Info anzeigen 148 -/var/ossec/bin/agent_control -i <AGENT-ID> 149 -{{/code}} 150 - 151 -== 5.3 Shared Agent Config (Remote-Befehle) == 152 - 153 -Ueber Gruppen-Configs koennen Befehle auf Agents ausgefuehrt werden: 154 - 155 -Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}} 156 - 157 -{{code language="xml"}} 158 -<agent_config> 159 - <!-- System Update per Wodle Command --> 160 - <wodle name="command"> 161 - <disabled>no</disabled> 162 - <tag>system-update</tag> 163 - <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command> 164 - <interval>1w</interval> 165 - <ignore_output>no</ignore_output> 166 - <run_on_start>yes</run_on_start> 167 - <timeout>600</timeout> 168 - </wodle> 169 -</agent_config> 170 -{{/code}} 171 - 172 -{{info}} 173 -Nach Aenderungen an der Agent-Config: Agents per API neustarten damit die Config sofort uebernommen wird. 174 -{{/info}} 175 - 176 ----- 177 - 178 -= 6. API = 179 - 180 -== 6.1 Authentifizierung == 181 - 182 -{{code language="bash"}} 183 -# Token holen 184 -TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])") 185 - 186 -# Agents auflisten 187 -curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true" 188 -{{/code}} 189 - 190 -== 6.2 Nuetzliche API-Aufrufe == 191 - 192 -|=Aktion|=Methode|=Endpunkt 193 -|Alle Agents|GET|/agents 194 -|Agent-Info|GET|/agents/<ID> 195 -|Agent neustarten|PUT|/agents/<ID>/restart 196 -|Vulnerabilities|GET|/vulnerability/<ID> 197 -|Active Response|PUT|/active-response 198 - 199 ----- 200 - 201 -= 7. Alerts und Severity-Levels = 202 - 203 -|=Level|=Bedeutung|=Aktion 204 -|0-3|Info/Debug|Keine 205 -|4-6|Niedrig|Beobachten 206 -|7-9|Mittel|Pruefen 207 -|10-12|Hoch|Zeitnah handeln 208 -|13-15|Kritisch|**Sofort handeln** 209 - 210 -Alert-Logdateien: 211 - 212 -* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} — Alle Alerts 213 -* {{code}}/var/ossec/logs/archives/archives.json{{/code}} — Alle Events (wenn aktiviert) 214 -* {{code}}/var/ossec/logs/ossec.log{{/code}} — Manager-Log 215 - 216 ----- 217 - 218 -= 8. Service-Management = 219 - 220 -{{code language="bash"}} 221 -# Status pruefen 222 -systemctl status wazuh-manager 223 -systemctl status wazuh-indexer 224 -systemctl status wazuh-dashboard 225 - 226 -# Neustarten 227 -systemctl restart wazuh-manager 228 - 229 -# Version pruefen 230 -/var/ossec/bin/wazuh-control info 231 - 232 -# Agent-Liste 233 -/var/ossec/bin/agent_control -l 234 -{{/code}} 235 - 236 ----- 237 - 238 -= 9. Upgrade = 239 - 240 -{{warning}} 241 -**Vor jedem Upgrade:** Backup der Config-Dateien erstellen! 242 -{{/warning}} 243 - 244 -{{code language="bash"}} 245 -# Backup 246 -cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak 247 -cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak 248 - 249 -# Upgrade 250 -apt-get update 251 -DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold" 252 -{{/code}} 253 - 254 -=== Bekannte Probleme nach Upgrade === 255 - 256 -* **Dashboard zeigt "Application Not Found":** defaultRoute hat sich geaendert (siehe Abschnitt 4.2) 257 -* **SSL-Zertifikat-Pfade:** Neue Config erwartet andere Dateinamen — mit Backup vergleichen 258 -* **Agent Version-Mismatch:** Agents laufen weiter, sollten aber zeitnah auch aktualisiert werden 259 - 260 ----- 261 - 262 -= 10. Troubleshooting = 263 - 264 -{{code language="bash"}} 265 -# Dashboard nicht erreichbar? 266 -systemctl status wazuh-dashboard 267 -journalctl -u wazuh-dashboard -n 50 --no-pager 268 - 269 -# Agent verbindet nicht? 270 -/var/ossec/bin/agent_control -i <AGENT-ID> 271 -# Auf dem Agent: 272 -cat /var/ossec/logs/ossec.log | tail -30 273 - 274 -# API-Fehler? 275 -curl -sk -u <USER>:<PASS> https://localhost:55000/ 276 - 277 -# Cert-Probleme? 278 -ls -la /etc/wazuh-dashboard/certs/ 279 -# Pfade in opensearch_dashboards.yml pruefen! 280 -{{/code}} 281 - 282 ----- 283 - 284 -//Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//