Changes for page Wazuh SIEM

Last modified by Jarvis on 2026/02/05 08:32

From version 1.1 >
edited by Jarvis
on 2026/02/03 22:36
To version < 3.1
edited by Jarvis
on 2026/02/05 08:32
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -1,284 +1,17 @@
1 -{{box title="Uebersicht" image="icon:shield"}}Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}}
1 += Wazuh SIEM =
2 2  
3 -= 1. Systemuebersicht =
3 +Security Information and Event Management System.
4 4  
5 -|=Eigenschaft|=Wert
6 -|Software|Wazuh SIEM
7 -|Version|<VERSION> (z.B. 4.14.2)
8 -|Server|<HOSTNAME> (<IP-ADRESSE>)
9 -|Dashboard|https://<WAZUH-FQDN>
10 -|API|https://<WAZUH-FQDN>:55000
11 -|OS|Ubuntu 22.04 LTS
5 +== Zugangsdaten ==
6 +* **URL:** https://wazuh.rs-servertech.com
7 +* **Server IP:** 192.168.10.47
8 +* **API Port:** 55000
9 +* **Version:** 4.7.5
12 12  
13 -----
11 +== Funktionen ==
12 +* Log-Analyse
13 +* Intrusion Detection
14 +* File Integrity Monitoring
15 +* Vulnerability Detection
16 +* Security Analytics
14 14  
15 -= 2. Komponenten =
16 -
17 -|=Komponente|=Port|=Beschreibung
18 -|Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation
19 -|Wazuh Authd|1515|Agent-Registrierung
20 -|Wazuh API|55000|REST API
21 -|Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards)
22 -|Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch)
23 -
24 -----
25 -
26 -= 3. Installation =
27 -
28 -== 3.1 Voraussetzungen ==
29 -
30 -* Ubuntu 22.04 LTS oder Debian 11/12
31 -* Mind. 4 GB RAM (8 GB empfohlen)
32 -* Mind. 50 GB Speicher
33 -* Root-Zugang
34 -
35 -== 3.2 All-in-One Installation ==
36 -
37 -{{code language="bash"}}
38 -# Wazuh Installation Script
39 -curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
40 -curl -sO https://packages.wazuh.com/4.14/config.yml
41 -
42 -# config.yml anpassen (Hostnamen setzen)
43 -# Dann ausfuehren:
44 -bash wazuh-install.sh -a
45 -{{/code}}
46 -
47 -Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!**
48 -
49 -----
50 -
51 -= 4. Konfiguration =
52 -
53 -== 4.1 Manager (ossec.conf) ==
54 -
55 -Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}}
56 -
57 -Wichtige Sektionen:
58 -
59 -{{code language="xml"}}
60 -<!-- Vulnerability Detection -->
61 -<vulnerability-detector>
62 - <enabled>yes</enabled>
63 - <interval>5m</interval>
64 - <run_on_start>yes</run_on_start>
65 - <provider name="canonical">
66 - <enabled>yes</enabled>
67 - <os>jammy</os>
68 - <update_interval>1h</update_interval>
69 - </provider>
70 - <provider name="debian">
71 - <enabled>yes</enabled>
72 - <os>buster</os>
73 - <os>bullseye</os>
74 - <os>bookworm</os>
75 - <update_interval>1h</update_interval>
76 - </provider>
77 - <provider name="nvd">
78 - <enabled>yes</enabled>
79 - <update_interval>1h</update_interval>
80 - </provider>
81 -</vulnerability-detector>
82 -
83 -<!-- Active Response (z.B. Brute-Force Block) -->
84 -<active-response>
85 - <command>firewall-drop</command>
86 - <location>local</location>
87 - <rules_id>5763</rules_id>
88 - <timeout>1800</timeout>
89 -</active-response>
90 -{{/code}}
91 -
92 -== 4.2 Dashboard (opensearch_dashboards.yml) ==
93 -
94 -Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}}
95 -
96 -{{code language="yaml"}}
97 -server.host: 0.0.0.0
98 -server.port: 443
99 -opensearch.hosts: https://localhost:9200
100 -server.ssl.enabled: true
101 -server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
102 -server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
103 -opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
104 -uiSettings.overrides.defaultRoute: /app/wz-home
105 -{{/code}}
106 -
107 -{{warning}}
108 -Bei einem Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von {{code}}/app/wazuh{{/code}} zu {{code}}/app/wz-home{{/code}}. Ausserdem koennen sich die Cert-Dateinamen aendern! Die neue Config liegt als {{code}}.dpkg-dist{{/code}} — Pfade vergleichen und anpassen.
109 -{{/warning}}
110 -
111 -----
112 -
113 -= 5. Agent-Verwaltung =
114 -
115 -== 5.1 Agent installieren ==
116 -
117 -{{code language="bash"}}
118 -# Auf dem Ziel-System:
119 -curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
120 -
121 -echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list
122 -
123 -apt-get update
124 -WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
125 -
126 -systemctl daemon-reload
127 -systemctl enable wazuh-agent
128 -systemctl start wazuh-agent
129 -{{/code}}
130 -
131 -== 5.2 Agent-Gruppen ==
132 -
133 -Gruppen ermoelichen unterschiedliche Konfigurationen pro Server-Typ:
134 -
135 -|=Gruppe|=Beschreibung|=Agents
136 -|default|Standard-Gruppe|Allgemeine Hosts
137 -|Server|Produktiv-Server|Anwendungs-Server
138 -|Linux|Alle Linux-Hosts|Alle Linux-Agents
139 -
140 -{{code language="bash"}}
141 -# Gruppen auflisten
142 -/var/ossec/bin/agent_groups -l
143 -
144 -# Agent einer Gruppe zuweisen
145 -/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPENNAME>
146 -
147 -# Agent-Info anzeigen
148 -/var/ossec/bin/agent_control -i <AGENT-ID>
149 -{{/code}}
150 -
151 -== 5.3 Shared Agent Config (Remote-Befehle) ==
152 -
153 -Ueber Gruppen-Configs koennen Befehle auf Agents ausgefuehrt werden:
154 -
155 -Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}}
156 -
157 -{{code language="xml"}}
158 -<agent_config>
159 - <!-- System Update per Wodle Command -->
160 - <wodle name="command">
161 - <disabled>no</disabled>
162 - <tag>system-update</tag>
163 - <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
164 - <interval>1w</interval>
165 - <ignore_output>no</ignore_output>
166 - <run_on_start>yes</run_on_start>
167 - <timeout>600</timeout>
168 - </wodle>
169 -</agent_config>
170 -{{/code}}
171 -
172 -{{info}}
173 -Nach Aenderungen an der Agent-Config: Agents per API neustarten damit die Config sofort uebernommen wird.
174 -{{/info}}
175 -
176 -----
177 -
178 -= 6. API =
179 -
180 -== 6.1 Authentifizierung ==
181 -
182 -{{code language="bash"}}
183 -# Token holen
184 -TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
185 -
186 -# Agents auflisten
187 -curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true"
188 -{{/code}}
189 -
190 -== 6.2 Nuetzliche API-Aufrufe ==
191 -
192 -|=Aktion|=Methode|=Endpunkt
193 -|Alle Agents|GET|/agents
194 -|Agent-Info|GET|/agents/<ID>
195 -|Agent neustarten|PUT|/agents/<ID>/restart
196 -|Vulnerabilities|GET|/vulnerability/<ID>
197 -|Active Response|PUT|/active-response
198 -
199 -----
200 -
201 -= 7. Alerts und Severity-Levels =
202 -
203 -|=Level|=Bedeutung|=Aktion
204 -|0-3|Info/Debug|Keine
205 -|4-6|Niedrig|Beobachten
206 -|7-9|Mittel|Pruefen
207 -|10-12|Hoch|Zeitnah handeln
208 -|13-15|Kritisch|**Sofort handeln**
209 -
210 -Alert-Logdateien:
211 -
212 -* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} — Alle Alerts
213 -* {{code}}/var/ossec/logs/archives/archives.json{{/code}} — Alle Events (wenn aktiviert)
214 -* {{code}}/var/ossec/logs/ossec.log{{/code}} — Manager-Log
215 -
216 -----
217 -
218 -= 8. Service-Management =
219 -
220 -{{code language="bash"}}
221 -# Status pruefen
222 -systemctl status wazuh-manager
223 -systemctl status wazuh-indexer
224 -systemctl status wazuh-dashboard
225 -
226 -# Neustarten
227 -systemctl restart wazuh-manager
228 -
229 -# Version pruefen
230 -/var/ossec/bin/wazuh-control info
231 -
232 -# Agent-Liste
233 -/var/ossec/bin/agent_control -l
234 -{{/code}}
235 -
236 -----
237 -
238 -= 9. Upgrade =
239 -
240 -{{warning}}
241 -**Vor jedem Upgrade:** Backup der Config-Dateien erstellen!
242 -{{/warning}}
243 -
244 -{{code language="bash"}}
245 -# Backup
246 -cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
247 -cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
248 -
249 -# Upgrade
250 -apt-get update
251 -DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
252 -{{/code}}
253 -
254 -=== Bekannte Probleme nach Upgrade ===
255 -
256 -* **Dashboard zeigt "Application Not Found":** defaultRoute hat sich geaendert (siehe Abschnitt 4.2)
257 -* **SSL-Zertifikat-Pfade:** Neue Config erwartet andere Dateinamen — mit Backup vergleichen
258 -* **Agent Version-Mismatch:** Agents laufen weiter, sollten aber zeitnah auch aktualisiert werden
259 -
260 -----
261 -
262 -= 10. Troubleshooting =
263 -
264 -{{code language="bash"}}
265 -# Dashboard nicht erreichbar?
266 -systemctl status wazuh-dashboard
267 -journalctl -u wazuh-dashboard -n 50 --no-pager
268 -
269 -# Agent verbindet nicht?
270 -/var/ossec/bin/agent_control -i <AGENT-ID>
271 -# Auf dem Agent:
272 -cat /var/ossec/logs/ossec.log | tail -30
273 -
274 -# API-Fehler?
275 -curl -sk -u <USER>:<PASS> https://localhost:55000/
276 -
277 -# Cert-Probleme?
278 -ls -la /etc/wazuh-dashboard/certs/
279 -# Pfade in opensearch_dashboards.yml pruefen!
280 -{{/code}}
281 -
282 -----
283 -
284 -//Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//

Applications

Need help?

If you need help with XWiki you can contact: