Änderungen von Dokument Wazuh SIEM
Zuletzt geändert von Jarvis am 2026/02/05 08:32
Änderungskommentar:
Es gibt keinen Kommentar für diese Version
Zusammenfassung
-
Seiteneigenschaften (1 geändert, 0 hinzugefügt, 0 gelöscht)
Details
- Seiteneigenschaften
-
- Inhalt
-
... ... @@ -1,266 +1,17 @@ 1 - {{box title="Uebersicht"image="icon:shield"}}Wazuhist eine Open-Source SIEM/XDR-Plattformfuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}}1 += Wazuh SIEM = 2 2 3 - = 1.Systemuebersicht=3 +Security Information and Event Management System. 4 4 5 -|=Eigenschaft|=Wert 6 -|Software|Wazuh SIEM 7 -|Version|<VERSION> 8 -|Server|<HOSTNAME> (<IP-ADRESSE>) 9 -|Dashboard|https://<WAZUH-FQDN> 10 -|API|https://<WAZUH-FQDN>:55000 11 -|OS|Ubuntu 22.04 LTS 5 +== Zugangsdaten == 6 +* **URL:** https://wazuh.rs-servertech.com 7 +* **Server IP:** 192.168.10.47 8 +* **API Port:** 55000 9 +* **Version:** 4.7.5 12 12 13 ----- 11 +== Funktionen == 12 +* Log-Analyse 13 +* Intrusion Detection 14 +* File Integrity Monitoring 15 +* Vulnerability Detection 16 +* Security Analytics 14 14 15 -= 2. Komponenten = 16 - 17 -|=Komponente|=Port|=Beschreibung 18 -|Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation 19 -|Wazuh Authd|1515|Agent-Registrierung 20 -|Wazuh API|55000|REST API 21 -|Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards) 22 -|Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch) 23 - 24 ----- 25 - 26 -= 3. Installation = 27 - 28 -== 3.1 Voraussetzungen == 29 - 30 -* Ubuntu 22.04 LTS oder Debian 11/12 31 -* Mind. 4 GB RAM (8 GB empfohlen) 32 -* Mind. 50 GB Speicher 33 -* Root-Zugang 34 - 35 -== 3.2 All-in-One Installation == 36 - 37 -{{code language="bash"}} 38 -curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh 39 -curl -sO https://packages.wazuh.com/4.14/config.yml 40 - 41 -# config.yml anpassen (Hostnamen setzen) 42 -bash wazuh-install.sh -a 43 -{{/code}} 44 - 45 -Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!** 46 - 47 ----- 48 - 49 -= 4. Konfiguration = 50 - 51 -== 4.1 Manager (ossec.conf) == 52 - 53 -Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}} 54 - 55 -{{code language="xml"}} 56 -<!-- Vulnerability Detection --> 57 -<vulnerability-detector> 58 - <enabled>yes</enabled> 59 - <interval>5m</interval> 60 - <run_on_start>yes</run_on_start> 61 - <provider name="canonical"> 62 - <enabled>yes</enabled> 63 - <os>jammy</os> 64 - <update_interval>1h</update_interval> 65 - </provider> 66 - <provider name="debian"> 67 - <enabled>yes</enabled> 68 - <os>buster</os> 69 - <os>bullseye</os> 70 - <os>bookworm</os> 71 - <update_interval>1h</update_interval> 72 - </provider> 73 -</vulnerability-detector> 74 - 75 -<!-- Active Response --> 76 -<active-response> 77 - <command>firewall-drop</command> 78 - <location>local</location> 79 - <rules_id>5763</rules_id> 80 - <timeout>1800</timeout> 81 -</active-response> 82 -{{/code}} 83 - 84 -== 4.2 Dashboard == 85 - 86 -Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}} 87 - 88 -{{code language="yaml"}} 89 -server.host: 0.0.0.0 90 -server.port: 443 91 -opensearch.hosts: https://localhost:9200 92 -server.ssl.enabled: true 93 -server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem" 94 -server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem" 95 -opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"] 96 -uiSettings.overrides.defaultRoute: /app/wz-home 97 -{{/code}} 98 - 99 -{{warning}} 100 -Bei Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von /app/wazuh zu /app/wz-home. Cert-Dateinamen koennen sich ebenfalls aendern! 101 -{{/warning}} 102 - 103 ----- 104 - 105 -= 5. Agent-Verwaltung = 106 - 107 -== 5.1 Agent installieren == 108 - 109 -{{code language="bash"}} 110 -curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring \ 111 - --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg 112 - 113 -echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \ 114 - | tee /etc/apt/sources.list.d/wazuh.list 115 - 116 -apt-get update 117 -WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent 118 - 119 -systemctl daemon-reload 120 -systemctl enable wazuh-agent 121 -systemctl start wazuh-agent 122 -{{/code}} 123 - 124 -== 5.2 Agent-Gruppen == 125 - 126 -|=Gruppe|=Beschreibung 127 -|default|Standard-Gruppe 128 -|Server|Produktiv-Server 129 -|Linux|Alle Linux-Hosts 130 - 131 -{{code language="bash"}} 132 -# Gruppen auflisten 133 -/var/ossec/bin/agent_groups -l 134 - 135 -# Agent zuweisen 136 -/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE> 137 - 138 -# Agent-Info 139 -/var/ossec/bin/agent_control -i <AGENT-ID> 140 -{{/code}} 141 - 142 -== 5.3 Shared Agent Config == 143 - 144 -Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}} 145 - 146 -{{code language="xml"}} 147 -<agent_config> 148 - <wodle name="command"> 149 - <disabled>no</disabled> 150 - <tag>system-update</tag> 151 - <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command> 152 - <interval>1w</interval> 153 - <run_on_start>yes</run_on_start> 154 - <timeout>600</timeout> 155 - </wodle> 156 -</agent_config> 157 -{{/code}} 158 - 159 -{{info}} 160 -Nach Config-Aenderungen: Agents per API neustarten fuer sofortige Uebernahme. 161 -{{/info}} 162 - 163 ----- 164 - 165 -= 6. API = 166 - 167 -{{code language="bash"}} 168 -# Token holen 169 -TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \ 170 - "https://<WAZUH-FQDN>:55000/security/user/authenticate" \ 171 - | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])") 172 - 173 -# Agents auflisten 174 -curl -sk -H "Authorization: Bearer $TOKEN" \ 175 - "https://<WAZUH-FQDN>:55000/agents?pretty=true" 176 - 177 -# Agent neustarten 178 -curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \ 179 - "https://<WAZUH-FQDN>:55000/agents/<ID>/restart" 180 -{{/code}} 181 - 182 -|=Aktion|=Methode|=Endpunkt 183 -|Alle Agents|GET|/agents 184 -|Agent-Info|GET|/agents/<ID> 185 -|Agent restart|PUT|/agents/<ID>/restart 186 -|Vulnerabilities|GET|/vulnerability/<ID> 187 - 188 ----- 189 - 190 -= 7. Alert-Levels = 191 - 192 -|=Level|=Bedeutung|=Aktion 193 -|0-3|Info/Debug|Keine 194 -|4-6|Niedrig|Beobachten 195 -|7-9|Mittel|Pruefen 196 -|10-12|Hoch|Zeitnah handeln 197 -|13-15|Kritisch|**Sofort handeln** 198 - 199 -Log-Pfade: 200 -* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} 201 -* {{code}}/var/ossec/logs/archives/archives.json{{/code}} 202 -* {{code}}/var/ossec/logs/ossec.log{{/code}} 203 - 204 ----- 205 - 206 -= 8. Service-Management = 207 - 208 -{{code language="bash"}} 209 -# Status 210 -systemctl status wazuh-manager wazuh-indexer wazuh-dashboard 211 - 212 -# Neustarten 213 -systemctl restart wazuh-manager 214 - 215 -# Version 216 -/var/ossec/bin/wazuh-control info 217 - 218 -# Agent-Liste 219 -/var/ossec/bin/agent_control -l 220 -{{/code}} 221 - 222 ----- 223 - 224 -= 9. Upgrade = 225 - 226 -{{warning}} 227 -**Vor jedem Upgrade:** Backup der Config-Dateien! 228 -{{/warning}} 229 - 230 -{{code language="bash"}} 231 -# Backup 232 -cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak 233 -cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak 234 - 235 -# Upgrade 236 -apt-get update 237 -DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold" 238 -{{/code}} 239 - 240 -=== Bekannte Upgrade-Probleme === 241 - 242 -* **"Application Not Found"** im Dashboard: defaultRoute anpassen (Abschnitt 4.2) 243 -* **SSL-Cert-Pfade falsch:** .dpkg-dist mit Backup vergleichen 244 -* **Agent Version-Mismatch:** Agents zeitnah nachziehen 245 - 246 ----- 247 - 248 -= 10. Troubleshooting = 249 - 250 -{{code language="bash"}} 251 -# Dashboard nicht erreichbar? 252 -journalctl -u wazuh-dashboard -n 50 --no-pager 253 - 254 -# Agent verbindet nicht? 255 -/var/ossec/bin/agent_control -i <AGENT-ID> 256 - 257 -# Auf dem Agent: 258 -tail -30 /var/ossec/logs/ossec.log 259 - 260 -# Cert-Probleme? 261 -ls -la /etc/wazuh-dashboard/certs/ 262 -{{/code}} 263 - 264 ----- 265 - 266 -//Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//