Changes for page Wazuh SIEM
Last modified by Jarvis on 2026/02/05 08:32
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -1,17 +1,284 @@ 1 -= Wazuh SIEM =1 +{{box title="Uebersicht" image="icon:shield"}}Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}} 2 2 3 - SecurityInformationand Event ManagementSystem.3 += 1. Systemuebersicht = 4 4 5 -== Zugangsdaten == 6 -* **URL:** https://wazuh.rs-servertech.com 7 -* **Server IP:** 192.168.10.47 8 -* **API Port:** 55000 9 -* **Version:** 4.7.5 5 +|=Eigenschaft|=Wert 6 +|Software|Wazuh SIEM 7 +|Version|<VERSION> (z.B. 4.14.2) 8 +|Server|<HOSTNAME> (<IP-ADRESSE>) 9 +|Dashboard|https://<WAZUH-FQDN> 10 +|API|https://<WAZUH-FQDN>:55000 11 +|OS|Ubuntu 22.04 LTS 10 10 11 -== Funktionen == 12 -* Log-Analyse 13 -* Intrusion Detection 14 -* File Integrity Monitoring 15 -* Vulnerability Detection 16 -* Security Analytics 13 +---- 17 17 15 += 2. Komponenten = 16 + 17 +|=Komponente|=Port|=Beschreibung 18 +|Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation 19 +|Wazuh Authd|1515|Agent-Registrierung 20 +|Wazuh API|55000|REST API 21 +|Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards) 22 +|Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch) 23 + 24 +---- 25 + 26 += 3. Installation = 27 + 28 +== 3.1 Voraussetzungen == 29 + 30 +* Ubuntu 22.04 LTS oder Debian 11/12 31 +* Mind. 4 GB RAM (8 GB empfohlen) 32 +* Mind. 50 GB Speicher 33 +* Root-Zugang 34 + 35 +== 3.2 All-in-One Installation == 36 + 37 +{{code language="bash"}} 38 +# Wazuh Installation Script 39 +curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh 40 +curl -sO https://packages.wazuh.com/4.14/config.yml 41 + 42 +# config.yml anpassen (Hostnamen setzen) 43 +# Dann ausfuehren: 44 +bash wazuh-install.sh -a 45 +{{/code}} 46 + 47 +Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!** 48 + 49 +---- 50 + 51 += 4. Konfiguration = 52 + 53 +== 4.1 Manager (ossec.conf) == 54 + 55 +Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}} 56 + 57 +Wichtige Sektionen: 58 + 59 +{{code language="xml"}} 60 +<!-- Vulnerability Detection --> 61 +<vulnerability-detector> 62 + <enabled>yes</enabled> 63 + <interval>5m</interval> 64 + <run_on_start>yes</run_on_start> 65 + <provider name="canonical"> 66 + <enabled>yes</enabled> 67 + <os>jammy</os> 68 + <update_interval>1h</update_interval> 69 + </provider> 70 + <provider name="debian"> 71 + <enabled>yes</enabled> 72 + <os>buster</os> 73 + <os>bullseye</os> 74 + <os>bookworm</os> 75 + <update_interval>1h</update_interval> 76 + </provider> 77 + <provider name="nvd"> 78 + <enabled>yes</enabled> 79 + <update_interval>1h</update_interval> 80 + </provider> 81 +</vulnerability-detector> 82 + 83 +<!-- Active Response (z.B. Brute-Force Block) --> 84 +<active-response> 85 + <command>firewall-drop</command> 86 + <location>local</location> 87 + <rules_id>5763</rules_id> 88 + <timeout>1800</timeout> 89 +</active-response> 90 +{{/code}} 91 + 92 +== 4.2 Dashboard (opensearch_dashboards.yml) == 93 + 94 +Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}} 95 + 96 +{{code language="yaml"}} 97 +server.host: 0.0.0.0 98 +server.port: 443 99 +opensearch.hosts: https://localhost:9200 100 +server.ssl.enabled: true 101 +server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem" 102 +server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem" 103 +opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"] 104 +uiSettings.overrides.defaultRoute: /app/wz-home 105 +{{/code}} 106 + 107 +{{warning}} 108 +Bei einem Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von {{code}}/app/wazuh{{/code}} zu {{code}}/app/wz-home{{/code}}. Ausserdem koennen sich die Cert-Dateinamen aendern! Die neue Config liegt als {{code}}.dpkg-dist{{/code}} — Pfade vergleichen und anpassen. 109 +{{/warning}} 110 + 111 +---- 112 + 113 += 5. Agent-Verwaltung = 114 + 115 +== 5.1 Agent installieren == 116 + 117 +{{code language="bash"}} 118 +# Auf dem Ziel-System: 119 +curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg 120 + 121 +echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list 122 + 123 +apt-get update 124 +WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent 125 + 126 +systemctl daemon-reload 127 +systemctl enable wazuh-agent 128 +systemctl start wazuh-agent 129 +{{/code}} 130 + 131 +== 5.2 Agent-Gruppen == 132 + 133 +Gruppen ermoelichen unterschiedliche Konfigurationen pro Server-Typ: 134 + 135 +|=Gruppe|=Beschreibung|=Agents 136 +|default|Standard-Gruppe|Allgemeine Hosts 137 +|Server|Produktiv-Server|Anwendungs-Server 138 +|Linux|Alle Linux-Hosts|Alle Linux-Agents 139 + 140 +{{code language="bash"}} 141 +# Gruppen auflisten 142 +/var/ossec/bin/agent_groups -l 143 + 144 +# Agent einer Gruppe zuweisen 145 +/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPENNAME> 146 + 147 +# Agent-Info anzeigen 148 +/var/ossec/bin/agent_control -i <AGENT-ID> 149 +{{/code}} 150 + 151 +== 5.3 Shared Agent Config (Remote-Befehle) == 152 + 153 +Ueber Gruppen-Configs koennen Befehle auf Agents ausgefuehrt werden: 154 + 155 +Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}} 156 + 157 +{{code language="xml"}} 158 +<agent_config> 159 + <!-- System Update per Wodle Command --> 160 + <wodle name="command"> 161 + <disabled>no</disabled> 162 + <tag>system-update</tag> 163 + <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command> 164 + <interval>1w</interval> 165 + <ignore_output>no</ignore_output> 166 + <run_on_start>yes</run_on_start> 167 + <timeout>600</timeout> 168 + </wodle> 169 +</agent_config> 170 +{{/code}} 171 + 172 +{{info}} 173 +Nach Aenderungen an der Agent-Config: Agents per API neustarten damit die Config sofort uebernommen wird. 174 +{{/info}} 175 + 176 +---- 177 + 178 += 6. API = 179 + 180 +== 6.1 Authentifizierung == 181 + 182 +{{code language="bash"}} 183 +# Token holen 184 +TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])") 185 + 186 +# Agents auflisten 187 +curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true" 188 +{{/code}} 189 + 190 +== 6.2 Nuetzliche API-Aufrufe == 191 + 192 +|=Aktion|=Methode|=Endpunkt 193 +|Alle Agents|GET|/agents 194 +|Agent-Info|GET|/agents/<ID> 195 +|Agent neustarten|PUT|/agents/<ID>/restart 196 +|Vulnerabilities|GET|/vulnerability/<ID> 197 +|Active Response|PUT|/active-response 198 + 199 +---- 200 + 201 += 7. Alerts und Severity-Levels = 202 + 203 +|=Level|=Bedeutung|=Aktion 204 +|0-3|Info/Debug|Keine 205 +|4-6|Niedrig|Beobachten 206 +|7-9|Mittel|Pruefen 207 +|10-12|Hoch|Zeitnah handeln 208 +|13-15|Kritisch|**Sofort handeln** 209 + 210 +Alert-Logdateien: 211 + 212 +* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} — Alle Alerts 213 +* {{code}}/var/ossec/logs/archives/archives.json{{/code}} — Alle Events (wenn aktiviert) 214 +* {{code}}/var/ossec/logs/ossec.log{{/code}} — Manager-Log 215 + 216 +---- 217 + 218 += 8. Service-Management = 219 + 220 +{{code language="bash"}} 221 +# Status pruefen 222 +systemctl status wazuh-manager 223 +systemctl status wazuh-indexer 224 +systemctl status wazuh-dashboard 225 + 226 +# Neustarten 227 +systemctl restart wazuh-manager 228 + 229 +# Version pruefen 230 +/var/ossec/bin/wazuh-control info 231 + 232 +# Agent-Liste 233 +/var/ossec/bin/agent_control -l 234 +{{/code}} 235 + 236 +---- 237 + 238 += 9. Upgrade = 239 + 240 +{{warning}} 241 +**Vor jedem Upgrade:** Backup der Config-Dateien erstellen! 242 +{{/warning}} 243 + 244 +{{code language="bash"}} 245 +# Backup 246 +cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak 247 +cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak 248 + 249 +# Upgrade 250 +apt-get update 251 +DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold" 252 +{{/code}} 253 + 254 +=== Bekannte Probleme nach Upgrade === 255 + 256 +* **Dashboard zeigt "Application Not Found":** defaultRoute hat sich geaendert (siehe Abschnitt 4.2) 257 +* **SSL-Zertifikat-Pfade:** Neue Config erwartet andere Dateinamen — mit Backup vergleichen 258 +* **Agent Version-Mismatch:** Agents laufen weiter, sollten aber zeitnah auch aktualisiert werden 259 + 260 +---- 261 + 262 += 10. Troubleshooting = 263 + 264 +{{code language="bash"}} 265 +# Dashboard nicht erreichbar? 266 +systemctl status wazuh-dashboard 267 +journalctl -u wazuh-dashboard -n 50 --no-pager 268 + 269 +# Agent verbindet nicht? 270 +/var/ossec/bin/agent_control -i <AGENT-ID> 271 +# Auf dem Agent: 272 +cat /var/ossec/logs/ossec.log | tail -30 273 + 274 +# API-Fehler? 275 +curl -sk -u <USER>:<PASS> https://localhost:55000/ 276 + 277 +# Cert-Probleme? 278 +ls -la /etc/wazuh-dashboard/certs/ 279 +# Pfade in opensearch_dashboards.yml pruefen! 280 +{{/code}} 281 + 282 +---- 283 + 284 +//Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//