Changes for page Wazuh SIEM

Last modified by Jarvis on 2026/02/05 08:32

From version < 3.1
edited by Jarvis
on 2026/02/05 08:32
To version 1.1 >
edited by Jarvis
on 2026/02/03 22:36
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -1,17 +1,284 @@
1 -= Wazuh SIEM =
1 +{{box title="Uebersicht" image="icon:shield"}}Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}}
2 2  
3 -Security Information and Event Management System.
3 += 1. Systemuebersicht =
4 4  
5 -== Zugangsdaten ==
6 -* **URL:** https://wazuh.rs-servertech.com
7 -* **Server IP:** 192.168.10.47
8 -* **API Port:** 55000
9 -* **Version:** 4.7.5
5 +|=Eigenschaft|=Wert
6 +|Software|Wazuh SIEM
7 +|Version|<VERSION> (z.B. 4.14.2)
8 +|Server|<HOSTNAME> (<IP-ADRESSE>)
9 +|Dashboard|https://<WAZUH-FQDN>
10 +|API|https://<WAZUH-FQDN>:55000
11 +|OS|Ubuntu 22.04 LTS
10 10  
11 -== Funktionen ==
12 -* Log-Analyse
13 -* Intrusion Detection
14 -* File Integrity Monitoring
15 -* Vulnerability Detection
16 -* Security Analytics
13 +----
17 17  
15 += 2. Komponenten =
16 +
17 +|=Komponente|=Port|=Beschreibung
18 +|Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation
19 +|Wazuh Authd|1515|Agent-Registrierung
20 +|Wazuh API|55000|REST API
21 +|Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards)
22 +|Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch)
23 +
24 +----
25 +
26 += 3. Installation =
27 +
28 +== 3.1 Voraussetzungen ==
29 +
30 +* Ubuntu 22.04 LTS oder Debian 11/12
31 +* Mind. 4 GB RAM (8 GB empfohlen)
32 +* Mind. 50 GB Speicher
33 +* Root-Zugang
34 +
35 +== 3.2 All-in-One Installation ==
36 +
37 +{{code language="bash"}}
38 +# Wazuh Installation Script
39 +curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
40 +curl -sO https://packages.wazuh.com/4.14/config.yml
41 +
42 +# config.yml anpassen (Hostnamen setzen)
43 +# Dann ausfuehren:
44 +bash wazuh-install.sh -a
45 +{{/code}}
46 +
47 +Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!**
48 +
49 +----
50 +
51 += 4. Konfiguration =
52 +
53 +== 4.1 Manager (ossec.conf) ==
54 +
55 +Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}}
56 +
57 +Wichtige Sektionen:
58 +
59 +{{code language="xml"}}
60 +<!-- Vulnerability Detection -->
61 +<vulnerability-detector>
62 + <enabled>yes</enabled>
63 + <interval>5m</interval>
64 + <run_on_start>yes</run_on_start>
65 + <provider name="canonical">
66 + <enabled>yes</enabled>
67 + <os>jammy</os>
68 + <update_interval>1h</update_interval>
69 + </provider>
70 + <provider name="debian">
71 + <enabled>yes</enabled>
72 + <os>buster</os>
73 + <os>bullseye</os>
74 + <os>bookworm</os>
75 + <update_interval>1h</update_interval>
76 + </provider>
77 + <provider name="nvd">
78 + <enabled>yes</enabled>
79 + <update_interval>1h</update_interval>
80 + </provider>
81 +</vulnerability-detector>
82 +
83 +<!-- Active Response (z.B. Brute-Force Block) -->
84 +<active-response>
85 + <command>firewall-drop</command>
86 + <location>local</location>
87 + <rules_id>5763</rules_id>
88 + <timeout>1800</timeout>
89 +</active-response>
90 +{{/code}}
91 +
92 +== 4.2 Dashboard (opensearch_dashboards.yml) ==
93 +
94 +Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}}
95 +
96 +{{code language="yaml"}}
97 +server.host: 0.0.0.0
98 +server.port: 443
99 +opensearch.hosts: https://localhost:9200
100 +server.ssl.enabled: true
101 +server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
102 +server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
103 +opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
104 +uiSettings.overrides.defaultRoute: /app/wz-home
105 +{{/code}}
106 +
107 +{{warning}}
108 +Bei einem Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von {{code}}/app/wazuh{{/code}} zu {{code}}/app/wz-home{{/code}}. Ausserdem koennen sich die Cert-Dateinamen aendern! Die neue Config liegt als {{code}}.dpkg-dist{{/code}} — Pfade vergleichen und anpassen.
109 +{{/warning}}
110 +
111 +----
112 +
113 += 5. Agent-Verwaltung =
114 +
115 +== 5.1 Agent installieren ==
116 +
117 +{{code language="bash"}}
118 +# Auf dem Ziel-System:
119 +curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
120 +
121 +echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list
122 +
123 +apt-get update
124 +WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
125 +
126 +systemctl daemon-reload
127 +systemctl enable wazuh-agent
128 +systemctl start wazuh-agent
129 +{{/code}}
130 +
131 +== 5.2 Agent-Gruppen ==
132 +
133 +Gruppen ermoelichen unterschiedliche Konfigurationen pro Server-Typ:
134 +
135 +|=Gruppe|=Beschreibung|=Agents
136 +|default|Standard-Gruppe|Allgemeine Hosts
137 +|Server|Produktiv-Server|Anwendungs-Server
138 +|Linux|Alle Linux-Hosts|Alle Linux-Agents
139 +
140 +{{code language="bash"}}
141 +# Gruppen auflisten
142 +/var/ossec/bin/agent_groups -l
143 +
144 +# Agent einer Gruppe zuweisen
145 +/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPENNAME>
146 +
147 +# Agent-Info anzeigen
148 +/var/ossec/bin/agent_control -i <AGENT-ID>
149 +{{/code}}
150 +
151 +== 5.3 Shared Agent Config (Remote-Befehle) ==
152 +
153 +Ueber Gruppen-Configs koennen Befehle auf Agents ausgefuehrt werden:
154 +
155 +Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}}
156 +
157 +{{code language="xml"}}
158 +<agent_config>
159 + <!-- System Update per Wodle Command -->
160 + <wodle name="command">
161 + <disabled>no</disabled>
162 + <tag>system-update</tag>
163 + <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
164 + <interval>1w</interval>
165 + <ignore_output>no</ignore_output>
166 + <run_on_start>yes</run_on_start>
167 + <timeout>600</timeout>
168 + </wodle>
169 +</agent_config>
170 +{{/code}}
171 +
172 +{{info}}
173 +Nach Aenderungen an der Agent-Config: Agents per API neustarten damit die Config sofort uebernommen wird.
174 +{{/info}}
175 +
176 +----
177 +
178 += 6. API =
179 +
180 +== 6.1 Authentifizierung ==
181 +
182 +{{code language="bash"}}
183 +# Token holen
184 +TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
185 +
186 +# Agents auflisten
187 +curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true"
188 +{{/code}}
189 +
190 +== 6.2 Nuetzliche API-Aufrufe ==
191 +
192 +|=Aktion|=Methode|=Endpunkt
193 +|Alle Agents|GET|/agents
194 +|Agent-Info|GET|/agents/<ID>
195 +|Agent neustarten|PUT|/agents/<ID>/restart
196 +|Vulnerabilities|GET|/vulnerability/<ID>
197 +|Active Response|PUT|/active-response
198 +
199 +----
200 +
201 += 7. Alerts und Severity-Levels =
202 +
203 +|=Level|=Bedeutung|=Aktion
204 +|0-3|Info/Debug|Keine
205 +|4-6|Niedrig|Beobachten
206 +|7-9|Mittel|Pruefen
207 +|10-12|Hoch|Zeitnah handeln
208 +|13-15|Kritisch|**Sofort handeln**
209 +
210 +Alert-Logdateien:
211 +
212 +* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} — Alle Alerts
213 +* {{code}}/var/ossec/logs/archives/archives.json{{/code}} — Alle Events (wenn aktiviert)
214 +* {{code}}/var/ossec/logs/ossec.log{{/code}} — Manager-Log
215 +
216 +----
217 +
218 += 8. Service-Management =
219 +
220 +{{code language="bash"}}
221 +# Status pruefen
222 +systemctl status wazuh-manager
223 +systemctl status wazuh-indexer
224 +systemctl status wazuh-dashboard
225 +
226 +# Neustarten
227 +systemctl restart wazuh-manager
228 +
229 +# Version pruefen
230 +/var/ossec/bin/wazuh-control info
231 +
232 +# Agent-Liste
233 +/var/ossec/bin/agent_control -l
234 +{{/code}}
235 +
236 +----
237 +
238 += 9. Upgrade =
239 +
240 +{{warning}}
241 +**Vor jedem Upgrade:** Backup der Config-Dateien erstellen!
242 +{{/warning}}
243 +
244 +{{code language="bash"}}
245 +# Backup
246 +cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
247 +cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
248 +
249 +# Upgrade
250 +apt-get update
251 +DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
252 +{{/code}}
253 +
254 +=== Bekannte Probleme nach Upgrade ===
255 +
256 +* **Dashboard zeigt "Application Not Found":** defaultRoute hat sich geaendert (siehe Abschnitt 4.2)
257 +* **SSL-Zertifikat-Pfade:** Neue Config erwartet andere Dateinamen — mit Backup vergleichen
258 +* **Agent Version-Mismatch:** Agents laufen weiter, sollten aber zeitnah auch aktualisiert werden
259 +
260 +----
261 +
262 += 10. Troubleshooting =
263 +
264 +{{code language="bash"}}
265 +# Dashboard nicht erreichbar?
266 +systemctl status wazuh-dashboard
267 +journalctl -u wazuh-dashboard -n 50 --no-pager
268 +
269 +# Agent verbindet nicht?
270 +/var/ossec/bin/agent_control -i <AGENT-ID>
271 +# Auf dem Agent:
272 +cat /var/ossec/logs/ossec.log | tail -30
273 +
274 +# API-Fehler?
275 +curl -sk -u <USER>:<PASS> https://localhost:55000/
276 +
277 +# Cert-Probleme?
278 +ls -la /etc/wazuh-dashboard/certs/
279 +# Pfade in opensearch_dashboards.yml pruefen!
280 +{{/code}}
281 +
282 +----
283 +
284 +//Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//

Applications

Need help?

If you need help with XWiki you can contact: