Changes for page Wazuh SIEM
Last modified by Jarvis on 2026/02/05 08:32
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -1,17 +1,266 @@ 1 -= Wazuh SIEM =1 +{{box title="Uebersicht" image="icon:shield"}}Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}} 2 2 3 - SecurityInformationand Event ManagementSystem.3 += 1. Systemuebersicht = 4 4 5 -== Zugangsdaten == 6 -* **URL:** https://wazuh.rs-servertech.com 7 -* **Server IP:** 192.168.10.47 8 -* **API Port:** 55000 9 -* **Version:** 4.7.5 5 +|=Eigenschaft|=Wert 6 +|Software|Wazuh SIEM 7 +|Version|<VERSION> 8 +|Server|<HOSTNAME> (<IP-ADRESSE>) 9 +|Dashboard|https://<WAZUH-FQDN> 10 +|API|https://<WAZUH-FQDN>:55000 11 +|OS|Ubuntu 22.04 LTS 10 10 11 -== Funktionen == 12 -* Log-Analyse 13 -* Intrusion Detection 14 -* File Integrity Monitoring 15 -* Vulnerability Detection 16 -* Security Analytics 13 +---- 17 17 15 += 2. Komponenten = 16 + 17 +|=Komponente|=Port|=Beschreibung 18 +|Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation 19 +|Wazuh Authd|1515|Agent-Registrierung 20 +|Wazuh API|55000|REST API 21 +|Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards) 22 +|Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch) 23 + 24 +---- 25 + 26 += 3. Installation = 27 + 28 +== 3.1 Voraussetzungen == 29 + 30 +* Ubuntu 22.04 LTS oder Debian 11/12 31 +* Mind. 4 GB RAM (8 GB empfohlen) 32 +* Mind. 50 GB Speicher 33 +* Root-Zugang 34 + 35 +== 3.2 All-in-One Installation == 36 + 37 +{{code language="bash"}} 38 +curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh 39 +curl -sO https://packages.wazuh.com/4.14/config.yml 40 + 41 +# config.yml anpassen (Hostnamen setzen) 42 +bash wazuh-install.sh -a 43 +{{/code}} 44 + 45 +Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!** 46 + 47 +---- 48 + 49 += 4. Konfiguration = 50 + 51 +== 4.1 Manager (ossec.conf) == 52 + 53 +Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}} 54 + 55 +{{code language="xml"}} 56 +<!-- Vulnerability Detection --> 57 +<vulnerability-detector> 58 + <enabled>yes</enabled> 59 + <interval>5m</interval> 60 + <run_on_start>yes</run_on_start> 61 + <provider name="canonical"> 62 + <enabled>yes</enabled> 63 + <os>jammy</os> 64 + <update_interval>1h</update_interval> 65 + </provider> 66 + <provider name="debian"> 67 + <enabled>yes</enabled> 68 + <os>buster</os> 69 + <os>bullseye</os> 70 + <os>bookworm</os> 71 + <update_interval>1h</update_interval> 72 + </provider> 73 +</vulnerability-detector> 74 + 75 +<!-- Active Response --> 76 +<active-response> 77 + <command>firewall-drop</command> 78 + <location>local</location> 79 + <rules_id>5763</rules_id> 80 + <timeout>1800</timeout> 81 +</active-response> 82 +{{/code}} 83 + 84 +== 4.2 Dashboard == 85 + 86 +Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}} 87 + 88 +{{code language="yaml"}} 89 +server.host: 0.0.0.0 90 +server.port: 443 91 +opensearch.hosts: https://localhost:9200 92 +server.ssl.enabled: true 93 +server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem" 94 +server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem" 95 +opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"] 96 +uiSettings.overrides.defaultRoute: /app/wz-home 97 +{{/code}} 98 + 99 +{{warning}} 100 +Bei Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von /app/wazuh zu /app/wz-home. Cert-Dateinamen koennen sich ebenfalls aendern! 101 +{{/warning}} 102 + 103 +---- 104 + 105 += 5. Agent-Verwaltung = 106 + 107 +== 5.1 Agent installieren == 108 + 109 +{{code language="bash"}} 110 +curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring \ 111 + --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg 112 + 113 +echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \ 114 + | tee /etc/apt/sources.list.d/wazuh.list 115 + 116 +apt-get update 117 +WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent 118 + 119 +systemctl daemon-reload 120 +systemctl enable wazuh-agent 121 +systemctl start wazuh-agent 122 +{{/code}} 123 + 124 +== 5.2 Agent-Gruppen == 125 + 126 +|=Gruppe|=Beschreibung 127 +|default|Standard-Gruppe 128 +|Server|Produktiv-Server 129 +|Linux|Alle Linux-Hosts 130 + 131 +{{code language="bash"}} 132 +# Gruppen auflisten 133 +/var/ossec/bin/agent_groups -l 134 + 135 +# Agent zuweisen 136 +/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE> 137 + 138 +# Agent-Info 139 +/var/ossec/bin/agent_control -i <AGENT-ID> 140 +{{/code}} 141 + 142 +== 5.3 Shared Agent Config == 143 + 144 +Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}} 145 + 146 +{{code language="xml"}} 147 +<agent_config> 148 + <wodle name="command"> 149 + <disabled>no</disabled> 150 + <tag>system-update</tag> 151 + <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command> 152 + <interval>1w</interval> 153 + <run_on_start>yes</run_on_start> 154 + <timeout>600</timeout> 155 + </wodle> 156 +</agent_config> 157 +{{/code}} 158 + 159 +{{info}} 160 +Nach Config-Aenderungen: Agents per API neustarten fuer sofortige Uebernahme. 161 +{{/info}} 162 + 163 +---- 164 + 165 += 6. API = 166 + 167 +{{code language="bash"}} 168 +# Token holen 169 +TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \ 170 + "https://<WAZUH-FQDN>:55000/security/user/authenticate" \ 171 + | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])") 172 + 173 +# Agents auflisten 174 +curl -sk -H "Authorization: Bearer $TOKEN" \ 175 + "https://<WAZUH-FQDN>:55000/agents?pretty=true" 176 + 177 +# Agent neustarten 178 +curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \ 179 + "https://<WAZUH-FQDN>:55000/agents/<ID>/restart" 180 +{{/code}} 181 + 182 +|=Aktion|=Methode|=Endpunkt 183 +|Alle Agents|GET|/agents 184 +|Agent-Info|GET|/agents/<ID> 185 +|Agent restart|PUT|/agents/<ID>/restart 186 +|Vulnerabilities|GET|/vulnerability/<ID> 187 + 188 +---- 189 + 190 += 7. Alert-Levels = 191 + 192 +|=Level|=Bedeutung|=Aktion 193 +|0-3|Info/Debug|Keine 194 +|4-6|Niedrig|Beobachten 195 +|7-9|Mittel|Pruefen 196 +|10-12|Hoch|Zeitnah handeln 197 +|13-15|Kritisch|**Sofort handeln** 198 + 199 +Log-Pfade: 200 +* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} 201 +* {{code}}/var/ossec/logs/archives/archives.json{{/code}} 202 +* {{code}}/var/ossec/logs/ossec.log{{/code}} 203 + 204 +---- 205 + 206 += 8. Service-Management = 207 + 208 +{{code language="bash"}} 209 +# Status 210 +systemctl status wazuh-manager wazuh-indexer wazuh-dashboard 211 + 212 +# Neustarten 213 +systemctl restart wazuh-manager 214 + 215 +# Version 216 +/var/ossec/bin/wazuh-control info 217 + 218 +# Agent-Liste 219 +/var/ossec/bin/agent_control -l 220 +{{/code}} 221 + 222 +---- 223 + 224 += 9. Upgrade = 225 + 226 +{{warning}} 227 +**Vor jedem Upgrade:** Backup der Config-Dateien! 228 +{{/warning}} 229 + 230 +{{code language="bash"}} 231 +# Backup 232 +cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak 233 +cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak 234 + 235 +# Upgrade 236 +apt-get update 237 +DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold" 238 +{{/code}} 239 + 240 +=== Bekannte Upgrade-Probleme === 241 + 242 +* **"Application Not Found"** im Dashboard: defaultRoute anpassen (Abschnitt 4.2) 243 +* **SSL-Cert-Pfade falsch:** .dpkg-dist mit Backup vergleichen 244 +* **Agent Version-Mismatch:** Agents zeitnah nachziehen 245 + 246 +---- 247 + 248 += 10. Troubleshooting = 249 + 250 +{{code language="bash"}} 251 +# Dashboard nicht erreichbar? 252 +journalctl -u wazuh-dashboard -n 50 --no-pager 253 + 254 +# Agent verbindet nicht? 255 +/var/ossec/bin/agent_control -i <AGENT-ID> 256 + 257 +# Auf dem Agent: 258 +tail -30 /var/ossec/logs/ossec.log 259 + 260 +# Cert-Probleme? 261 +ls -la /etc/wazuh-dashboard/certs/ 262 +{{/code}} 263 + 264 +---- 265 + 266 +//Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//