Changes for page Wazuh SIEM

Last modified by Jarvis on 2026/02/05 08:32

<
From version < 3.1
edited by Jarvis
on 2026/02/05 08:32
To version < 2.1 >
edited by Jarvis
on 2026/02/03 22:37
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -1,17 +1,266 @@
1 -= Wazuh SIEM =
1 +{{box title="Uebersicht" image="icon:shield"}}Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}}
2 2  
3 -Security Information and Event Management System.
3 += 1. Systemuebersicht =
4 4  
5 -== Zugangsdaten ==
6 -* **URL:** https://wazuh.rs-servertech.com
7 -* **Server IP:** 192.168.10.47
8 -* **API Port:** 55000
9 -* **Version:** 4.7.5
5 +|=Eigenschaft|=Wert
6 +|Software|Wazuh SIEM
7 +|Version|<VERSION>
8 +|Server|<HOSTNAME> (<IP-ADRESSE>)
9 +|Dashboard|https://<WAZUH-FQDN>
10 +|API|https://<WAZUH-FQDN>:55000
11 +|OS|Ubuntu 22.04 LTS
10 10  
11 -== Funktionen ==
12 -* Log-Analyse
13 -* Intrusion Detection
14 -* File Integrity Monitoring
15 -* Vulnerability Detection
16 -* Security Analytics
13 +----
17 17  
15 += 2. Komponenten =
16 +
17 +|=Komponente|=Port|=Beschreibung
18 +|Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation
19 +|Wazuh Authd|1515|Agent-Registrierung
20 +|Wazuh API|55000|REST API
21 +|Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards)
22 +|Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch)
23 +
24 +----
25 +
26 += 3. Installation =
27 +
28 +== 3.1 Voraussetzungen ==
29 +
30 +* Ubuntu 22.04 LTS oder Debian 11/12
31 +* Mind. 4 GB RAM (8 GB empfohlen)
32 +* Mind. 50 GB Speicher
33 +* Root-Zugang
34 +
35 +== 3.2 All-in-One Installation ==
36 +
37 +{{code language="bash"}}
38 +curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
39 +curl -sO https://packages.wazuh.com/4.14/config.yml
40 +
41 +# config.yml anpassen (Hostnamen setzen)
42 +bash wazuh-install.sh -a
43 +{{/code}}
44 +
45 +Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!**
46 +
47 +----
48 +
49 += 4. Konfiguration =
50 +
51 +== 4.1 Manager (ossec.conf) ==
52 +
53 +Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}}
54 +
55 +{{code language="xml"}}
56 +<!-- Vulnerability Detection -->
57 +<vulnerability-detector>
58 + <enabled>yes</enabled>
59 + <interval>5m</interval>
60 + <run_on_start>yes</run_on_start>
61 + <provider name="canonical">
62 + <enabled>yes</enabled>
63 + <os>jammy</os>
64 + <update_interval>1h</update_interval>
65 + </provider>
66 + <provider name="debian">
67 + <enabled>yes</enabled>
68 + <os>buster</os>
69 + <os>bullseye</os>
70 + <os>bookworm</os>
71 + <update_interval>1h</update_interval>
72 + </provider>
73 +</vulnerability-detector>
74 +
75 +<!-- Active Response -->
76 +<active-response>
77 + <command>firewall-drop</command>
78 + <location>local</location>
79 + <rules_id>5763</rules_id>
80 + <timeout>1800</timeout>
81 +</active-response>
82 +{{/code}}
83 +
84 +== 4.2 Dashboard ==
85 +
86 +Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}}
87 +
88 +{{code language="yaml"}}
89 +server.host: 0.0.0.0
90 +server.port: 443
91 +opensearch.hosts: https://localhost:9200
92 +server.ssl.enabled: true
93 +server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
94 +server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
95 +opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
96 +uiSettings.overrides.defaultRoute: /app/wz-home
97 +{{/code}}
98 +
99 +{{warning}}
100 +Bei Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von /app/wazuh zu /app/wz-home. Cert-Dateinamen koennen sich ebenfalls aendern!
101 +{{/warning}}
102 +
103 +----
104 +
105 += 5. Agent-Verwaltung =
106 +
107 +== 5.1 Agent installieren ==
108 +
109 +{{code language="bash"}}
110 +curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring \
111 + --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
112 +
113 +echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \
114 + | tee /etc/apt/sources.list.d/wazuh.list
115 +
116 +apt-get update
117 +WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
118 +
119 +systemctl daemon-reload
120 +systemctl enable wazuh-agent
121 +systemctl start wazuh-agent
122 +{{/code}}
123 +
124 +== 5.2 Agent-Gruppen ==
125 +
126 +|=Gruppe|=Beschreibung
127 +|default|Standard-Gruppe
128 +|Server|Produktiv-Server
129 +|Linux|Alle Linux-Hosts
130 +
131 +{{code language="bash"}}
132 +# Gruppen auflisten
133 +/var/ossec/bin/agent_groups -l
134 +
135 +# Agent zuweisen
136 +/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE>
137 +
138 +# Agent-Info
139 +/var/ossec/bin/agent_control -i <AGENT-ID>
140 +{{/code}}
141 +
142 +== 5.3 Shared Agent Config ==
143 +
144 +Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}}
145 +
146 +{{code language="xml"}}
147 +<agent_config>
148 + <wodle name="command">
149 + <disabled>no</disabled>
150 + <tag>system-update</tag>
151 + <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
152 + <interval>1w</interval>
153 + <run_on_start>yes</run_on_start>
154 + <timeout>600</timeout>
155 + </wodle>
156 +</agent_config>
157 +{{/code}}
158 +
159 +{{info}}
160 +Nach Config-Aenderungen: Agents per API neustarten fuer sofortige Uebernahme.
161 +{{/info}}
162 +
163 +----
164 +
165 += 6. API =
166 +
167 +{{code language="bash"}}
168 +# Token holen
169 +TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \
170 + "https://<WAZUH-FQDN>:55000/security/user/authenticate" \
171 + | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
172 +
173 +# Agents auflisten
174 +curl -sk -H "Authorization: Bearer $TOKEN" \
175 + "https://<WAZUH-FQDN>:55000/agents?pretty=true"
176 +
177 +# Agent neustarten
178 +curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \
179 + "https://<WAZUH-FQDN>:55000/agents/<ID>/restart"
180 +{{/code}}
181 +
182 +|=Aktion|=Methode|=Endpunkt
183 +|Alle Agents|GET|/agents
184 +|Agent-Info|GET|/agents/<ID>
185 +|Agent restart|PUT|/agents/<ID>/restart
186 +|Vulnerabilities|GET|/vulnerability/<ID>
187 +
188 +----
189 +
190 += 7. Alert-Levels =
191 +
192 +|=Level|=Bedeutung|=Aktion
193 +|0-3|Info/Debug|Keine
194 +|4-6|Niedrig|Beobachten
195 +|7-9|Mittel|Pruefen
196 +|10-12|Hoch|Zeitnah handeln
197 +|13-15|Kritisch|**Sofort handeln**
198 +
199 +Log-Pfade:
200 +* {{code}}/var/ossec/logs/alerts/alerts.json{{/code}}
201 +* {{code}}/var/ossec/logs/archives/archives.json{{/code}}
202 +* {{code}}/var/ossec/logs/ossec.log{{/code}}
203 +
204 +----
205 +
206 += 8. Service-Management =
207 +
208 +{{code language="bash"}}
209 +# Status
210 +systemctl status wazuh-manager wazuh-indexer wazuh-dashboard
211 +
212 +# Neustarten
213 +systemctl restart wazuh-manager
214 +
215 +# Version
216 +/var/ossec/bin/wazuh-control info
217 +
218 +# Agent-Liste
219 +/var/ossec/bin/agent_control -l
220 +{{/code}}
221 +
222 +----
223 +
224 += 9. Upgrade =
225 +
226 +{{warning}}
227 +**Vor jedem Upgrade:** Backup der Config-Dateien!
228 +{{/warning}}
229 +
230 +{{code language="bash"}}
231 +# Backup
232 +cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
233 +cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
234 +
235 +# Upgrade
236 +apt-get update
237 +DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
238 +{{/code}}
239 +
240 +=== Bekannte Upgrade-Probleme ===
241 +
242 +* **"Application Not Found"** im Dashboard: defaultRoute anpassen (Abschnitt 4.2)
243 +* **SSL-Cert-Pfade falsch:** .dpkg-dist mit Backup vergleichen
244 +* **Agent Version-Mismatch:** Agents zeitnah nachziehen
245 +
246 +----
247 +
248 += 10. Troubleshooting =
249 +
250 +{{code language="bash"}}
251 +# Dashboard nicht erreichbar?
252 +journalctl -u wazuh-dashboard -n 50 --no-pager
253 +
254 +# Agent verbindet nicht?
255 +/var/ossec/bin/agent_control -i <AGENT-ID>
256 +
257 +# Auf dem Agent:
258 +tail -30 /var/ossec/logs/ossec.log
259 +
260 +# Cert-Probleme?
261 +ls -la /etc/wazuh-dashboard/certs/
262 +{{/code}}
263 +
264 +----
265 +
266 +//Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//

Applications

Need help?

If you need help with XWiki you can contact: