Uebersicht
Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.
1. Systemuebersicht
| Eigenschaft | Wert |
|---|---|
| Software | Wazuh SIEM |
| Version | <VERSION> (z.B. 4.14.2) |
| Server | <HOSTNAME> (<IP-ADRESSE>) |
| Dashboard | https://<WAZUH-FQDN> |
| API | https://<WAZUH-FQDN>:55000 |
| OS | Ubuntu 22.04 LTS |
2. Komponenten
| Komponente | Port | Beschreibung |
|---|---|---|
| Wazuh Manager | 1514 (UDP/TCP) | Agent-Kommunikation |
| Wazuh Authd | 1515 | Agent-Registrierung |
| Wazuh API | 55000 | REST API |
| Wazuh Dashboard | 443 | Web-Oberflaeche (OpenSearch Dashboards) |
| Wazuh Indexer | 9200 (lokal) | Datenbank (OpenSearch) |
3. Installation
3.1 Voraussetzungen
- Ubuntu 22.04 LTS oder Debian 11/12
- Mind. 4 GB RAM (8 GB empfohlen)
- Mind. 50 GB Speicher
- Root-Zugang
3.2 All-in-One Installation
# Wazuh Installation Script
curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
curl -sO https://packages.wazuh.com/4.14/config.yml
# config.yml anpassen (Hostnamen setzen)
# Dann ausfuehren:
bash wazuh-install.sh -a
curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
curl -sO https://packages.wazuh.com/4.14/config.yml
# config.yml anpassen (Hostnamen setzen)
# Dann ausfuehren:
bash wazuh-install.sh -a
Nach der Installation werden Zugangsdaten angezeigt — sofort notieren!
4. Konfiguration
4.1 Manager (ossec.conf)
Pfad: /var/ossec/etc/ossec.conf
Wichtige Sektionen:
<!-- Vulnerability Detection -->
<vulnerability-detector>
<enabled>yes</enabled>
<interval>5m</interval>
<run_on_start>yes</run_on_start>
<provider name="canonical">
<enabled>yes</enabled>
<os>jammy</os>
<update_interval>1h</update_interval>
</provider>
<provider name="debian">
<enabled>yes</enabled>
<os>buster</os>
<os>bullseye</os>
<os>bookworm</os>
<update_interval>1h</update_interval>
</provider>
<provider name="nvd">
<enabled>yes</enabled>
<update_interval>1h</update_interval>
</provider>
</vulnerability-detector>
<!-- Active Response (z.B. Brute-Force Block) -->
<active-response>
<command>firewall-drop</command>
<location>local</location>
<rules_id>5763</rules_id>
<timeout>1800</timeout>
</active-response>
<vulnerability-detector>
<enabled>yes</enabled>
<interval>5m</interval>
<run_on_start>yes</run_on_start>
<provider name="canonical">
<enabled>yes</enabled>
<os>jammy</os>
<update_interval>1h</update_interval>
</provider>
<provider name="debian">
<enabled>yes</enabled>
<os>buster</os>
<os>bullseye</os>
<os>bookworm</os>
<update_interval>1h</update_interval>
</provider>
<provider name="nvd">
<enabled>yes</enabled>
<update_interval>1h</update_interval>
</provider>
</vulnerability-detector>
<!-- Active Response (z.B. Brute-Force Block) -->
<active-response>
<command>firewall-drop</command>
<location>local</location>
<rules_id>5763</rules_id>
<timeout>1800</timeout>
</active-response>
4.2 Dashboard (opensearch_dashboards.yml)
Pfad: /etc/wazuh-dashboard/opensearch_dashboards.yml
server.host: 0.0.0.0
server.port: 443
opensearch.hosts: https://localhost:9200
server.ssl.enabled: true
server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
uiSettings.overrides.defaultRoute: /app/wz-home
server.port: 443
opensearch.hosts: https://localhost:9200
server.ssl.enabled: true
server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
uiSettings.overrides.defaultRoute: /app/wz-home
5. Agent-Verwaltung
5.1 Agent installieren
# Auf dem Ziel-System:
curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list
apt-get update
WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
systemctl daemon-reload
systemctl enable wazuh-agent
systemctl start wazuh-agent
curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list
apt-get update
WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
systemctl daemon-reload
systemctl enable wazuh-agent
systemctl start wazuh-agent
5.2 Agent-Gruppen
Gruppen ermoelichen unterschiedliche Konfigurationen pro Server-Typ:
| Gruppe | Beschreibung | Agents |
|---|---|---|
| default | Standard-Gruppe | Allgemeine Hosts |
| Server | Produktiv-Server | Anwendungs-Server |
| Linux | Alle Linux-Hosts | Alle Linux-Agents |
# Gruppen auflisten
/var/ossec/bin/agent_groups -l
# Agent einer Gruppe zuweisen
/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPENNAME>
# Agent-Info anzeigen
/var/ossec/bin/agent_control -i <AGENT-ID>
/var/ossec/bin/agent_groups -l
# Agent einer Gruppe zuweisen
/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPENNAME>
# Agent-Info anzeigen
/var/ossec/bin/agent_control -i <AGENT-ID>
5.3 Shared Agent Config (Remote-Befehle)
Ueber Gruppen-Configs koennen Befehle auf Agents ausgefuehrt werden:
Pfad: /var/ossec/etc/shared/<GRUPPE>/agent.conf
<agent_config>
<!-- System Update per Wodle Command -->
<wodle name="command">
<disabled>no</disabled>
<tag>system-update</tag>
<command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
<interval>1w</interval>
<ignore_output>no</ignore_output>
<run_on_start>yes</run_on_start>
<timeout>600</timeout>
</wodle>
</agent_config>
<!-- System Update per Wodle Command -->
<wodle name="command">
<disabled>no</disabled>
<tag>system-update</tag>
<command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
<interval>1w</interval>
<ignore_output>no</ignore_output>
<run_on_start>yes</run_on_start>
<timeout>600</timeout>
</wodle>
</agent_config>
6. API
6.1 Authentifizierung
# Token holen
TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
# Agents auflisten
curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true"
TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
# Agents auflisten
curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true"
6.2 Nuetzliche API-Aufrufe
| Aktion | Methode | Endpunkt |
|---|---|---|
| Alle Agents | GET | /agents |
| Agent-Info | GET | /agents/<ID> |
| Agent neustarten | PUT | /agents/<ID>/restart |
| Vulnerabilities | GET | /vulnerability/<ID> |
| Active Response | PUT | /active-response |
7. Alerts und Severity-Levels
| Level | Bedeutung | Aktion |
|---|---|---|
| 0-3 | Info/Debug | Keine |
| 4-6 | Niedrig | Beobachten |
| 7-9 | Mittel | Pruefen |
| 10-12 | Hoch | Zeitnah handeln |
| 13-15 | Kritisch | Sofort handeln |
Alert-Logdateien:
- /var/ossec/logs/alerts/alerts.json — Alle Alerts
- /var/ossec/logs/archives/archives.json — Alle Events (wenn aktiviert)
- /var/ossec/logs/ossec.log — Manager-Log
8. Service-Management
# Status pruefen
systemctl status wazuh-manager
systemctl status wazuh-indexer
systemctl status wazuh-dashboard
# Neustarten
systemctl restart wazuh-manager
# Version pruefen
/var/ossec/bin/wazuh-control info
# Agent-Liste
/var/ossec/bin/agent_control -l
systemctl status wazuh-manager
systemctl status wazuh-indexer
systemctl status wazuh-dashboard
# Neustarten
systemctl restart wazuh-manager
# Version pruefen
/var/ossec/bin/wazuh-control info
# Agent-Liste
/var/ossec/bin/agent_control -l
9. Upgrade
# Backup
cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
# Upgrade
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
# Upgrade
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
Bekannte Probleme nach Upgrade
- Dashboard zeigt "Application Not Found": defaultRoute hat sich geaendert (siehe Abschnitt 4.2)
- SSL-Zertifikat-Pfade: Neue Config erwartet andere Dateinamen — mit Backup vergleichen
- Agent Version-Mismatch: Agents laufen weiter, sollten aber zeitnah auch aktualisiert werden
10. Troubleshooting
# Dashboard nicht erreichbar?
systemctl status wazuh-dashboard
journalctl -u wazuh-dashboard -n 50 --no-pager
# Agent verbindet nicht?
/var/ossec/bin/agent_control -i <AGENT-ID>
# Auf dem Agent:
cat /var/ossec/logs/ossec.log | tail -30
# API-Fehler?
curl -sk -u <USER>:<PASS> https://localhost:55000/
# Cert-Probleme?
ls -la /etc/wazuh-dashboard/certs/
# Pfade in opensearch_dashboards.yml pruefen!
systemctl status wazuh-dashboard
journalctl -u wazuh-dashboard -n 50 --no-pager
# Agent verbindet nicht?
/var/ossec/bin/agent_control -i <AGENT-ID>
# Auf dem Agent:
cat /var/ossec/logs/ossec.log | tail -30
# API-Fehler?
curl -sk -u <USER>:<PASS> https://localhost:55000/
# Cert-Probleme?
ls -la /etc/wazuh-dashboard/certs/
# Pfade in opensearch_dashboards.yml pruefen!
Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0