Wiki source code of Wazuh SIEM

Version 1.1 by Jarvis on 2026/02/03 22:36

Show last authors
1 {{box title="Uebersicht" image="icon:shield"}}Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}}
2
3 = 1. Systemuebersicht =
4
5 |=Eigenschaft|=Wert
6 |Software|Wazuh SIEM
7 |Version|<VERSION> (z.B. 4.14.2)
8 |Server|<HOSTNAME> (<IP-ADRESSE>)
9 |Dashboard|https://<WAZUH-FQDN>
10 |API|https://<WAZUH-FQDN>:55000
11 |OS|Ubuntu 22.04 LTS
12
13 ----
14
15 = 2. Komponenten =
16
17 |=Komponente|=Port|=Beschreibung
18 |Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation
19 |Wazuh Authd|1515|Agent-Registrierung
20 |Wazuh API|55000|REST API
21 |Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards)
22 |Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch)
23
24 ----
25
26 = 3. Installation =
27
28 == 3.1 Voraussetzungen ==
29
30 * Ubuntu 22.04 LTS oder Debian 11/12
31 * Mind. 4 GB RAM (8 GB empfohlen)
32 * Mind. 50 GB Speicher
33 * Root-Zugang
34
35 == 3.2 All-in-One Installation ==
36
37 {{code language="bash"}}
38 # Wazuh Installation Script
39 curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
40 curl -sO https://packages.wazuh.com/4.14/config.yml
41
42 # config.yml anpassen (Hostnamen setzen)
43 # Dann ausfuehren:
44 bash wazuh-install.sh -a
45 {{/code}}
46
47 Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!**
48
49 ----
50
51 = 4. Konfiguration =
52
53 == 4.1 Manager (ossec.conf) ==
54
55 Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}}
56
57 Wichtige Sektionen:
58
59 {{code language="xml"}}
60 <!-- Vulnerability Detection -->
61 <vulnerability-detector>
62 <enabled>yes</enabled>
63 <interval>5m</interval>
64 <run_on_start>yes</run_on_start>
65 <provider name="canonical">
66 <enabled>yes</enabled>
67 <os>jammy</os>
68 <update_interval>1h</update_interval>
69 </provider>
70 <provider name="debian">
71 <enabled>yes</enabled>
72 <os>buster</os>
73 <os>bullseye</os>
74 <os>bookworm</os>
75 <update_interval>1h</update_interval>
76 </provider>
77 <provider name="nvd">
78 <enabled>yes</enabled>
79 <update_interval>1h</update_interval>
80 </provider>
81 </vulnerability-detector>
82
83 <!-- Active Response (z.B. Brute-Force Block) -->
84 <active-response>
85 <command>firewall-drop</command>
86 <location>local</location>
87 <rules_id>5763</rules_id>
88 <timeout>1800</timeout>
89 </active-response>
90 {{/code}}
91
92 == 4.2 Dashboard (opensearch_dashboards.yml) ==
93
94 Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}}
95
96 {{code language="yaml"}}
97 server.host: 0.0.0.0
98 server.port: 443
99 opensearch.hosts: https://localhost:9200
100 server.ssl.enabled: true
101 server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
102 server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
103 opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
104 uiSettings.overrides.defaultRoute: /app/wz-home
105 {{/code}}
106
107 {{warning}}
108 Bei einem Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von {{code}}/app/wazuh{{/code}} zu {{code}}/app/wz-home{{/code}}. Ausserdem koennen sich die Cert-Dateinamen aendern! Die neue Config liegt als {{code}}.dpkg-dist{{/code}} — Pfade vergleichen und anpassen.
109 {{/warning}}
110
111 ----
112
113 = 5. Agent-Verwaltung =
114
115 == 5.1 Agent installieren ==
116
117 {{code language="bash"}}
118 # Auf dem Ziel-System:
119 curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
120
121 echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list
122
123 apt-get update
124 WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
125
126 systemctl daemon-reload
127 systemctl enable wazuh-agent
128 systemctl start wazuh-agent
129 {{/code}}
130
131 == 5.2 Agent-Gruppen ==
132
133 Gruppen ermoelichen unterschiedliche Konfigurationen pro Server-Typ:
134
135 |=Gruppe|=Beschreibung|=Agents
136 |default|Standard-Gruppe|Allgemeine Hosts
137 |Server|Produktiv-Server|Anwendungs-Server
138 |Linux|Alle Linux-Hosts|Alle Linux-Agents
139
140 {{code language="bash"}}
141 # Gruppen auflisten
142 /var/ossec/bin/agent_groups -l
143
144 # Agent einer Gruppe zuweisen
145 /var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPENNAME>
146
147 # Agent-Info anzeigen
148 /var/ossec/bin/agent_control -i <AGENT-ID>
149 {{/code}}
150
151 == 5.3 Shared Agent Config (Remote-Befehle) ==
152
153 Ueber Gruppen-Configs koennen Befehle auf Agents ausgefuehrt werden:
154
155 Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}}
156
157 {{code language="xml"}}
158 <agent_config>
159 <!-- System Update per Wodle Command -->
160 <wodle name="command">
161 <disabled>no</disabled>
162 <tag>system-update</tag>
163 <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
164 <interval>1w</interval>
165 <ignore_output>no</ignore_output>
166 <run_on_start>yes</run_on_start>
167 <timeout>600</timeout>
168 </wodle>
169 </agent_config>
170 {{/code}}
171
172 {{info}}
173 Nach Aenderungen an der Agent-Config: Agents per API neustarten damit die Config sofort uebernommen wird.
174 {{/info}}
175
176 ----
177
178 = 6. API =
179
180 == 6.1 Authentifizierung ==
181
182 {{code language="bash"}}
183 # Token holen
184 TOKEN=$(curl -sk -u <API-USER>:<API-PASS> -X POST "https://<WAZUH-FQDN>:55000/security/user/authenticate" | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
185
186 # Agents auflisten
187 curl -sk -H "Authorization: Bearer $TOKEN" "https://<WAZUH-FQDN>:55000/agents?pretty=true"
188 {{/code}}
189
190 == 6.2 Nuetzliche API-Aufrufe ==
191
192 |=Aktion|=Methode|=Endpunkt
193 |Alle Agents|GET|/agents
194 |Agent-Info|GET|/agents/<ID>
195 |Agent neustarten|PUT|/agents/<ID>/restart
196 |Vulnerabilities|GET|/vulnerability/<ID>
197 |Active Response|PUT|/active-response
198
199 ----
200
201 = 7. Alerts und Severity-Levels =
202
203 |=Level|=Bedeutung|=Aktion
204 |0-3|Info/Debug|Keine
205 |4-6|Niedrig|Beobachten
206 |7-9|Mittel|Pruefen
207 |10-12|Hoch|Zeitnah handeln
208 |13-15|Kritisch|**Sofort handeln**
209
210 Alert-Logdateien:
211
212 * {{code}}/var/ossec/logs/alerts/alerts.json{{/code}} — Alle Alerts
213 * {{code}}/var/ossec/logs/archives/archives.json{{/code}} — Alle Events (wenn aktiviert)
214 * {{code}}/var/ossec/logs/ossec.log{{/code}} — Manager-Log
215
216 ----
217
218 = 8. Service-Management =
219
220 {{code language="bash"}}
221 # Status pruefen
222 systemctl status wazuh-manager
223 systemctl status wazuh-indexer
224 systemctl status wazuh-dashboard
225
226 # Neustarten
227 systemctl restart wazuh-manager
228
229 # Version pruefen
230 /var/ossec/bin/wazuh-control info
231
232 # Agent-Liste
233 /var/ossec/bin/agent_control -l
234 {{/code}}
235
236 ----
237
238 = 9. Upgrade =
239
240 {{warning}}
241 **Vor jedem Upgrade:** Backup der Config-Dateien erstellen!
242 {{/warning}}
243
244 {{code language="bash"}}
245 # Backup
246 cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
247 cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
248
249 # Upgrade
250 apt-get update
251 DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
252 {{/code}}
253
254 === Bekannte Probleme nach Upgrade ===
255
256 * **Dashboard zeigt "Application Not Found":** defaultRoute hat sich geaendert (siehe Abschnitt 4.2)
257 * **SSL-Zertifikat-Pfade:** Neue Config erwartet andere Dateinamen — mit Backup vergleichen
258 * **Agent Version-Mismatch:** Agents laufen weiter, sollten aber zeitnah auch aktualisiert werden
259
260 ----
261
262 = 10. Troubleshooting =
263
264 {{code language="bash"}}
265 # Dashboard nicht erreichbar?
266 systemctl status wazuh-dashboard
267 journalctl -u wazuh-dashboard -n 50 --no-pager
268
269 # Agent verbindet nicht?
270 /var/ossec/bin/agent_control -i <AGENT-ID>
271 # Auf dem Agent:
272 cat /var/ossec/logs/ossec.log | tail -30
273
274 # API-Fehler?
275 curl -sk -u <USER>:<PASS> https://localhost:55000/
276
277 # Cert-Probleme?
278 ls -la /etc/wazuh-dashboard/certs/
279 # Pfade in opensearch_dashboards.yml pruefen!
280 {{/code}}
281
282 ----
283
284 //Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//