Wazuh SIEM

Version 2.1 by Jarvis on 2026/02/03 22:37

shield
Uebersicht

Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.

1. Systemuebersicht

EigenschaftWert
SoftwareWazuh SIEM
Version<VERSION>
Server<HOSTNAME> (<IP-ADRESSE>)
Dashboardhttps://<WAZUH-FQDN>
APIhttps://<WAZUH-FQDN>:55000
OSUbuntu 22.04 LTS

2. Komponenten

KomponentePortBeschreibung
Wazuh Manager1514 (UDP/TCP)Agent-Kommunikation
Wazuh Authd1515Agent-Registrierung
Wazuh API55000REST API
Wazuh Dashboard443Web-Oberflaeche (OpenSearch Dashboards)
Wazuh Indexer9200 (lokal)Datenbank (OpenSearch)

3. Installation

3.1 Voraussetzungen

  • Ubuntu 22.04 LTS oder Debian 11/12
  • Mind. 4 GB RAM (8 GB empfohlen)
  • Mind. 50 GB Speicher
  • Root-Zugang

3.2 All-in-One Installation

curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
curl -sO https://packages.wazuh.com/4.14/config.yml

# config.yml anpassen (Hostnamen setzen)
bash wazuh-install.sh -a

Nach der Installation werden Zugangsdaten angezeigt — sofort notieren!


4. Konfiguration

4.1 Manager (ossec.conf)

Pfad: /var/ossec/etc/ossec.conf

<!-- Vulnerability Detection -->
<vulnerability-detector>
 <enabled>yes</enabled>
 <interval>5m</interval>
 <run_on_start>yes</run_on_start>
 <provider name="canonical">
   <enabled>yes</enabled>
   <os>jammy</os>
   <update_interval>1h</update_interval>
 </provider>
 <provider name="debian">
   <enabled>yes</enabled>
   <os>buster</os>
   <os>bullseye</os>
   <os>bookworm</os>
   <update_interval>1h</update_interval>
 </provider>
</vulnerability-detector>

<!-- Active Response -->
<active-response>
 <command>firewall-drop</command>
 <location>local</location>
 <rules_id>5763</rules_id>
 <timeout>1800</timeout>
</active-response>

4.2 Dashboard

Pfad: /etc/wazuh-dashboard/opensearch_dashboards.yml

server.host: 0.0.0.0
server.port: 443
opensearch.hosts: https://localhost:9200
server.ssl.enabled: true
server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
uiSettings.overrides.defaultRoute: /app/wz-home

Bei Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von /app/wazuh zu /app/wz-home. Cert-Dateinamen koennen sich ebenfalls aendern!


5. Agent-Verwaltung

5.1 Agent installieren

curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring \
 --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg

echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \
 | tee /etc/apt/sources.list.d/wazuh.list

apt-get update
WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent

systemctl daemon-reload
systemctl enable wazuh-agent
systemctl start wazuh-agent

5.2 Agent-Gruppen

GruppeBeschreibung
defaultStandard-Gruppe
ServerProduktiv-Server
LinuxAlle Linux-Hosts
# Gruppen auflisten
/var/ossec/bin/agent_groups -l

# Agent zuweisen
/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE>

# Agent-Info
/var/ossec/bin/agent_control -i <AGENT-ID>

5.3 Shared Agent Config

Pfad: /var/ossec/etc/shared/<GRUPPE>/agent.conf

<agent_config>
 <wodle name="command">
   <disabled>no</disabled>
   <tag>system-update</tag>
   <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
   <interval>1w</interval>
   <run_on_start>yes</run_on_start>
   <timeout>600</timeout>
 </wodle>
</agent_config>

Nach Config-Aenderungen: Agents per API neustarten fuer sofortige Uebernahme.


6. API

# Token holen
TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \
 "https://<WAZUH-FQDN>:55000/security/user/authenticate" \
 | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")

# Agents auflisten
curl -sk -H "Authorization: Bearer $TOKEN" \
 "https://<WAZUH-FQDN>:55000/agents?pretty=true"

# Agent neustarten
curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \
 "https://<WAZUH-FQDN>:55000/agents/<ID>/restart"
AktionMethodeEndpunkt
Alle AgentsGET/agents
Agent-InfoGET/agents/<ID>
Agent restartPUT/agents/<ID>/restart
VulnerabilitiesGET/vulnerability/<ID>

7. Alert-Levels

LevelBedeutungAktion
0-3Info/DebugKeine
4-6NiedrigBeobachten
7-9MittelPruefen
10-12HochZeitnah handeln
13-15KritischSofort handeln

Log-Pfade:

  • /var/ossec/logs/alerts/alerts.json
  • /var/ossec/logs/archives/archives.json
  • /var/ossec/logs/ossec.log

8. Service-Management

# Status
systemctl status wazuh-manager wazuh-indexer wazuh-dashboard

# Neustarten
systemctl restart wazuh-manager

# Version
/var/ossec/bin/wazuh-control info

# Agent-Liste
/var/ossec/bin/agent_control -l

9. Upgrade

Vor jedem Upgrade: Backup der Config-Dateien!

# Backup
cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak

# Upgrade
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"

Bekannte Upgrade-Probleme

  • "Application Not Found" im Dashboard: defaultRoute anpassen (Abschnitt 4.2)
  • SSL-Cert-Pfade falsch: .dpkg-dist mit Backup vergleichen
  • Agent Version-Mismatch: Agents zeitnah nachziehen

10. Troubleshooting

# Dashboard nicht erreichbar?
journalctl -u wazuh-dashboard -n 50 --no-pager

# Agent verbindet nicht?
/var/ossec/bin/agent_control -i <AGENT-ID>

# Auf dem Agent:
tail -30 /var/ossec/logs/ossec.log

# Cert-Probleme?
ls -la /etc/wazuh-dashboard/certs/

Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0

    

Applications

Need help?

If you need help with XWiki you can contact: