Wiki source code of Wazuh SIEM

Version 2.1 by Jarvis on 2026/02/03 22:37

Show last authors
1 {{box title="Uebersicht" image="icon:shield"}}Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.{{/box}}
2
3 = 1. Systemuebersicht =
4
5 |=Eigenschaft|=Wert
6 |Software|Wazuh SIEM
7 |Version|<VERSION>
8 |Server|<HOSTNAME> (<IP-ADRESSE>)
9 |Dashboard|https://<WAZUH-FQDN>
10 |API|https://<WAZUH-FQDN>:55000
11 |OS|Ubuntu 22.04 LTS
12
13 ----
14
15 = 2. Komponenten =
16
17 |=Komponente|=Port|=Beschreibung
18 |Wazuh Manager|1514 (UDP/TCP)|Agent-Kommunikation
19 |Wazuh Authd|1515|Agent-Registrierung
20 |Wazuh API|55000|REST API
21 |Wazuh Dashboard|443|Web-Oberflaeche (OpenSearch Dashboards)
22 |Wazuh Indexer|9200 (lokal)|Datenbank (OpenSearch)
23
24 ----
25
26 = 3. Installation =
27
28 == 3.1 Voraussetzungen ==
29
30 * Ubuntu 22.04 LTS oder Debian 11/12
31 * Mind. 4 GB RAM (8 GB empfohlen)
32 * Mind. 50 GB Speicher
33 * Root-Zugang
34
35 == 3.2 All-in-One Installation ==
36
37 {{code language="bash"}}
38 curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
39 curl -sO https://packages.wazuh.com/4.14/config.yml
40
41 # config.yml anpassen (Hostnamen setzen)
42 bash wazuh-install.sh -a
43 {{/code}}
44
45 Nach der Installation werden Zugangsdaten angezeigt — **sofort notieren!**
46
47 ----
48
49 = 4. Konfiguration =
50
51 == 4.1 Manager (ossec.conf) ==
52
53 Pfad: {{code language="none"}}/var/ossec/etc/ossec.conf{{/code}}
54
55 {{code language="xml"}}
56 <!-- Vulnerability Detection -->
57 <vulnerability-detector>
58 <enabled>yes</enabled>
59 <interval>5m</interval>
60 <run_on_start>yes</run_on_start>
61 <provider name="canonical">
62 <enabled>yes</enabled>
63 <os>jammy</os>
64 <update_interval>1h</update_interval>
65 </provider>
66 <provider name="debian">
67 <enabled>yes</enabled>
68 <os>buster</os>
69 <os>bullseye</os>
70 <os>bookworm</os>
71 <update_interval>1h</update_interval>
72 </provider>
73 </vulnerability-detector>
74
75 <!-- Active Response -->
76 <active-response>
77 <command>firewall-drop</command>
78 <location>local</location>
79 <rules_id>5763</rules_id>
80 <timeout>1800</timeout>
81 </active-response>
82 {{/code}}
83
84 == 4.2 Dashboard ==
85
86 Pfad: {{code language="none"}}/etc/wazuh-dashboard/opensearch_dashboards.yml{{/code}}
87
88 {{code language="yaml"}}
89 server.host: 0.0.0.0
90 server.port: 443
91 opensearch.hosts: https://localhost:9200
92 server.ssl.enabled: true
93 server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
94 server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
95 opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
96 uiSettings.overrides.defaultRoute: /app/wz-home
97 {{/code}}
98
99 {{warning}}
100 Bei Upgrade von 4.7.x auf 4.14.x aendert sich die defaultRoute von /app/wazuh zu /app/wz-home. Cert-Dateinamen koennen sich ebenfalls aendern!
101 {{/warning}}
102
103 ----
104
105 = 5. Agent-Verwaltung =
106
107 == 5.1 Agent installieren ==
108
109 {{code language="bash"}}
110 curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring \
111 --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
112
113 echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \
114 | tee /etc/apt/sources.list.d/wazuh.list
115
116 apt-get update
117 WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
118
119 systemctl daemon-reload
120 systemctl enable wazuh-agent
121 systemctl start wazuh-agent
122 {{/code}}
123
124 == 5.2 Agent-Gruppen ==
125
126 |=Gruppe|=Beschreibung
127 |default|Standard-Gruppe
128 |Server|Produktiv-Server
129 |Linux|Alle Linux-Hosts
130
131 {{code language="bash"}}
132 # Gruppen auflisten
133 /var/ossec/bin/agent_groups -l
134
135 # Agent zuweisen
136 /var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE>
137
138 # Agent-Info
139 /var/ossec/bin/agent_control -i <AGENT-ID>
140 {{/code}}
141
142 == 5.3 Shared Agent Config ==
143
144 Pfad: {{code language="none"}}/var/ossec/etc/shared/<GRUPPE>/agent.conf{{/code}}
145
146 {{code language="xml"}}
147 <agent_config>
148 <wodle name="command">
149 <disabled>no</disabled>
150 <tag>system-update</tag>
151 <command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
152 <interval>1w</interval>
153 <run_on_start>yes</run_on_start>
154 <timeout>600</timeout>
155 </wodle>
156 </agent_config>
157 {{/code}}
158
159 {{info}}
160 Nach Config-Aenderungen: Agents per API neustarten fuer sofortige Uebernahme.
161 {{/info}}
162
163 ----
164
165 = 6. API =
166
167 {{code language="bash"}}
168 # Token holen
169 TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \
170 "https://<WAZUH-FQDN>:55000/security/user/authenticate" \
171 | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
172
173 # Agents auflisten
174 curl -sk -H "Authorization: Bearer $TOKEN" \
175 "https://<WAZUH-FQDN>:55000/agents?pretty=true"
176
177 # Agent neustarten
178 curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \
179 "https://<WAZUH-FQDN>:55000/agents/<ID>/restart"
180 {{/code}}
181
182 |=Aktion|=Methode|=Endpunkt
183 |Alle Agents|GET|/agents
184 |Agent-Info|GET|/agents/<ID>
185 |Agent restart|PUT|/agents/<ID>/restart
186 |Vulnerabilities|GET|/vulnerability/<ID>
187
188 ----
189
190 = 7. Alert-Levels =
191
192 |=Level|=Bedeutung|=Aktion
193 |0-3|Info/Debug|Keine
194 |4-6|Niedrig|Beobachten
195 |7-9|Mittel|Pruefen
196 |10-12|Hoch|Zeitnah handeln
197 |13-15|Kritisch|**Sofort handeln**
198
199 Log-Pfade:
200 * {{code}}/var/ossec/logs/alerts/alerts.json{{/code}}
201 * {{code}}/var/ossec/logs/archives/archives.json{{/code}}
202 * {{code}}/var/ossec/logs/ossec.log{{/code}}
203
204 ----
205
206 = 8. Service-Management =
207
208 {{code language="bash"}}
209 # Status
210 systemctl status wazuh-manager wazuh-indexer wazuh-dashboard
211
212 # Neustarten
213 systemctl restart wazuh-manager
214
215 # Version
216 /var/ossec/bin/wazuh-control info
217
218 # Agent-Liste
219 /var/ossec/bin/agent_control -l
220 {{/code}}
221
222 ----
223
224 = 9. Upgrade =
225
226 {{warning}}
227 **Vor jedem Upgrade:** Backup der Config-Dateien!
228 {{/warning}}
229
230 {{code language="bash"}}
231 # Backup
232 cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
233 cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
234
235 # Upgrade
236 apt-get update
237 DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
238 {{/code}}
239
240 === Bekannte Upgrade-Probleme ===
241
242 * **"Application Not Found"** im Dashboard: defaultRoute anpassen (Abschnitt 4.2)
243 * **SSL-Cert-Pfade falsch:** .dpkg-dist mit Backup vergleichen
244 * **Agent Version-Mismatch:** Agents zeitnah nachziehen
245
246 ----
247
248 = 10. Troubleshooting =
249
250 {{code language="bash"}}
251 # Dashboard nicht erreichbar?
252 journalctl -u wazuh-dashboard -n 50 --no-pager
253
254 # Agent verbindet nicht?
255 /var/ossec/bin/agent_control -i <AGENT-ID>
256
257 # Auf dem Agent:
258 tail -30 /var/ossec/logs/ossec.log
259
260 # Cert-Probleme?
261 ls -la /etc/wazuh-dashboard/certs/
262 {{/code}}
263
264 ----
265
266 //Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0//

Need help?

If you need help with XWiki you can contact: