Uebersicht
Wazuh ist eine Open-Source SIEM/XDR-Plattform fuer Security Monitoring, Intrusion Detection, Vulnerability Assessment und Compliance.
1. Systemuebersicht
| Eigenschaft | Wert |
|---|---|
| Software | Wazuh SIEM |
| Version | <VERSION> |
| Server | <HOSTNAME> (<IP-ADRESSE>) |
| Dashboard | https://<WAZUH-FQDN> |
| API | https://<WAZUH-FQDN>:55000 |
| OS | Ubuntu 22.04 LTS |
2. Komponenten
| Komponente | Port | Beschreibung |
|---|---|---|
| Wazuh Manager | 1514 (UDP/TCP) | Agent-Kommunikation |
| Wazuh Authd | 1515 | Agent-Registrierung |
| Wazuh API | 55000 | REST API |
| Wazuh Dashboard | 443 | Web-Oberflaeche (OpenSearch Dashboards) |
| Wazuh Indexer | 9200 (lokal) | Datenbank (OpenSearch) |
3. Installation
3.1 Voraussetzungen
- Ubuntu 22.04 LTS oder Debian 11/12
- Mind. 4 GB RAM (8 GB empfohlen)
- Mind. 50 GB Speicher
- Root-Zugang
3.2 All-in-One Installation
curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh
curl -sO https://packages.wazuh.com/4.14/config.yml
# config.yml anpassen (Hostnamen setzen)
bash wazuh-install.sh -a
curl -sO https://packages.wazuh.com/4.14/config.yml
# config.yml anpassen (Hostnamen setzen)
bash wazuh-install.sh -a
Nach der Installation werden Zugangsdaten angezeigt — sofort notieren!
4. Konfiguration
4.1 Manager (ossec.conf)
Pfad: /var/ossec/etc/ossec.conf
<!-- Vulnerability Detection -->
<vulnerability-detector>
<enabled>yes</enabled>
<interval>5m</interval>
<run_on_start>yes</run_on_start>
<provider name="canonical">
<enabled>yes</enabled>
<os>jammy</os>
<update_interval>1h</update_interval>
</provider>
<provider name="debian">
<enabled>yes</enabled>
<os>buster</os>
<os>bullseye</os>
<os>bookworm</os>
<update_interval>1h</update_interval>
</provider>
</vulnerability-detector>
<!-- Active Response -->
<active-response>
<command>firewall-drop</command>
<location>local</location>
<rules_id>5763</rules_id>
<timeout>1800</timeout>
</active-response>
<vulnerability-detector>
<enabled>yes</enabled>
<interval>5m</interval>
<run_on_start>yes</run_on_start>
<provider name="canonical">
<enabled>yes</enabled>
<os>jammy</os>
<update_interval>1h</update_interval>
</provider>
<provider name="debian">
<enabled>yes</enabled>
<os>buster</os>
<os>bullseye</os>
<os>bookworm</os>
<update_interval>1h</update_interval>
</provider>
</vulnerability-detector>
<!-- Active Response -->
<active-response>
<command>firewall-drop</command>
<location>local</location>
<rules_id>5763</rules_id>
<timeout>1800</timeout>
</active-response>
4.2 Dashboard
Pfad: /etc/wazuh-dashboard/opensearch_dashboards.yml
server.host: 0.0.0.0
server.port: 443
opensearch.hosts: https://localhost:9200
server.ssl.enabled: true
server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
uiSettings.overrides.defaultRoute: /app/wz-home
server.port: 443
opensearch.hosts: https://localhost:9200
server.ssl.enabled: true
server.ssl.key: "/etc/wazuh-dashboard/certs/<CERT-KEY>.pem"
server.ssl.certificate: "/etc/wazuh-dashboard/certs/<CERT>.pem"
opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
uiSettings.overrides.defaultRoute: /app/wz-home
5. Agent-Verwaltung
5.1 Agent installieren
curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring \
--keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \
| tee /etc/apt/sources.list.d/wazuh.list
apt-get update
WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
systemctl daemon-reload
systemctl enable wazuh-agent
systemctl start wazuh-agent
--keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" \
| tee /etc/apt/sources.list.d/wazuh.list
apt-get update
WAZUH_MANAGER="<MANAGER-IP>" apt-get install wazuh-agent
systemctl daemon-reload
systemctl enable wazuh-agent
systemctl start wazuh-agent
5.2 Agent-Gruppen
| Gruppe | Beschreibung |
|---|---|
| default | Standard-Gruppe |
| Server | Produktiv-Server |
| Linux | Alle Linux-Hosts |
# Gruppen auflisten
/var/ossec/bin/agent_groups -l
# Agent zuweisen
/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE>
# Agent-Info
/var/ossec/bin/agent_control -i <AGENT-ID>
/var/ossec/bin/agent_groups -l
# Agent zuweisen
/var/ossec/bin/agent_groups -a -i <AGENT-ID> -g <GRUPPE>
# Agent-Info
/var/ossec/bin/agent_control -i <AGENT-ID>
5.3 Shared Agent Config
Pfad: /var/ossec/etc/shared/<GRUPPE>/agent.conf
<agent_config>
<wodle name="command">
<disabled>no</disabled>
<tag>system-update</tag>
<command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
<interval>1w</interval>
<run_on_start>yes</run_on_start>
<timeout>600</timeout>
</wodle>
</agent_config>
<wodle name="command">
<disabled>no</disabled>
<tag>system-update</tag>
<command>apt-get update && DEBIAN_FRONTEND=noninteractive apt-get upgrade -y</command>
<interval>1w</interval>
<run_on_start>yes</run_on_start>
<timeout>600</timeout>
</wodle>
</agent_config>
6. API
# Token holen
TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \
"https://<WAZUH-FQDN>:55000/security/user/authenticate" \
| python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
# Agents auflisten
curl -sk -H "Authorization: Bearer $TOKEN" \
"https://<WAZUH-FQDN>:55000/agents?pretty=true"
# Agent neustarten
curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \
"https://<WAZUH-FQDN>:55000/agents/<ID>/restart"
TOKEN=$(curl -sk -u <USER>:<PASS> -X POST \
"https://<WAZUH-FQDN>:55000/security/user/authenticate" \
| python3 -c "import sys,json; print(json.load(sys.stdin)['data']['token'])")
# Agents auflisten
curl -sk -H "Authorization: Bearer $TOKEN" \
"https://<WAZUH-FQDN>:55000/agents?pretty=true"
# Agent neustarten
curl -sk -X PUT -H "Authorization: Bearer $TOKEN" \
"https://<WAZUH-FQDN>:55000/agents/<ID>/restart"
| Aktion | Methode | Endpunkt |
|---|---|---|
| Alle Agents | GET | /agents |
| Agent-Info | GET | /agents/<ID> |
| Agent restart | PUT | /agents/<ID>/restart |
| Vulnerabilities | GET | /vulnerability/<ID> |
7. Alert-Levels
| Level | Bedeutung | Aktion |
|---|---|---|
| 0-3 | Info/Debug | Keine |
| 4-6 | Niedrig | Beobachten |
| 7-9 | Mittel | Pruefen |
| 10-12 | Hoch | Zeitnah handeln |
| 13-15 | Kritisch | Sofort handeln |
Log-Pfade:
- /var/ossec/logs/alerts/alerts.json
- /var/ossec/logs/archives/archives.json
- /var/ossec/logs/ossec.log
8. Service-Management
# Status
systemctl status wazuh-manager wazuh-indexer wazuh-dashboard
# Neustarten
systemctl restart wazuh-manager
# Version
/var/ossec/bin/wazuh-control info
# Agent-Liste
/var/ossec/bin/agent_control -l
systemctl status wazuh-manager wazuh-indexer wazuh-dashboard
# Neustarten
systemctl restart wazuh-manager
# Version
/var/ossec/bin/wazuh-control info
# Agent-Liste
/var/ossec/bin/agent_control -l
9. Upgrade
# Backup
cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
# Upgrade
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.conf.bak
cp /etc/wazuh-dashboard/opensearch_dashboards.yml /etc/wazuh-dashboard/opensearch_dashboards.yml.bak
# Upgrade
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get upgrade -y -o Dpkg::Options::="--force-confold"
Bekannte Upgrade-Probleme
- "Application Not Found" im Dashboard: defaultRoute anpassen (Abschnitt 4.2)
- SSL-Cert-Pfade falsch: .dpkg-dist mit Backup vergleichen
- Agent Version-Mismatch: Agents zeitnah nachziehen
10. Troubleshooting
# Dashboard nicht erreichbar?
journalctl -u wazuh-dashboard -n 50 --no-pager
# Agent verbindet nicht?
/var/ossec/bin/agent_control -i <AGENT-ID>
# Auf dem Agent:
tail -30 /var/ossec/logs/ossec.log
# Cert-Probleme?
ls -la /etc/wazuh-dashboard/certs/
journalctl -u wazuh-dashboard -n 50 --no-pager
# Agent verbindet nicht?
/var/ossec/bin/agent_control -i <AGENT-ID>
# Auf dem Agent:
tail -30 /var/ossec/logs/ossec.log
# Cert-Probleme?
ls -la /etc/wazuh-dashboard/certs/
Erstellt: 2026-02-03 | Autor: JARVIS | Version: 1.0