forked from wazuh/wazuh-docker
Add Wazuh indexer cluster configuration
This commit is contained in:
+1
-1
@@ -31,7 +31,7 @@ services:
|
|||||||
|
|
||||||
elasticsearch:
|
elasticsearch:
|
||||||
image: wazuh-indexer
|
image: wazuh-indexer
|
||||||
hostname: elasticsearch
|
hostname: node1
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
- "9700:9700"
|
- "9700:9700"
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
FROM amazon/opendistro-for-elasticsearch-kibana:1.13.2
|
FROM amazon/opendistro-for-elasticsearch-kibana:1.13.2
|
||||||
USER kibana
|
USER kibana
|
||||||
ARG ELASTIC_VERSION=7.10.2
|
ARG ELASTIC_VERSION=7.10.2
|
||||||
ARG WAZUH_VERSION=4.3.0
|
ARG WAZUH_VERSION=4.2.5
|
||||||
ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}"
|
ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}"
|
||||||
|
|
||||||
WORKDIR /usr/share/kibana
|
WORKDIR /usr/share/kibana
|
||||||
|
|||||||
+37
-34
@@ -11,7 +11,7 @@ services:
|
|||||||
- "514:514/udp"
|
- "514:514/udp"
|
||||||
- "55000:55000"
|
- "55000:55000"
|
||||||
environment:
|
environment:
|
||||||
- ELASTICSEARCH_URL=https://elasticsearch:9700
|
- ELASTICSEARCH_URL=https://wazuh-indexer:9700
|
||||||
- ELASTIC_USERNAME=admin
|
- ELASTIC_USERNAME=admin
|
||||||
- ELASTIC_PASSWORD=SecretPassword
|
- ELASTIC_PASSWORD=SecretPassword
|
||||||
- FILEBEAT_SSL_VERIFICATION_MODE=full
|
- FILEBEAT_SSL_VERIFICATION_MODE=full
|
||||||
@@ -42,7 +42,7 @@ services:
|
|||||||
hostname: wazuh-worker
|
hostname: wazuh-worker
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
- ELASTICSEARCH_URL=https://elasticsearch:9700
|
- ELASTICSEARCH_URL=https://wazuh-indexer:9700
|
||||||
- ELASTIC_USERNAME=admin
|
- ELASTIC_USERNAME=admin
|
||||||
- ELASTIC_PASSWORD=SecretPassword
|
- ELASTIC_PASSWORD=SecretPassword
|
||||||
- FILEBEAT_SSL_VERIFICATION_MODE=full
|
- FILEBEAT_SSL_VERIFICATION_MODE=full
|
||||||
@@ -66,14 +66,15 @@ services:
|
|||||||
- ./production_cluster/wazuh_indexer_ssl_certs/filebeat.key:/etc/ssl/filebeat.key
|
- ./production_cluster/wazuh_indexer_ssl_certs/filebeat.key:/etc/ssl/filebeat.key
|
||||||
- ./production_cluster/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf
|
- ./production_cluster/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf
|
||||||
|
|
||||||
elasticsearch:
|
wazuh-indexer:
|
||||||
image: wazuh/wazuh-indexer:4.3.0
|
image: wazuh-indexer
|
||||||
hostname: elasticsearch
|
hostname: wazuh-indexer
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
- "9700:9700"
|
- "9700:9700"
|
||||||
environment:
|
environment:
|
||||||
- "ES_JAVA_OPTS=-Xms512m -Xmx512m -Dlog4j2.formatMsgNoLookups=true"
|
- "ES_JAVA_OPTS=-Xms1g -Xmx1g"
|
||||||
|
- "NODE_TYPE=master"
|
||||||
ulimits:
|
ulimits:
|
||||||
memlock:
|
memlock:
|
||||||
soft: -1
|
soft: -1
|
||||||
@@ -82,21 +83,22 @@ services:
|
|||||||
soft: 65536
|
soft: 65536
|
||||||
hard: 65536
|
hard: 65536
|
||||||
volumes:
|
volumes:
|
||||||
- elastic-data-1:/var/lib/wazuh-indexer
|
- wazuh-indexer-data-1:/var/lib/wazuh-indexer
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/root-ca.pem:/etc/wazuh-indexer/certs/root-ca.pem
|
- ./production_cluster/wazuh_indexer_ssl_certs/root-ca.pem:/etc/wazuh-indexer/certs/root-ca.pem
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/node1.key:/etc/wazuh-indexer/certs/node1.key
|
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh-indexer.key:/etc/wazuh-indexer/certs/wazuh-indexer.key
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/node1.pem:/etc/wazuh-indexer/certs/node1.pem
|
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh-indexer.pem:/etc/wazuh-indexer/certs/wazuh-indexer.pem
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/admin.pem:/etc/wazuh-indexer/certs/admin.pem
|
- ./production_cluster/wazuh_indexer_ssl_certs/admin.pem:/etc/wazuh-indexer/certs/admin.pem
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/admin.key:/etc/wazuh-indexer/certs/admin.key
|
- ./production_cluster/wazuh_indexer_ssl_certs/admin.key:/etc/wazuh-indexer/certs/admin.key
|
||||||
- ./production_cluster/elastic_opendistro/wazuh-indexer-node1.yml:/etc/wazuh-indexer/opensearch.yml
|
- ./production_cluster/wazuh-indexer/opnesearch-node1.yml:/etc/wazuh-indexer/opensearch.yml
|
||||||
- ./production_cluster/elastic_opendistro/internal_users.yml:/usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/internal_users.yml
|
- ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/internal_users.yml
|
||||||
|
|
||||||
elasticsearch-2:
|
wazuh-indexer-2:
|
||||||
image: wazuh/wazuh-indexer:4.3.0
|
image: wazuh-indexer
|
||||||
hostname: elasticsearch-2
|
hostname: wazuh-indexer-2
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
- "ES_JAVA_OPTS=-Xms512m -Xmx512m -Dlog4j2.formatMsgNoLookups=true"
|
- "ES_JAVA_OPTS=-Xms1g -Xmx1g"
|
||||||
|
- "NODE_TYPE=worker"
|
||||||
ulimits:
|
ulimits:
|
||||||
memlock:
|
memlock:
|
||||||
soft: -1
|
soft: -1
|
||||||
@@ -105,19 +107,20 @@ services:
|
|||||||
soft: 65536
|
soft: 65536
|
||||||
hard: 65536
|
hard: 65536
|
||||||
volumes:
|
volumes:
|
||||||
- elastic-data-2:/var/lib/wazuh-indexer
|
- wazuh-indexer-data-2:/var/lib/wazuh-indexer
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/root-ca.pem:/etc/wazuh-indexer/certs/root-ca.pem
|
- ./production_cluster/wazuh_indexer_ssl_certs/root-ca.pem:/etc/wazuh-indexer/certs/root-ca.pem
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/node2.key:/etc/wazuh-indexer/certs/node2.key
|
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh-indexer-2.key:/etc/wazuh-indexer/certs/wazuh-indexer-2.key
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/node2.pem:/etc/wazuh-indexer/certs/node2.pem
|
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh-indexer-2.pem:/etc/wazuh-indexer/certs/wazuh-indexer-2.pem
|
||||||
- ./production_cluster/elastic_opendistro/wazuh-indexer-node2.yml:/etc/wazuh-indexer/elasticsearch.yml
|
- ./production_cluster/wazuh-indexer/opnesearch-node2.yml:/etc/wazuh-indexer/opensearch.yml
|
||||||
- ./production_cluster/elastic_opendistro/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml
|
- ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml
|
||||||
|
|
||||||
elasticsearch-3:
|
wazuh-indexer-3:
|
||||||
image: wazuh/wazuh-indexer:4.3.0
|
image: wazuh-indexer
|
||||||
hostname: elasticsearch-3
|
hostname: wazuh-indexer-3
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
- "ES_JAVA_OPTS=-Xms512m -Xmx512m -Dlog4j2.formatMsgNoLookups=true"
|
- "ES_JAVA_OPTS=-Xms1g -Xmx1g"
|
||||||
|
- "NODE_TYPE=worker"
|
||||||
ulimits:
|
ulimits:
|
||||||
memlock:
|
memlock:
|
||||||
soft: -1
|
soft: -1
|
||||||
@@ -126,12 +129,12 @@ services:
|
|||||||
soft: 65536
|
soft: 65536
|
||||||
hard: 65536
|
hard: 65536
|
||||||
volumes:
|
volumes:
|
||||||
- elastic-data-3:/var/lib/wazuh-indexer
|
- wazuh-indexer-data-3:/var/lib/wazuh-indexer
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/root-ca.pem:/etc/wazuh-indexer/certs/root-ca.pem
|
- ./production_cluster/wazuh_indexer_ssl_certs/root-ca.pem:/etc/wazuh-indexer/certs/root-ca.pem
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/node3.key:/etc/wazuh-indexer/certs/node3.key
|
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh-indexer-3.key:/etc/wazuh-indexer/certs/wazuh-indexer-3.key
|
||||||
- ./production_cluster/wazuh_indexer_ssl_certs/node3.pem:/etc/wazuh-indexer/certs/node3.pem
|
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh-indexer-3.pem:/etc/wazuh-indexer/certs/wazuh-indexer-3.pem
|
||||||
- ./production_cluster/elastic_opendistro/wazuh-indexer-node3.yml:/etc/wazuh-indexer/elasticsearch.yml
|
- ./production_cluster/wazuh-indexer/opnesearch-node3.yml:/etc/wazuh-indexer/opensearch.yml
|
||||||
- ./production_cluster/elastic_opendistro/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml
|
- ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml
|
||||||
|
|
||||||
kibana:
|
kibana:
|
||||||
image: wazuh/wazuh-dashboard:4.3.0
|
image: wazuh/wazuh-dashboard:4.3.0
|
||||||
@@ -153,9 +156,9 @@ services:
|
|||||||
- ./production_cluster/kibana_ssl/key.pem:/etc/wazuh-dashboard/certs/key.pem
|
- ./production_cluster/kibana_ssl/key.pem:/etc/wazuh-dashboard/certs/key.pem
|
||||||
|
|
||||||
depends_on:
|
depends_on:
|
||||||
- elasticsearch
|
- wazuh-indexer
|
||||||
links:
|
links:
|
||||||
- elasticsearch:elasticsearch
|
- wazuh-indexer:wazuh-indexer
|
||||||
- wazuh-master:wazuh-master
|
- wazuh-master:wazuh-master
|
||||||
|
|
||||||
nginx:
|
nginx:
|
||||||
@@ -201,6 +204,6 @@ volumes:
|
|||||||
worker-ossec-wodles:
|
worker-ossec-wodles:
|
||||||
worker-filebeat-etc:
|
worker-filebeat-etc:
|
||||||
worker-filebeat-var:
|
worker-filebeat-var:
|
||||||
elastic-data-1:
|
wazuh-indexer-data-1:
|
||||||
elastic-data-2:
|
wazuh-indexer-data-2:
|
||||||
elastic-data-3:
|
wazuh-indexer-data-3:
|
||||||
|
|||||||
@@ -1,31 +0,0 @@
|
|||||||
network.host: elasticsearch
|
|
||||||
cluster.name: wazuh-cluster
|
|
||||||
node.name: elasticsearch
|
|
||||||
discovery.seed_hosts: elasticsearch,elasticsearch-2,elasticsearch-3
|
|
||||||
cluster.initial_master_nodes: elasticsearch
|
|
||||||
bootstrap.memory_lock: true
|
|
||||||
|
|
||||||
opendistro_security.ssl.transport.pemcert_filepath: node1.pem
|
|
||||||
opendistro_security.ssl.transport.pemkey_filepath: node1.key
|
|
||||||
opendistro_security.ssl.transport.pemtrustedcas_filepath: root-ca.pem
|
|
||||||
opendistro_security.ssl.transport.enforce_hostname_verification: false
|
|
||||||
opendistro_security.ssl.transport.resolve_hostname: false
|
|
||||||
opendistro_security.ssl.http.enabled: true
|
|
||||||
opendistro_security.ssl.http.pemcert_filepath: node1.pem
|
|
||||||
opendistro_security.ssl.http.pemkey_filepath: node1.key
|
|
||||||
opendistro_security.ssl.http.pemtrustedcas_filepath: root-ca.pem
|
|
||||||
opendistro_security.allow_default_init_securityindex: true
|
|
||||||
opendistro_security.nodes_dn:
|
|
||||||
- 'CN=node1,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=node2,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=node3,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
opendistro_security.authcz.admin_dn: ['CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com']
|
|
||||||
opendistro_security.audit.type: internal_elasticsearch
|
|
||||||
opendistro_security.enable_snapshot_restore_privilege: true
|
|
||||||
opendistro_security.check_snapshot_restore_write_privileges: true
|
|
||||||
opendistro_security.restapi.roles_enabled: ["all_access", "security_rest_api_access"]
|
|
||||||
cluster.routing.allocation.disk.threshold_enabled: false
|
|
||||||
#opendistro_security.audit.config.disabled_rest_categories: NONE
|
|
||||||
#opendistro_security.audit.config.disabled_transport_categories: NONE
|
|
||||||
opendistro_security.audit.log_request_body: false
|
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
network.host: elasticsearch-2
|
|
||||||
cluster.name: wazuh-cluster
|
|
||||||
node.name: elasticsearch-2
|
|
||||||
discovery.seed_hosts: elasticsearch,elasticsearch-2,elasticsearch-3
|
|
||||||
cluster.initial_master_nodes: elasticsearch
|
|
||||||
bootstrap.memory_lock: true
|
|
||||||
|
|
||||||
opendistro_security.ssl.transport.pemcert_filepath: node2.pem
|
|
||||||
opendistro_security.ssl.transport.pemkey_filepath: node2.key
|
|
||||||
opendistro_security.ssl.transport.pemtrustedcas_filepath: root-ca.pem
|
|
||||||
opendistro_security.ssl.transport.enforce_hostname_verification: false
|
|
||||||
opendistro_security.ssl.transport.resolve_hostname: false
|
|
||||||
opendistro_security.ssl.http.enabled: true
|
|
||||||
opendistro_security.ssl.http.pemcert_filepath: node2.pem
|
|
||||||
opendistro_security.ssl.http.pemkey_filepath: node2.key
|
|
||||||
opendistro_security.ssl.http.pemtrustedcas_filepath: root-ca.pem
|
|
||||||
opendistro_security.allow_default_init_securityindex: true
|
|
||||||
opendistro_security.nodes_dn:
|
|
||||||
- 'CN=node1,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=node2,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=node3,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
opendistro_security.authcz.admin_dn: ['CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com']
|
|
||||||
opendistro_security.audit.type: internal_elasticsearch
|
|
||||||
opendistro_security.enable_snapshot_restore_privilege: true
|
|
||||||
opendistro_security.check_snapshot_restore_write_privileges: true
|
|
||||||
opendistro_security.restapi.roles_enabled: ["all_access", "security_rest_api_access"]
|
|
||||||
cluster.routing.allocation.disk.threshold_enabled: false
|
|
||||||
#opendistro_security.audit.config.disabled_rest_categories: NONE
|
|
||||||
#opendistro_security.audit.config.disabled_transport_categories: NONE
|
|
||||||
opendistro_security.audit.log_request_body: false
|
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
network.host: elasticsearch-3
|
|
||||||
cluster.name: wazuh-cluster
|
|
||||||
node.name: elasticsearch-3
|
|
||||||
discovery.seed_hosts: elasticsearch,elasticsearch-2,elasticsearch-3
|
|
||||||
cluster.initial_master_nodes: elasticsearch
|
|
||||||
bootstrap.memory_lock: true
|
|
||||||
|
|
||||||
opendistro_security.ssl.transport.pemcert_filepath: node3.pem
|
|
||||||
opendistro_security.ssl.transport.pemkey_filepath: node3.key
|
|
||||||
opendistro_security.ssl.transport.pemtrustedcas_filepath: root-ca.pem
|
|
||||||
opendistro_security.ssl.transport.enforce_hostname_verification: false
|
|
||||||
opendistro_security.ssl.transport.resolve_hostname: false
|
|
||||||
opendistro_security.ssl.http.enabled: true
|
|
||||||
opendistro_security.ssl.http.pemcert_filepath: node3.pem
|
|
||||||
opendistro_security.ssl.http.pemkey_filepath: node3.key
|
|
||||||
opendistro_security.ssl.http.pemtrustedcas_filepath: root-ca.pem
|
|
||||||
opendistro_security.allow_default_init_securityindex: true
|
|
||||||
opendistro_security.nodes_dn:
|
|
||||||
- 'CN=node1,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=node2,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=node3,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
- 'CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com'
|
|
||||||
opendistro_security.authcz.admin_dn: ['CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com']
|
|
||||||
opendistro_security.audit.type: internal_elasticsearch
|
|
||||||
opendistro_security.enable_snapshot_restore_privilege: true
|
|
||||||
opendistro_security.check_snapshot_restore_write_privileges: true
|
|
||||||
opendistro_security.restapi.roles_enabled: ["all_access", "security_rest_api_access"]
|
|
||||||
cluster.routing.allocation.disk.threshold_enabled: false
|
|
||||||
#opendistro_security.audit.config.disabled_rest_categories: NONE
|
|
||||||
#opendistro_security.audit.config.disabled_transport_categories: NONE
|
|
||||||
opendistro_security.audit.log_request_body: false
|
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIDazCCAlOgAwIBAgIUeEaU6PZXSb2RQhzz6NQDsnXgPCYwDQYJKoZIhvcNAQEL
|
||||||
|
BQAwRTELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoM
|
||||||
|
GEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMjAxMjUxNTM4MjRaFw0yMzAx
|
||||||
|
MjUxNTM4MjRaMEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEw
|
||||||
|
HwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwggEiMA0GCSqGSIb3DQEB
|
||||||
|
AQUAA4IBDwAwggEKAoIBAQDKJlBieT/1IJkd4AoUja9eFy6Z+k1yskwRLdVHuYLL
|
||||||
|
EhbDhsOOnoB0Yg7XAylxbyvXvxeNC5uQJWrU5nDwf70cGNmIG29sDd9XXKmEj7lo
|
||||||
|
NffkHBD+/UQb9aodWVaTVnu81qB+jCwi/vThaslb7ycmC+wyPz+P3SZbhQKT3BTI
|
||||||
|
2vYNzznPcugs1qFhnA0Mn4DuY4daEkFDYXjxtxfE8rWZOr+bbhxjgdAp25KaA1Sz
|
||||||
|
k47DiodTxASOumODtR/j/CPm4W9oZQ0y+cAE+mYg8TmMz+kyPK1oW8mMsjUHK1/m
|
||||||
|
EiBCMX1rdOVFNQ3ia7aX+xJzH/7ZDJPg7tG0MbfUxv+7AgMBAAGjUzBRMB0GA1Ud
|
||||||
|
DgQWBBTwTfEThtctV2m1mXpoUE0o7fQgXzAfBgNVHSMEGDAWgBTwTfEThtctV2m1
|
||||||
|
mXpoUE0o7fQgXzAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCq
|
||||||
|
1JHCAZCKFyJh/Dx8vjvXIhPeOjNBWcx4Dl4mw+DlkNyAfX6xJprUy3f/hIuXhZcs
|
||||||
|
TvLjLi2IFcGk/lGUh1SIxyAmyz49rSm/B0rYWR+rBwrEFHZwYHegS/oGtLn1kwZz
|
||||||
|
kMn3WzLFMwBLoSOs5tT3i3E0EAuH/MsO9a61HJUKbWJGG9cv3OtcCSU6wb+lQyK5
|
||||||
|
mTsI8kjVAuKmuzwl9S3I7TqXolhwodz9MAagmLcwSfAU8Ce7qTwwpBOz4YkOHqkH
|
||||||
|
JAZhYEcLbLKCh2mGtB84mdA2pHoxK8y/J05P85ENwcYooFD7gYcsHphkKKKszNmf
|
||||||
|
AArKqDwDGSRGfbq/3rOE
|
||||||
|
-----END CERTIFICATE-----
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
-----BEGIN PRIVATE KEY-----
|
||||||
|
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDKJlBieT/1IJkd
|
||||||
|
4AoUja9eFy6Z+k1yskwRLdVHuYLLEhbDhsOOnoB0Yg7XAylxbyvXvxeNC5uQJWrU
|
||||||
|
5nDwf70cGNmIG29sDd9XXKmEj7loNffkHBD+/UQb9aodWVaTVnu81qB+jCwi/vTh
|
||||||
|
aslb7ycmC+wyPz+P3SZbhQKT3BTI2vYNzznPcugs1qFhnA0Mn4DuY4daEkFDYXjx
|
||||||
|
txfE8rWZOr+bbhxjgdAp25KaA1Szk47DiodTxASOumODtR/j/CPm4W9oZQ0y+cAE
|
||||||
|
+mYg8TmMz+kyPK1oW8mMsjUHK1/mEiBCMX1rdOVFNQ3ia7aX+xJzH/7ZDJPg7tG0
|
||||||
|
MbfUxv+7AgMBAAECggEBAI1K0F6z3vdHjJ4sDP+mtI9wZpsrL1zesHpFbdCPIpMr
|
||||||
|
loudsywJL0GplDPGuv3VNXC72Qs1tMrAzHX4h7Ihpp1v5QPUIUIGRDf8xWOpTW9A
|
||||||
|
YX6n+10uyp88S2XuHqwnA5/O6CjrcqIXUDQKfqlqdBOMu8+3E4dLjNblFhMg/coQ
|
||||||
|
ueGY8BV7bLIIBCxZV9Ca/DuQZQQXBRJjGDEcxWl+GBuWR81P9D5BITma+js9yZKw
|
||||||
|
yvZckvfObSyJ9nR5bsWPlybn3GrdGHeBwXvGXswDekwj9wsRVc00LcQ0BwrwCn7I
|
||||||
|
xjnB0XuoH4+T4OrIS08XQROzKalhUOZKwYilKEt78ikCgYEA+xX+z3QW5lVcDVIx
|
||||||
|
IIU2elZlr515NqSDBkFbdUSAlDQqPxyqQg3y110xymypdJwvh3DL3tuLyAswANKD
|
||||||
|
M3nj8U/hhKKcDjxiHutk/3R3sb+z/X6apS7nfWHn7X2G97Xv1GSp+Jxv+bZAQ+jP
|
||||||
|
k4fe3CB8JHu+V9My69XYBwx6468CgYEAzhsisB+Y0nKBIfoMoB752fFbPissycMI
|
||||||
|
QliFZsp8upIZ8dGeThubhuSMTAvL73rZpN3pJCrAwxKDvwf/sPIK2Q/ux8oB3rUr
|
||||||
|
jkTNM2D51VRNkcNbedg2LJETNzrqChH+J4ZeSMXHG7kkgJHfNiyMOwAzR0pFTtQC
|
||||||
|
tRDrF1j8i7UCgYA2NiuMEx6WoLt9TM+6m8iFZX4TCscPGzoG8bmTejTgytqMQd4o
|
||||||
|
4OYbxc1oTUnRGZ/ReHMsLO7jRDcbFliplpm2km64untDP5pX3q8x0K2/PQrZoqo1
|
||||||
|
HAlzMt5mkoG/nhKoIwvn1679lXIOt4eJ7P4bPRBQuD8Cq2EFNmisLO+jlQKBgGeR
|
||||||
|
MykVd5GogEM2h0mexyZBJfxjbaolGu1b1g0FCxAlgmwFTWsqbEioZ+d+tgesz9kM
|
||||||
|
ua623Q4pK5K+zjl4JwNUAkTauX3TxANFh2ed/2y3ZBMu+7SKdQ6ICAPk0t4klHYA
|
||||||
|
Czi+SYMg0brZkjSCxiSPwTS9mX43AvVBfyDIUn9RAoGBAKfABXsKw34AI2M/Dhyh
|
||||||
|
2tpjW/luRWhzeO9pBDbe7jHOKqXSdFuRj0uniTiAHiK2ozL0xCXvG7b2l2rQQ6dn
|
||||||
|
cPCPagKSZmyFQcHxRr6QG+EGAbKa61eVWlGgEmp8jinv96V9eifgg+W+yH988PwC
|
||||||
|
e+liYHi4YGgobcnMDrIUdWrw
|
||||||
|
-----END PRIVATE KEY-----
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIDazCCAlOgAwIBAgIULAht6hsQE8zjr2rgFMp7AGNsjWAwDQYJKoZIhvcNAQEL
|
||||||
|
BQAwRTELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoM
|
||||||
|
GEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMjAxMjUxNTM4MzNaFw0yMzAx
|
||||||
|
MjUxNTM4MzNaMEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEw
|
||||||
|
HwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwggEiMA0GCSqGSIb3DQEB
|
||||||
|
AQUAA4IBDwAwggEKAoIBAQC/++0tPSSbcSvhVG1VSu+GdJEECzJYrmflmBU6s+PP
|
||||||
|
zQ4wvQSuZKlItQdOyJgoOfX1LZDfmoPvg4cmtaozJZyXqSOEj+Y2RXu+CB1SbonQ
|
||||||
|
PvWWPIGHS2LDWuVF3xgi0yvwiDcbydThjv4iQ9peVwG+6d2Ehg8lo6eENUsnqh2U
|
||||||
|
hn8mGg3mUx+AeGLE8lVQtyFG5ucjn5lobOGbobWVDddCOibCEnoyLXRHH5Z+PQ1d
|
||||||
|
+qCe8QHh7+y9HEo7Qy5HHuZgeAaDglUXrymNE9LvZ+yeeztt1LBsy8bQPqCJ5dS0
|
||||||
|
e4DffxSURZqUFqMLsUDcIMZw1Gb1YNxeX9VzngVew4QRAgMBAAGjUzBRMB0GA1Ud
|
||||||
|
DgQWBBRGuAOx1cBaeCbgkVevNEQ6TnCOCzAfBgNVHSMEGDAWgBRGuAOx1cBaeCbg
|
||||||
|
kVevNEQ6TnCOCzAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAJ
|
||||||
|
S8e8tpUAkEB/zxdCF5R/RsFu0cpeBSma2hEd5o5vjuOCo1lX0Mjx3p16ZI6nlkGG
|
||||||
|
TByVQAQmvETyc2SY/TX9OqBzZIqqSs1mRQOJvF7kEBI6o3JDiURynd54uPKboO6Y
|
||||||
|
rsWAtFwcpzOF+zTUeCNFXPzCwivoKFvnxh2bUFX0WxxTBrR5scKR23BKoMAWeR+h
|
||||||
|
7cXsjd+wI8EhhVduJRvFV8m+rXPgBDHo446aAp0aDC8hEWhnWAIrJKIsmV06ZtKc
|
||||||
|
Kun1/kyNF8QloO4XNoY3DAKWmBW99PgV3gci535AZDMMCrDzZ4bcoqLMfXVR6odh
|
||||||
|
eumaeNEXCPMIb5+vAao3
|
||||||
|
-----END CERTIFICATE-----
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
-----BEGIN PRIVATE KEY-----
|
||||||
|
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQC/++0tPSSbcSvh
|
||||||
|
VG1VSu+GdJEECzJYrmflmBU6s+PPzQ4wvQSuZKlItQdOyJgoOfX1LZDfmoPvg4cm
|
||||||
|
taozJZyXqSOEj+Y2RXu+CB1SbonQPvWWPIGHS2LDWuVF3xgi0yvwiDcbydThjv4i
|
||||||
|
Q9peVwG+6d2Ehg8lo6eENUsnqh2Uhn8mGg3mUx+AeGLE8lVQtyFG5ucjn5lobOGb
|
||||||
|
obWVDddCOibCEnoyLXRHH5Z+PQ1d+qCe8QHh7+y9HEo7Qy5HHuZgeAaDglUXrymN
|
||||||
|
E9LvZ+yeeztt1LBsy8bQPqCJ5dS0e4DffxSURZqUFqMLsUDcIMZw1Gb1YNxeX9Vz
|
||||||
|
ngVew4QRAgMBAAECggEAIp6hVGkUMtujmAyLcrgCnXJjvCDwwUEiByr3mRBbYluN
|
||||||
|
1YggUfpg9HWAjdpqZcad7cp7t3a7l/NV6csUmAiORmL/vqXcU6kP+WKpNvYr79uK
|
||||||
|
mb7rdKRJeQTpF0J1rcH6yHMnzOEGfG42saMeu6hg7jZp9b3e+WCbkqGxncN1dhTC
|
||||||
|
sNsHGGwlvfR0z7soAuVewysnJ5fckEP3mpHnEhegIz9LHeZvRbavpI1q/cgz2+FT
|
||||||
|
h1AAHXSio1dLEypHbTKw3uf+FA9Jpalbm6mBuY+7L0Lh5qkJ3sPdhQn6EfcDPY7O
|
||||||
|
YnsfAfY02g48ZsTbaRokPMDN95DWV0MmS4bMaUMlYQKBgQDtVJfC6ZOANtZCKFXO
|
||||||
|
/Rs20i9CYMXOp4m7qlfiKAezp5bh2uUlh49/BeAUJ45Hf5o+RleAhowmS3PTjy9t
|
||||||
|
vDBuU0m13K9b2e8KlFOSEkkwRhEChkHa3aTsIYgI1cXhTVIl9sRRHWLmFe0C5DEG
|
||||||
|
WQMjYL6POByAI8DNMdPv0aqe7QKBgQDPFiPODbRav0vabFl3E1R7ff2PpXSKgGj6
|
||||||
|
Y/oeM+iAKwE6/9aHIqsDLaSMzAVXb0TMvEEjI77tIfGg3Azv/lfq3j4bXMEWVY6H
|
||||||
|
92JBDqagSxzzbFcqelyzEKLFBYG01MUEwOz8oNcIiQNndw8xakH04csBzHTMWUMb
|
||||||
|
3jUujDJxNQKBgQDNZN6KkzdSSSMY0mug3bAFu9WmrrXCaYBr57pzQY2Yz7tm79hM
|
||||||
|
qItptR3+k1UxT5+fsaTc2JTGN5qgR1UWtT183Zv3RmyFI5EbKM9CpYytuJXUB3lK
|
||||||
|
/3NR4Jsoekns+MvVi0DPqo0C74rVa8N56OMsZPfGXxtbUpXzf+IZtOzi6QKBgCKp
|
||||||
|
2BBzps7R2oaTQF54M9n/+uOClIFigS/4cDOCCNb7W9deX7B7ExkTGMoglHxQObnz
|
||||||
|
gQu6vgi/d8yvSNMbReggj1DRM9jjNVp5BE9TfnyyVgRBDE4l8UJf9H76Lv3v55Km
|
||||||
|
IIUg/x2Eobc97KMe4C93ZB3G9X4HKv6NMWW7Pe5JAoGBAJwsmcmyhgCmJ1F5dYj4
|
||||||
|
kOZaiJrM8XNKdeIskzpyyfJRAbLWtClc2iZdOBP3YKnSYB5CyI16Padp60cDhVrX
|
||||||
|
5M1s/Uf8aJP+T/dtXPKH+Mug1Qbc5vBHKpEGaZNuvfbauTAH2B+QaoeVmEqNQg7T
|
||||||
|
lO5yoHbI38TYyvnY4YAmJ+N2
|
||||||
|
-----END PRIVATE KEY-----
|
||||||
@@ -1,35 +1,22 @@
|
|||||||
ca:
|
|
||||||
root:
|
|
||||||
dn: CN=root-ca,OU=CA,O=Example\, Inc.,DC=example,DC=com
|
|
||||||
pkPassword: none
|
|
||||||
keysize: 2048
|
|
||||||
file: root-ca.pem
|
|
||||||
intermediate:
|
|
||||||
dn: CN=intermediate,OU=CA,O=Example\, Inc.,DC=example,DC=com
|
|
||||||
keysize: 2048
|
|
||||||
validityDays: 3650
|
|
||||||
pkPassword: intermediate-ca-password
|
|
||||||
file: intermediate-ca.pem
|
|
||||||
|
|
||||||
nodes:
|
nodes:
|
||||||
- name: node1
|
# Elasticsearch server nodes
|
||||||
dn: CN=node1,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
#wazuh-indexer:
|
||||||
dns:
|
- name: wazuh-indexer
|
||||||
- elasticsearch
|
ip: wazuh-indexer
|
||||||
- name: node2
|
- name: wazuh-indexer-2
|
||||||
dn: CN=node2,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
ip: wazuh-indexer-2
|
||||||
dns:
|
- name: wazuh-indexer-3
|
||||||
- elasticsearch-2
|
ip: wazuh-indexer-3
|
||||||
- name: node3
|
# Wazuh server nodes
|
||||||
dn: CN=node3,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
# Use node_type only with more than one Wazuh manager
|
||||||
dns:
|
#wazuh_servers:
|
||||||
- elasticsearch-3
|
- name: wazuh-master
|
||||||
- name: filebeat
|
ip: wazuh-master
|
||||||
dn: CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
#node_type: master
|
||||||
dns:
|
- name: wazuh-worker
|
||||||
- wazuh
|
ip: wazuh-worker
|
||||||
|
#node_type: worker
|
||||||
clients:
|
# Kibana node
|
||||||
- name: admin
|
#kibana:
|
||||||
dn: CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
- name: kibana
|
||||||
admin: true
|
ip: kibana
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
ca:
|
||||||
|
root:
|
||||||
|
dn: CN=root-ca,OU=CA,O=Example\, Inc.,DC=example,DC=com
|
||||||
|
pkPassword: none
|
||||||
|
keysize: 2048
|
||||||
|
file: root-ca.pem
|
||||||
|
intermediate:
|
||||||
|
dn: CN=intermediate,OU=CA,O=Example\, Inc.,DC=example,DC=com
|
||||||
|
keysize: 2048
|
||||||
|
validityDays: 3650
|
||||||
|
pkPassword: intermediate-ca-password
|
||||||
|
file: intermediate-ca.pem
|
||||||
|
|
||||||
|
nodes:
|
||||||
|
- name: wazuh-indexer
|
||||||
|
dn: CN=wazuh-indexer,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
||||||
|
dns:
|
||||||
|
- wazuh-indexer
|
||||||
|
- name: wazuh-indexer-2
|
||||||
|
dn: CN=wazuh-indexer-2,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
||||||
|
dns:
|
||||||
|
- wazuh-indexer-2
|
||||||
|
- name: wazuh-indexer-3
|
||||||
|
dn: CN=wazuh-indexer-3,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
||||||
|
dns:
|
||||||
|
- wazuh-indexer-3
|
||||||
|
- name: filebeat
|
||||||
|
dn: CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
||||||
|
dns:
|
||||||
|
- wazuh
|
||||||
|
|
||||||
|
clients:
|
||||||
|
- name: admin
|
||||||
|
dn: CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com
|
||||||
|
admin: true
|
||||||
@@ -7,7 +7,7 @@ ARG WAZUH_VERSION=4.3.0-1
|
|||||||
RUN apt-get update && apt install curl libcap2-bin -y
|
RUN apt-get update && apt install curl libcap2-bin -y
|
||||||
|
|
||||||
#Download and install Wazuh Dashboard
|
#Download and install Wazuh Dashboard
|
||||||
RUN curl https://s3.amazonaws.com/warehouse.wazuh.com/stack/dashboard/stable/wazuh-dashboard_${WAZUH_VERSION}_amd64.deb --output wazuh-dashboard_${WAZUH_VERSION}_amd64.deb && \
|
RUN curl https://s3.us-west-1.amazonaws.com/packages-dev.wazuh.com/pre-release/apt/pool/main/w/wazuh-dashboard/wazuh-dashboard_${WAZUH_VERSION}_amd64.deb --output wazuh-dashboard_${WAZUH_VERSION}_amd64.deb && \
|
||||||
dpkg -i wazuh-dashboard_${WAZUH_VERSION}_amd64.deb && \
|
dpkg -i wazuh-dashboard_${WAZUH_VERSION}_amd64.deb && \
|
||||||
apt-get clean -y && rm -rf wazuh-dashboard_${WAZUH_VERSION}_amd64.deb
|
apt-get clean -y && rm -rf wazuh-dashboard_${WAZUH_VERSION}_amd64.deb
|
||||||
|
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ USER root
|
|||||||
RUN yum install initscripts -y
|
RUN yum install initscripts -y
|
||||||
|
|
||||||
#Download and install Wazuh indexer
|
#Download and install Wazuh indexer
|
||||||
RUN curl https://s3.amazonaws.com/warehouse.wazuh.com/stack/indexer/stable/wazuh-indexer-${WAZUH_VERSION}.x86_64.rpm --output wazuh-indexer-${WAZUH_VERSION}.x86_64.rpm && \
|
RUN curl https://s3.us-west-1.amazonaws.com/packages-dev.wazuh.com/pre-release/yum/wazuh-indexer-${WAZUH_VERSION}.x86_64.rpm --output wazuh-indexer-${WAZUH_VERSION}.x86_64.rpm && \
|
||||||
rpm -i wazuh-indexer-${WAZUH_VERSION}.x86_64.rpm && \
|
rpm -i wazuh-indexer-${WAZUH_VERSION}.x86_64.rpm && \
|
||||||
yum clean all && rm -rf /var/cache/yum && rm -rf wazuh-indexer-${WAZUH_VERSION}.x86_64.rpm
|
yum clean all && rm -rf /var/cache/yum && rm -rf wazuh-indexer-${WAZUH_VERSION}.x86_64.rpm
|
||||||
|
|
||||||
|
|||||||
@@ -5,18 +5,37 @@
|
|||||||
# Start Wazuh indexer
|
# Start Wazuh indexer
|
||||||
##############################################################################
|
##############################################################################
|
||||||
|
|
||||||
rm -rf /var/lib/wazuh-indexer/*
|
|
||||||
|
|
||||||
service wazuh-indexer start
|
|
||||||
|
|
||||||
sleep 20
|
|
||||||
|
|
||||||
echo "inicio ver hostname"
|
service wazuh-indexer start
|
||||||
echo $HOSTNAME
|
sleep 5
|
||||||
echo "fin ver hostname"
|
service wazuh-indexer status
|
||||||
export OPENSEARCH_PATH_CONF=/etc/wazuh-indexer
|
sleep 5
|
||||||
export JAVA_HOME=/usr/share/wazuh-indexer/jdk
|
|
||||||
/usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh -cd /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig -icl -p 9800 -cd /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig -nhnv -cacert /etc/wazuh-indexer/certs/root-ca.pem -cert /etc/wazuh-indexer/certs/admin.pem -key /etc/wazuh-indexer/certs/admin-key.pem
|
if [ $NODE_TYPE == "worker" ]
|
||||||
|
then
|
||||||
|
echo "inicio ver node_type"
|
||||||
|
echo $NODE_TYPE
|
||||||
|
echo "fin ver node_type"
|
||||||
|
rm -rf /var/lib/wazuh-indexer/*
|
||||||
|
else
|
||||||
|
echo "inicio ver hostname"
|
||||||
|
echo $HOSTNAME
|
||||||
|
sleep 1
|
||||||
|
echo "fin ver hostname"
|
||||||
|
echo "inicio ver node_type"
|
||||||
|
echo $NODE_TYPE
|
||||||
|
sleep 1
|
||||||
|
echo "fin ver node_type"
|
||||||
|
export OPENSEARCH_PATH_CONF=/etc/wazuh-indexer
|
||||||
|
export JAVA_HOME=/usr/share/wazuh-indexer/jdk
|
||||||
|
/usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh -cd /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig -icl -p 9800 -cd /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig -nhnv -cacert /etc/wazuh-indexer/certs/root-ca.pem -cert /etc/wazuh-indexer/certs/admin.pem -key /etc/wazuh-indexer/certs/admin-key.pem
|
||||||
|
cat /var/log/wazuh-indexer/opensearch.log
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
#export JAVA_HOME=/usr/share/wazuh-indexer/jdk/ && bash /usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh -cd /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/ -nhnv -cacert /etc/wazuh-indexer/certs/root-ca.pem -cert /etc/wazuh-indexer/certs/admin.pem -key /etc/wazuh-indexer/certs/admin-key.pem -p 9800 -icl
|
#export JAVA_HOME=/usr/share/wazuh-indexer/jdk/ && bash /usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh -cd /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/ -nhnv -cacert /etc/wazuh-indexer/certs/root-ca.pem -cert /etc/wazuh-indexer/certs/admin.pem -key /etc/wazuh-indexer/certs/admin-key.pem -p 9800 -icl
|
||||||
|
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ FROM centos:7
|
|||||||
|
|
||||||
ARG FILEBEAT_CHANNEL=filebeat-oss
|
ARG FILEBEAT_CHANNEL=filebeat-oss
|
||||||
ARG FILEBEAT_VERSION=7.10.2
|
ARG FILEBEAT_VERSION=7.10.2
|
||||||
ARG WAZUH_VERSION=4.3.0-1
|
ARG WAZUH_VERSION=4.2.5-1
|
||||||
ARG TEMPLATE_VERSION="master"
|
ARG TEMPLATE_VERSION="master"
|
||||||
ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.1.tar.gz"
|
ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.1.tar.gz"
|
||||||
|
|
||||||
@@ -14,7 +14,7 @@ COPY config/wazuh.repo /etc/yum.repos.d/wazuh.repo
|
|||||||
|
|
||||||
RUN yum --enablerepo=updates clean metadata && \
|
RUN yum --enablerepo=updates clean metadata && \
|
||||||
yum upgrade -y && \
|
yum upgrade -y && \
|
||||||
yum -y install openssl which expect openssh-clients && yum -y install wazuh-manager-${WAZUH_VERSION} -y && \
|
yum -y install openssl which expect openssh-clients && yum install wazuh-manager-${WAZUH_VERSION} -y && \
|
||||||
sed -i "s/^enabled=1/enabled=0/" /etc/yum.repos.d/wazuh.repo && \
|
sed -i "s/^enabled=1/enabled=0/" /etc/yum.repos.d/wazuh.repo && \
|
||||||
yum clean all && rm -rf /var/cache/yum
|
yum clean all && rm -rf /var/cache/yum
|
||||||
|
|
||||||
@@ -40,7 +40,7 @@ ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/e
|
|||||||
RUN chmod go-w /etc/filebeat/wazuh-template.json
|
RUN chmod go-w /etc/filebeat/wazuh-template.json
|
||||||
|
|
||||||
COPY config/etc/ /etc/
|
COPY config/etc/ /etc/
|
||||||
COPY --chown=root:wazuh config/create_user.py /var/ossec/framework/scripts/create_user.py
|
COPY --chown=root:1000 config/create_user.py /var/ossec/framework/scripts/create_user.py
|
||||||
|
|
||||||
# Prepare permanent data
|
# Prepare permanent data
|
||||||
# Sync calls are due to https://github.com/docker/docker/issues/9547
|
# Sync calls are due to https://github.com/docker/docker/issues/9547
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ setup.template.json.name: 'wazuh'
|
|||||||
setup.template.overwrite: true
|
setup.template.overwrite: true
|
||||||
setup.ilm.enabled: false
|
setup.ilm.enabled: false
|
||||||
output.elasticsearch:
|
output.elasticsearch:
|
||||||
hosts: ['https://elasticsearch:9200']
|
hosts: ['https://elasticsearch:9700']
|
||||||
#username:
|
#username:
|
||||||
#password:
|
#password:
|
||||||
#ssl.verification_mode:
|
#ssl.verification_mode:
|
||||||
|
|||||||
Reference in New Issue
Block a user