From 8cdfca24cfd154e69ddee7eb3a3867b282d2750b Mon Sep 17 00:00:00 2001 From: Jean-Philippe Lachance Date: Thu, 3 Oct 2019 10:00:37 -0400 Subject: [PATCH 1/6] + Add a simple sed in the Wazuh manager configuration script to replace "to_be_replaced_by_hostname" by the hostname in ossec.conf --- wazuh/config/00-wazuh.sh | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/wazuh/config/00-wazuh.sh b/wazuh/config/00-wazuh.sh index 32fdd4f4..75573829 100644 --- a/wazuh/config/00-wazuh.sh +++ b/wazuh/config/00-wazuh.sh @@ -104,6 +104,17 @@ function ossec_shutdown(){ ${WAZUH_INSTALL_PATH}/bin/ossec-control stop; } +############################################################################## +# Allow users to set the container hostname as dynamically on +# container start. +# +# To use this: +# 1. Create your own ossec.conf file +# 2. In your ossec.conf file, set to_be_replaced_by_hostname as your node_name +# 3. Mount your custom ossec.conf file at $WAZUH_CONFIG_MOUNT/etc/ossec.conf +############################################################################## +sed -i 's/to_be_replaced_by_hostname<\/node_name>/'"${HOSTNAME}"'<\/node_name>/g' /var/ossec/etc/ossec.conf + # Trap exit signals and do a proper shutdown trap "ossec_shutdown; exit" SIGINT SIGTERM From 237f55d7e2aff41f2eafe070a0a0be9e684fb043 Mon Sep 17 00:00:00 2001 From: Jean-Philippe Lachance Date: Mon, 7 Oct 2019 11:03:40 -0400 Subject: [PATCH 2/6] * Apply Jose's code review --- wazuh/config/00-wazuh.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wazuh/config/00-wazuh.sh b/wazuh/config/00-wazuh.sh index 75573829..9d5614f9 100644 --- a/wazuh/config/00-wazuh.sh +++ b/wazuh/config/00-wazuh.sh @@ -113,7 +113,7 @@ function ossec_shutdown(){ # 2. In your ossec.conf file, set to_be_replaced_by_hostname as your node_name # 3. Mount your custom ossec.conf file at $WAZUH_CONFIG_MOUNT/etc/ossec.conf ############################################################################## -sed -i 's/to_be_replaced_by_hostname<\/node_name>/'"${HOSTNAME}"'<\/node_name>/g' /var/ossec/etc/ossec.conf +sed -i 's/to_be_replaced_by_hostname<\/node_name>/'"${HOSTNAME}"'<\/node_name>/g' ${WAZUH_INSTALL_PATH}/etc/ossec.conf # Trap exit signals and do a proper shutdown trap "ossec_shutdown; exit" SIGINT SIGTERM From 846ff81102e704c417273e6b76fe86bc9dbda29d Mon Sep 17 00:00:00 2001 From: manuasir Date: Wed, 13 Nov 2019 15:31:06 +0100 Subject: [PATCH 3/6] Updated Filebeat configuration file, fixes #266 --- wazuh/config/filebeat.yml | 60 +++++++-------------------------------- 1 file changed, 11 insertions(+), 49 deletions(-) diff --git a/wazuh/config/filebeat.yml b/wazuh/config/filebeat.yml index 628e4479..46600662 100644 --- a/wazuh/config/filebeat.yml +++ b/wazuh/config/filebeat.yml @@ -1,53 +1,15 @@ -# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -filebeat.inputs: - - type: log - paths: - - '/var/ossec/logs/alerts/alerts.json' +# Wazuh - Filebeat configuration file +filebeat.modules: + - module: wazuh + alerts: + enabled: true + archives: + enabled: false setup.template.json.enabled: true -setup.template.json.path: "/etc/filebeat/wazuh-template.json" -setup.template.json.name: "wazuh" +setup.template.json.path: '/etc/filebeat/wazuh-template.json' +setup.template.json.name: 'wazuh' setup.template.overwrite: true +setup.ilm.enabled: false -processors: - - decode_json_fields: - fields: ['message'] - process_array: true - max_depth: 200 - target: '' - overwrite_keys: true - - drop_fields: - fields: ['message', 'ecs', 'beat', 'input_type', 'tags', 'count', '@version', 'log', 'offset', 'type', 'host'] - - rename: - fields: - - from: "data.aws.sourceIPAddress" - to: "@src_ip" - ignore_missing: true - fail_on_error: false - when: - regexp: - data.aws.sourceIPAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b - - rename: - fields: - - from: "data.srcip" - to: "@src_ip" - ignore_missing: true - fail_on_error: false - when: - regexp: - data.srcip: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b - - rename: - fields: - - from: "data.win.eventdata.ipAddress" - to: "@src_ip" - ignore_missing: true - fail_on_error: false - when: - regexp: - data.win.eventdata.ipAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b - -output.elasticsearch: - hosts: ['http://elasticsearch:9200'] - #pipeline: geoip - indices: - - index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}' +output.elasticsearch.hosts: ['http://elasticsearch:9200'] \ No newline at end of file From afb1c1fba323f6de1e1b36693f1c1815a4ec7677 Mon Sep 17 00:00:00 2001 From: Jose M Date: Tue, 7 Jan 2020 14:55:52 +0100 Subject: [PATCH 4/6] Bump version to 3.11.1_7.5.1 --- VERSION | 4 ++-- docker-compose.yml | 8 ++++---- elasticsearch/Dockerfile | 2 +- kibana/Dockerfile | 2 +- wazuh/Dockerfile | 4 ++-- 5 files changed, 10 insertions(+), 10 deletions(-) diff --git a/VERSION b/VERSION index 407ab706..a6dcc8c8 100644 --- a/VERSION +++ b/VERSION @@ -1,2 +1,2 @@ -WAZUH-DOCKER_VERSION="3.11.0_7.5.1" -REVISION="31100" +WAZUH-DOCKER_VERSION="3.11.1_7.5.1" +REVISION="31110" diff --git a/docker-compose.yml b/docker-compose.yml index 5f6b23c8..0fb073a0 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -3,7 +3,7 @@ version: '2' services: wazuh: - image: wazuh/wazuh:3.11.0_7.5.1 + image: wazuh/wazuh:3.11.1_7.5.1 hostname: wazuh-manager restart: always ports: @@ -13,7 +13,7 @@ services: - "55000:55000" elasticsearch: - image: wazuh/wazuh-elasticsearch:3.11.0_7.5.1 + image: wazuh/wazuh-elasticsearch:3.11.1_7.5.1 hostname: elasticsearch restart: always ports: @@ -30,7 +30,7 @@ services: mem_limit: 2g kibana: - image: wazuh/wazuh-kibana:3.11.0_7.5.1 + image: wazuh/wazuh-kibana:3.11.1_7.5.1 hostname: kibana restart: always depends_on: @@ -39,7 +39,7 @@ services: - elasticsearch:elasticsearch - wazuh:wazuh nginx: - image: wazuh/wazuh-nginx:3.11.0_7.5.1 + image: wazuh/wazuh-nginx:3.11.1_7.5.1 hostname: nginx restart: always environment: diff --git a/elasticsearch/Dockerfile b/elasticsearch/Dockerfile index ede61fbc..66a00475 100644 --- a/elasticsearch/Dockerfile +++ b/elasticsearch/Dockerfile @@ -15,7 +15,7 @@ ENV XPACK_ML="true" ENV ENABLE_CONFIGURE_S3="false" -ARG TEMPLATE_VERSION=v3.11.0 +ARG TEMPLATE_VERSION=v3.11.1 # Elasticearch cluster configuration environment variables # If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration diff --git a/kibana/Dockerfile b/kibana/Dockerfile index 3bfad3de..79715c91 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -2,7 +2,7 @@ FROM docker.elastic.co/kibana/kibana:7.5.1 USER kibana ARG ELASTIC_VERSION=7.5.1 -ARG WAZUH_VERSION=3.11.0 +ARG WAZUH_VERSION=3.11.1 ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}" #ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /usr/share/kibana/ diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index 4dc7b238..9a8748cf 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -3,12 +3,12 @@ FROM phusion/baseimage:latest ARG FILEBEAT_VERSION=7.5.1 -ARG WAZUH_VERSION=3.11.0-1 +ARG WAZUH_VERSION=3.11.1-1 ENV API_USER="foo" \ API_PASS="bar" -ARG TEMPLATE_VERSION="v3.11.0" +ARG TEMPLATE_VERSION="v3.11.1" # Set repositories. RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list && \ From bba5b90716bfe6ae94a51ef5879e5ba7f602179b Mon Sep 17 00:00:00 2001 From: Jose M Date: Tue, 7 Jan 2020 14:56:04 +0100 Subject: [PATCH 5/6] Update CHANGELOG.md --- CHANGELOG.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 19b71325..f3eba0b0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,12 @@ # Change Log All notable changes to this project will be documented in this file. +## Wazuh Docker v3.11.1_7.5.1 + +### Added + +- Update to Wazuh version 3.11.1_7.5.1 + ## Wazuh Docker v3.11.0_7.5.1 ### Added From 95cb2fa3aafef33913a78bf4423f86609b6bf8ed Mon Sep 17 00:00:00 2001 From: Jose M Date: Tue, 7 Jan 2020 15:11:08 +0100 Subject: [PATCH 6/6] Update CHANGELOG.md --- CHANGELOG.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f3eba0b0..27506a28 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,14 +6,14 @@ All notable changes to this project will be documented in this file. ### Added - Update to Wazuh version 3.11.1_7.5.1 +- Filebeat configuration file updated to latest version ([@manuasir](https://github.com/manuasir)) [#271](https://github.com/wazuh/wazuh-docker/pull/271) +- Allow using the hostname as node_name for managers ([@JPLachance](https://github.com/JPLachance)) [#261](https://github.com/wazuh/wazuh-docker/pull/261) ## Wazuh Docker v3.11.0_7.5.1 ### Added - Update to Wazuh version 3.11.0_7.5.1 -- Filebeat configuration file updated to latest version ([@manuasir](https://github.com/manuasir)) [#271](https://github.com/wazuh/wazuh-docker/pull/271) -- Allow using the hostname as node_name for managers ([@JPLachance](https://github.com/JPLachance)) [#261](https://github.com/wazuh/wazuh-docker/pull/261) ## Wazuh Docker v3.10.2_7.5.0