diff --git a/CHANGELOG.md b/CHANGELOG.md index 003c533b..c5972578 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,13 @@ # Change Log All notable changes to this project will be documented in this file. +## Wazuh Docker v3.9.1_7.1.0 + +### Added + +- Support for Elastic v7.1.0 +- New environment variables for Kibana ([@manuasir](https://github.com/manuasir)) [#22ad43](https://github.com/wazuh/wazuh-docker/commit/22ad4360f548e54bb0c5e929f8c84a186ad2ab88) + ## Wazuh Docker v3.9.1_6.8.0 ### Added diff --git a/README.md b/README.md index 030754ef..173b7eb5 100644 --- a/README.md +++ b/README.md @@ -8,7 +8,6 @@ In this repository you will find the containers to run: * wazuh: It runs the Wazuh manager, Wazuh API and Filebeat (for integration with Elastic Stack) -* wazuh-logstash: It is used to receive alerts generated by the manager and feed Elasticsearch using an alerts template * wazuh-kibana: Provides a web user interface to browse through alerts data. It includes Wazuh plugin for Kibana, that allows you to visualize agents configuration and status. * wazuh-nginx: Proxies the Kibana container, adding HTTPS (via self-signed SSL certificate) and [Basic authentication](https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#Basic_authentication_scheme). * wazuh-elasticsearch: An Elasticsearch container (working as a single-node cluster) using Elastic Stack Docker images. **Be aware to increase the `vm.max_map_count` setting, as it's detailed in the [Wazuh documentation](https://documentation.wazuh.com/current/docker/wazuh-container.html#increase-max-map-count-on-your-host-linux).** @@ -33,11 +32,6 @@ In addition, a docker-compose file is provided to launch the containers mentione │   │   └── kibana.yml │   └── Dockerfile ├── LICENSE - ├── logstash - │   ├── config - │   │   ├── 01-wazuh.conf - │   │   └── run.sh - │   └── Dockerfile ├── nginx │   ├── config │   │   └── entrypoint.sh @@ -76,7 +70,7 @@ We thank you them and everyone else who has contributed to this project. ## License and copyright -Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) ## Web references diff --git a/VERSION b/VERSION index 3e8fc28f..92cf5618 100644 --- a/VERSION +++ b/VERSION @@ -1,2 +1,2 @@ -WAZUH-DOCKER_VERSION="3.9.1_6.8.0" -REVISION="3901" \ No newline at end of file +WAZUH-DOCKER_VERSION="3.9.1_7.1.0" +REVISION="3911" \ No newline at end of file diff --git a/docker-compose.yml b/docker-compose.yml index 8c43d7a7..d0a5692c 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,49 +1,36 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) version: '2' services: wazuh: - image: wazuh/wazuh:3.9.1_6.8.0 + build: wazuh hostname: wazuh-manager restart: always ports: - - "1514:1514/udp" - - "1515:1515" - - "514:514/udp" - - "55000:55000" - depends_on: - - logstash - logstash: - image: wazuh/wazuh-logstash:3.9.1_6.8.0 - hostname: logstash - restart: always - links: - - elasticsearch:elasticsearch - ports: - - "5000:5000" - depends_on: - - elasticsearch - environment: - - LS_HEAP_SIZE=2048m + - '1514:1514/udp' + - '1515:1515' + - '514:514/udp' + - '55000:55000' elasticsearch: - image: wazuh/wazuh-elasticsearch:3.9.1_6.8.0 + build: elasticsearch hostname: elasticsearch restart: always ports: - - "9200:9200" + - '9200:9200' environment: - node.name=node-1 - cluster.name=wazuh - - network.host=0.0.0.0 + - network.host=localhost + - discovery.type=single-node - bootstrap.memory_lock=true - - "ES_JAVA_OPTS=-Xms1g -Xmx1g" + - 'ES_JAVA_OPTS=-Xms1g -Xmx1g' ulimits: memlock: soft: -1 hard: -1 mem_limit: 2g kibana: - image: wazuh/wazuh-kibana:3.9.1_6.8.0 + build: kibana hostname: kibana restart: always depends_on: @@ -52,15 +39,15 @@ services: - elasticsearch:elasticsearch - wazuh:wazuh nginx: - image: wazuh/wazuh-nginx:3.9.1_6.8.0 + build: nginx hostname: nginx restart: always environment: - NGINX_PORT=443 - NGINX_CREDENTIALS ports: - - "80:80" - - "443:443" + - '80:80' + - '443:443' depends_on: - kibana links: diff --git a/elasticsearch/Dockerfile b/elasticsearch/Dockerfile index 10ecaea3..93238c65 100644 --- a/elasticsearch/Dockerfile +++ b/elasticsearch/Dockerfile @@ -1,5 +1,5 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/elasticsearch/elasticsearch:6.8.0 +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) +FROM docker.elastic.co/elasticsearch/elasticsearch:7.1.0 ENV ELASTICSEARCH_URL="http://elasticsearch:9200" @@ -17,6 +17,7 @@ ENV TEMPLATE_VERSION=v3.9.1 # Elasticearch cluster configuration environment variables # If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration +# CLUSTER_INITIAL_MASTER_NODES set to own node by default. ENV ELASTIC_CLUSTER="false" \ CLUSTER_NAME="wazuh" \ CLUSTER_NODE_MASTER="true" \ @@ -27,11 +28,12 @@ ENV ELASTIC_CLUSTER="false" \ CLUSTER_DISCOVERY_SERVICE="wazuh-elasticsearch" \ CLUSTER_NUMBER_OF_MASTERS="2" \ CLUSTER_MAX_NODES="1" \ - CLUSTER_DELAYED_TIMEOUT="1m" + CLUSTER_DELAYED_TIMEOUT="1m" \ + CLUSTER_INITIAL_MASTER_NODES="wazuh-elasticsearch" -ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/6.x/wazuh-template.json /usr/share/elasticsearch/config +ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /usr/share/elasticsearch/config -COPY config/entrypoint.sh /entrypoint.sh +COPY config/entrypoint.sh /entrypoint.sh RUN chmod 755 /entrypoint.sh @@ -39,7 +41,7 @@ COPY --chown=elasticsearch:elasticsearch ./config/load_settings.sh ./ RUN chmod +x ./load_settings.sh -RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-6.8.0.zip +RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-7.1.0.zip COPY config/configure_s3.sh ./config/configure_s3.sh RUN chmod 755 ./config/configure_s3.sh diff --git a/elasticsearch/config/config_cluster.sh b/elasticsearch/config/config_cluster.sh index b4063825..2222099e 100644 --- a/elasticsearch/config/config_cluster.sh +++ b/elasticsearch/config/config_cluster.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) elastic_config_file="/usr/share/elasticsearch/config/elasticsearch.yml" @@ -10,7 +10,7 @@ then # Set the cluster.name and discovery.zen.minimun_master_nodes variables sed -i 's:cluster.name\: "docker-cluster":cluster.name\: "'$CLUSTER_NAME'":g' $elastic_config_file - sed -i 's:discovery.zen.minimum_master_nodes\: 1:discovery.zen.minimum_master_nodes\: '$CLUSTER_NUMBER_OF_MASTERS':g' $elastic_config_file + #sed -i 's:discovery.zen.minimum_master_nodes\: 1:discovery.zen.minimum_master_nodes\: '$CLUSTER_NUMBER_OF_MASTERS':g' $elastic_config_file # Add the cluster configuration echo " @@ -23,11 +23,19 @@ node: max_local_storage_nodes: ${CLUSTER_MAX_NODES} bootstrap: - memory_lock: ${CLUSTER_MEMORY_LOCK} + memory_lock: ${CLUSTER_MEMORY_LOCK} + +cluster.initial_master_nodes: + - '${CLUSTER_INITIAL_MASTER_NODES}' -discovery: - zen: - ping.unicast.hosts: ${CLUSTER_DISCOVERY_SERVICE} - " >> $elastic_config_file +else + +cat >> $elastic_config_file <<'EOF' +cluster.initial_master_nodes: + - 'elasticsearch' +EOF + +# echo 'discovery.type: single-node' + fi diff --git a/elasticsearch/config/configure_s3.sh b/elasticsearch/config/configure_s3.sh index 49c88a25..5d4e3901 100644 --- a/elasticsearch/config/configure_s3.sh +++ b/elasticsearch/config/configure_s3.sh @@ -1,4 +1,5 @@ #!/bin/bash +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) set -e diff --git a/elasticsearch/config/entrypoint.sh b/elasticsearch/config/entrypoint.sh index 9c799812..5b42adb7 100644 --- a/elasticsearch/config/entrypoint.sh +++ b/elasticsearch/config/entrypoint.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) # For more information https://github.com/elastic/elasticsearch-docker/blob/6.8.0/build/elasticsearch/bin/docker-entrypoint.sh diff --git a/elasticsearch/config/load_settings.sh b/elasticsearch/config/load_settings.sh index 23fabd6c..65f90a76 100644 --- a/elasticsearch/config/load_settings.sh +++ b/elasticsearch/config/load_settings.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) set -e @@ -11,7 +11,7 @@ else wazuh_url="${WAZUH_API_URL}" fi -if [ ${ENABLED_XPACK} != "true" || "x${ELASTICSEARCH_USERNAME}" = "x" || "x${ELASTICSEARCH_PASSWORD}" = "x" ]; then +if [[ ${ENABLED_XPACK} != "true" || "x${ELASTICSEARCH_USERNAME}" = "x" || "x${ELASTICSEARCH_PASSWORD}" = "x" ]]; then auth="" else auth="--user ${ELASTICSEARCH_USERNAME}:${ELASTICSEARCH_PASSWORD}" @@ -45,20 +45,15 @@ fi #Insert default templates -sed -i 's| "index.refresh_interval": "5s"| "index.refresh_interval": "5s", "number_of_shards" : '"${ALERTS_SHARDS}"', "number_of_replicas" : '"${ALERTS_REPLICAS}"'|' /usr/share/elasticsearch/config/wazuh-template.json - -cat /usr/share/elasticsearch/config/wazuh-template.json | curl -XPUT "$el_url/_template/wazuh" ${auth} -H 'Content-Type: application/json' -d @- -sleep 5 - - API_PASS_Q=`echo "$API_PASS" | tr -d '"'` API_USER_Q=`echo "$API_USER" | tr -d '"'` API_PASSWORD=`echo -n $API_PASS_Q | base64` echo "Setting API credentials into Wazuh APP" -CONFIG_CODE=$(curl -s -o /dev/null -w "%{http_code}" -XGET $el_url/.wazuh/wazuh-configuration/1513629884013 ${auth}) -if [ "x$CONFIG_CODE" = "x404" ]; then - curl -s -XPOST $el_url/.wazuh/wazuh-configuration/1513629884013 ${auth} -H 'Content-Type: application/json' -d' +CONFIG_CODE=$(curl -s -o /dev/null -w "%{http_code}" -XGET $el_url/.wazuh/_doc/1513629884013 ${auth}) + +if [ "x$CONFIG_CODE" != "x200" ]; then + curl -s -XPOST $el_url/.wazuh/_doc/1513629884013 ${auth} -H 'Content-Type: application/json' -d' { "api_user": "'"$API_USER_Q"'", "api_password": "'"$API_PASSWORD"'", diff --git a/kibana/Dockerfile b/kibana/Dockerfile index 7d59926d..a5e42fd5 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -1,13 +1,12 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/kibana/kibana:6.8.0 -ARG WAZUH_APP_VERSION=3.9.1_6.8.0 +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) +FROM docker.elastic.co/kibana/kibana:7.1.0 +ARG WAZUH_APP_VERSION=3.9.1_7.1.0 USER root -ADD https://packages-dev.wazuh.com/pre-release/app/kibana/wazuhapp-3.9.1_6.8.0.zip /tmp +ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp -RUN NODE_OPTIONS="--max-old-space-size=3072" /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-3.9.1_6.8.0.zip &&\ - chown -R kibana:kibana /usr/share/kibana &&\ - rm -rf /tmp/* +RUN /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip +RUN rm -rf /tmp/wazuhapp-${WAZUH_APP_VERSION}.zip COPY config/entrypoint.sh ./entrypoint.sh RUN chmod 755 ./entrypoint.sh diff --git a/kibana/config/entrypoint.sh b/kibana/config/entrypoint.sh index f171374f..80cf73cd 100644 --- a/kibana/config/entrypoint.sh +++ b/kibana/config/entrypoint.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) set -e diff --git a/kibana/config/kibana_settings.sh b/kibana/config/kibana_settings.sh index 96e5f35b..1982e352 100644 --- a/kibana/config/kibana_settings.sh +++ b/kibana/config/kibana_settings.sh @@ -1,6 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) - +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) WAZUH_MAJOR=3 @@ -19,8 +18,24 @@ WAZUH_MAJOR=3 # Customize elasticsearch ip ############################################################################## if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then + sed -i "s:#elasticsearch.hosts:elasticsearch.hosts:g" /usr/share/kibana/config/kibana.yml sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_KIBANA_IP'|g' /usr/share/kibana/config/kibana.yml +fi +# If KIBANA_INDEX was set, then change the default index in kibana.yml configuration file. If there was an index, then delete it and recreate. +if [ "$KIBANA_INDEX" != "" ]; then + if grep -q 'kibana.index' /usr/share/kibana/config/kibana.yml; then + sed -i '/kibana.index/d' /usr/share/kibana/config/kibana.yml + fi + echo "kibana.index: $KIBANA_INDEX" >> /usr/share/kibana/config/kibana.yml +fi + +# If XPACK_SECURITY_ENABLED was set, then change the xpack.security.enabled option from true (default) to false. +if [ "$XPACK_SECURITY_ENABLED" != "" ]; then + if grep -q 'xpack.security.enabled' /usr/share/kibana/config/kibana.yml; then + sed -i '/xpack.security.enabled/d' /usr/share/kibana/config/kibana.yml + fi + echo "xpack.security.enabled: $XPACK_SECURITY_ENABLED" >> /usr/share/kibana/config/kibana.yml fi if [ "$KIBANA_IP" != "" ]; then diff --git a/kibana/config/wazuh_app_config.sh b/kibana/config/wazuh_app_config.sh index 6fffd005..5f238325 100644 --- a/kibana/config/wazuh_app_config.sh +++ b/kibana/config/wazuh_app_config.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) kibana_config_file="/usr/share/kibana/plugins/wazuh/config.yml" diff --git a/kibana/config/welcome_wazuh.sh b/kibana/config/welcome_wazuh.sh index 0925d57a..fb90b949 100644 --- a/kibana/config/welcome_wazuh.sh +++ b/kibana/config/welcome_wazuh.sh @@ -1,4 +1,5 @@ #!/bin/bash +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) if [[ $CHANGE_WELCOME == "true" ]] then diff --git a/kibana/config/xpack_config.sh b/kibana/config/xpack_config.sh index 0dbd5ce8..0713dcb8 100644 --- a/kibana/config/xpack_config.sh +++ b/kibana/config/xpack_config.sh @@ -1,4 +1,5 @@ #!/bin/bash +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) kibana_config_file="/usr/share/kibana/config/kibana.yml" if grep -Fq "#xpack features" "$kibana_config_file"; diff --git a/logstash/Dockerfile b/logstash/Dockerfile deleted file mode 100644 index 404b7b9d..00000000 --- a/logstash/Dockerfile +++ /dev/null @@ -1,12 +0,0 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/logstash/logstash:6.8.0 - -COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh - -RUN chmod 755 /entrypoint.sh - -RUN rm -f /usr/share/logstash/pipeline/logstash.conf - -COPY config/01-wazuh.conf /usr/share/logstash/pipeline/01-wazuh.conf - -ENTRYPOINT /entrypoint.sh diff --git a/logstash/config/01-wazuh.conf b/logstash/config/01-wazuh.conf deleted file mode 100644 index 791cfd3f..00000000 --- a/logstash/config/01-wazuh.conf +++ /dev/null @@ -1,45 +0,0 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# Wazuh - Logstash configuration file -## Remote Wazuh Manager - Filebeat input -input { - beats { - port => 5000 - codec => "json_lines" -# ssl => true -# ssl_certificate => "/etc/logstash/logstash.crt" -# ssl_key => "/etc/logstash/logstash.key" - } -} -filter { - if [data][srcip] { - mutate { - add_field => [ "@src_ip", "%{[data][srcip]}" ] - } - } - if [data][aws][sourceIPAddress] { - mutate { - add_field => [ "@src_ip", "%{[data][aws][sourceIPAddress]}" ] - } - } -} -filter { - geoip { - source => "@src_ip" - target => "GeoLocation" - fields => ["city_name", "country_name", "region_name", "location"] - } - date { - match => ["timestamp", "ISO8601"] - target => "@timestamp" - } - mutate { - remove_field => [ "timestamp", "beat", "input_type", "tags", "count", "@version", "log", "offset", "type", "@src_ip", "host"] - } -} -output { - elasticsearch { - hosts => ["elasticsearch:9200"] - index => "wazuh-alerts-3.x-%{+YYYY.MM.dd}" - document_type => "wazuh" - } -} diff --git a/logstash/config/entrypoint.sh b/logstash/config/entrypoint.sh deleted file mode 100644 index 4aaff056..00000000 --- a/logstash/config/entrypoint.sh +++ /dev/null @@ -1,72 +0,0 @@ -#!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# -# OSSEC container bootstrap. See the README for information of the environment -# variables expected by this script. -# - -set -e - -############################################################################## -# Waiting for elasticsearch -############################################################################## - -if [ "x${ELASTICSEARCH_URL}" = "x" ]; then - el_url="http://elasticsearch:9200" -else - el_url="${ELASTICSEARCH_URL}" -fi - -############################################################################## -# Customize logstash output ip -############################################################################## - -if [ "$LOGSTASH_OUTPUT" != "" ]; then - >&2 echo "Customize Logstash ouput ip." - sed -i 's|elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/pipeline/01-wazuh.conf - sed -i 's|http://elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/config/logstash.yml -fi - -until curl -XGET $el_url; do - >&2 echo "Elastic is unavailable - sleeping." - sleep 5 -done - -sleep 2 - ->&2 echo "Elasticsearch is up." - -############################################################################## -# Waiting for wazuh alerts template -############################################################################## - -strlen=0 - -while [[ $strlen -eq 0 ]] -do - template=$(curl $el_url/_cat/templates/wazuh -s) - strlen=${#template} - >&2 echo "Wazuh alerts template not loaded - sleeping." - sleep 2 -done - -sleep 2 - ->&2 echo "Wazuh alerts template is loaded." - -############################################################################## -# Map environment variables to entries in logstash.yml. -# Note that this will mutate logstash.yml in place if any such settings are found. -# This may be undesirable, especially if logstash.yml is bind-mounted from the -# host system. -############################################################################## - -env2yaml /usr/share/logstash/config/logstash.yml - -export LS_JAVA_OPTS="-Dls.cgroup.cpuacct.path.override=/ -Dls.cgroup.cpu.path.override=/ $LS_JAVA_OPTS" - -if [[ -z $1 ]] || [[ ${1:0:1} == '-' ]] ; then - exec logstash "$@" -else - exec "$@" -fi diff --git a/nginx/Dockerfile b/nginx/Dockerfile index 9ed0950e..2ca20d6f 100644 --- a/nginx/Dockerfile +++ b/nginx/Dockerfile @@ -1,4 +1,4 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) FROM nginx:latest ENV DEBIAN_FRONTEND noninteractive diff --git a/nginx/config/entrypoint.sh b/nginx/config/entrypoint.sh index 385d7aa8..468c8a92 100644 --- a/nginx/config/entrypoint.sh +++ b/nginx/config/entrypoint.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) set -e diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index e5016dd1..9f822892 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -1,10 +1,12 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) FROM phusion/baseimage:latest -ARG FILEBEAT_VERSION=6.8.0 +ARG FILEBEAT_VERSION=7.1.0 ARG WAZUH_VERSION=3.9.1-1 ENV API_USER="foo" \ - API_PASS="bar" + API_PASS="bar" + +ENV TEMPLATE_VERSION="v3.9.1" # Set repositories. RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list && \ @@ -31,12 +33,12 @@ COPY config/00-wazuh.sh /entrypoint-scripts/00-wazuh.sh # Sync calls are due to https://github.com/docker/docker/issues/9547 RUN chmod 755 /init.bash && \ - sync && /init.bash && \ - sync && rm /init.bash && \ - curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-${FILEBEAT_VERSION}-amd64.deb &&\ - dpkg -i filebeat-${FILEBEAT_VERSION}-amd64.deb && rm -f filebeat-${FILEBEAT_VERSION}-amd64.deb && \ - chmod 755 /entrypoint.sh && \ - chmod 755 /entrypoint-scripts/00-wazuh.sh + sync && /init.bash && \ + sync && rm /init.bash && \ + curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-${FILEBEAT_VERSION}-amd64.deb &&\ + dpkg -i filebeat-${FILEBEAT_VERSION}-amd64.deb && rm -f filebeat-${FILEBEAT_VERSION}-amd64.deb && \ + chmod 755 /entrypoint.sh && \ + chmod 755 /entrypoint-scripts/00-wazuh.sh COPY config/filebeat.yml /etc/filebeat/ RUN chmod go-w /etc/filebeat/filebeat.yml @@ -52,9 +54,9 @@ EXPOSE 55000/tcp 1514/udp 1515/tcp 514/udp 1516/tcp # Adding services RUN mkdir /etc/service/wazuh && \ - mkdir /etc/service/wazuh-api && \ - mkdir /etc/service/postfix && \ - mkdir /etc/service/filebeat + mkdir /etc/service/wazuh-api && \ + mkdir /etc/service/postfix && \ + mkdir /etc/service/filebeat COPY config/wazuh.runit.service /etc/service/wazuh/run COPY config/wazuh-api.runit.service /etc/service/wazuh-api/run @@ -62,9 +64,13 @@ COPY config/postfix.runit.service /etc/service/postfix/run COPY config/filebeat.runit.service /etc/service/filebeat/run RUN chmod +x /etc/service/wazuh-api/run && \ - chmod +x /etc/service/wazuh/run && \ - chmod +x /etc/service/postfix/run && \ - chmod +x /etc/service/filebeat/run + chmod +x /etc/service/wazuh/run && \ + chmod +x /etc/service/postfix/run && \ + chmod +x /etc/service/filebeat/run + + +ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat +RUN chmod go-w /etc/filebeat/wazuh-template.json # Run all services ENTRYPOINT ["/entrypoint.sh"] diff --git a/wazuh/config/00-wazuh.sh b/wazuh/config/00-wazuh.sh index 5935f8cb..32fdd4f4 100644 --- a/wazuh/config/00-wazuh.sh +++ b/wazuh/config/00-wazuh.sh @@ -1,17 +1,10 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# -# OSSEC container bootstrap. See the README for information of the environment +# Wazuh container bootstrap. See the README for information of the environment # variables expected by this script. -# -# - -# # Startup the services -# - source /data_dirs.env FIRST_TIME_INSTALLATION=false @@ -139,13 +132,4 @@ echo "Change Wazuh API user credentials" change_user="node htpasswd -b -c user $API_USER $API_PASS" eval $change_user -popd - - -############################################################################## -# Customize filebeat output ip -############################################################################## -if [ "$FILEBEAT_OUTPUT" != "" ]; then - sed -i "s/logstash:5000/$FILEBEAT_OUTPUT:5000/" /etc/filebeat/filebeat.yml -fi - +popd \ No newline at end of file diff --git a/wazuh/config/entrypoint.sh b/wazuh/config/entrypoint.sh index bc07ae4a..d8ae1163 100644 --- a/wazuh/config/entrypoint.sh +++ b/wazuh/config/entrypoint.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) # It will run every .sh script located in entrypoint-scripts folder in lexicographical order for script in `ls /entrypoint-scripts/*.sh | sort -n`; do diff --git a/wazuh/config/filebeat.runit.service b/wazuh/config/filebeat.runit.service index 2a46f7b0..9b048caa 100644 --- a/wazuh/config/filebeat.runit.service +++ b/wazuh/config/filebeat.runit.service @@ -1,3 +1,4 @@ #!/bin/sh +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service filebeat start tail -f /var/log/filebeat/filebeat diff --git a/wazuh/config/filebeat.yml b/wazuh/config/filebeat.yml index bb02a5d8..628e4479 100644 --- a/wazuh/config/filebeat.yml +++ b/wazuh/config/filebeat.yml @@ -1,18 +1,53 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -filebeat: - prospectors: +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) +filebeat.inputs: - type: log paths: - - "/var/ossec/logs/alerts/alerts.json" - document_type: json - json.message_key: log - json.keys_under_root: true - json.overwrite_keys: true - tail_files: true + - '/var/ossec/logs/alerts/alerts.json' -output: - logstash: - # The Logstash hosts - hosts: ["logstash:5000"] -# ssl: -# certificate_authorities: ["/etc/filebeat/logstash.crt"] +setup.template.json.enabled: true +setup.template.json.path: "/etc/filebeat/wazuh-template.json" +setup.template.json.name: "wazuh" +setup.template.overwrite: true + +processors: + - decode_json_fields: + fields: ['message'] + process_array: true + max_depth: 200 + target: '' + overwrite_keys: true + - drop_fields: + fields: ['message', 'ecs', 'beat', 'input_type', 'tags', 'count', '@version', 'log', 'offset', 'type', 'host'] + - rename: + fields: + - from: "data.aws.sourceIPAddress" + to: "@src_ip" + ignore_missing: true + fail_on_error: false + when: + regexp: + data.aws.sourceIPAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b + - rename: + fields: + - from: "data.srcip" + to: "@src_ip" + ignore_missing: true + fail_on_error: false + when: + regexp: + data.srcip: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b + - rename: + fields: + - from: "data.win.eventdata.ipAddress" + to: "@src_ip" + ignore_missing: true + fail_on_error: false + when: + regexp: + data.win.eventdata.ipAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b + +output.elasticsearch: + hosts: ['http://elasticsearch:9200'] + #pipeline: geoip + indices: + - index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}' diff --git a/wazuh/config/init.bash b/wazuh/config/init.bash index cfff523d..e40fab94 100644 --- a/wazuh/config/init.bash +++ b/wazuh/config/init.bash @@ -1,9 +1,7 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# # Initialize the custom data directory layout -# source /data_dirs.env cd /var/ossec diff --git a/wazuh/config/postfix.runit.service b/wazuh/config/postfix.runit.service index 02856a35..e900b5e5 100644 --- a/wazuh/config/postfix.runit.service +++ b/wazuh/config/postfix.runit.service @@ -1,3 +1,4 @@ #!/bin/sh +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service postfix start tail -f /var/log/mail.log diff --git a/wazuh/config/wazuh-api.runit.service b/wazuh/config/wazuh-api.runit.service index e24b8f8d..198fa4a1 100644 --- a/wazuh/config/wazuh-api.runit.service +++ b/wazuh/config/wazuh-api.runit.service @@ -1,4 +1,5 @@ #!/bin/sh +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service wazuh-api start tail -f /var/ossec/data/logs/api.log diff --git a/wazuh/config/wazuh.runit.service b/wazuh/config/wazuh.runit.service index 28a2a5b0..7ab6f1e1 100644 --- a/wazuh/config/wazuh.runit.service +++ b/wazuh/config/wazuh.runit.service @@ -1,4 +1,5 @@ #!/bin/sh +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service wazuh-manager start tail -f /var/ossec/data/logs/ossec.log