From f63d9fa387c07cede948a900d3d936ec9d6bc4b0 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Fri, 10 May 2019 22:24:41 +0200 Subject: [PATCH 01/20] Include protocol and port in LOGSTASH_OUTPUT environment variable (#164) * Including protocol and port in the LOGSTASH_OUTPUT env var. --- logstash/config/entrypoint.sh | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/logstash/config/entrypoint.sh b/logstash/config/entrypoint.sh index 88c3d169..4aaff056 100644 --- a/logstash/config/entrypoint.sh +++ b/logstash/config/entrypoint.sh @@ -17,6 +17,16 @@ else el_url="${ELASTICSEARCH_URL}" fi +############################################################################## +# Customize logstash output ip +############################################################################## + +if [ "$LOGSTASH_OUTPUT" != "" ]; then + >&2 echo "Customize Logstash ouput ip." + sed -i 's|elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/pipeline/01-wazuh.conf + sed -i 's|http://elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/config/logstash.yml +fi + until curl -XGET $el_url; do >&2 echo "Elastic is unavailable - sleeping." sleep 5 @@ -44,16 +54,6 @@ sleep 2 >&2 echo "Wazuh alerts template is loaded." -############################################################################## -# Customize logstash output ip -############################################################################## - -if [ "$LOGSTASH_OUTPUT" != "" ]; then - >&2 echo "Customize Logstash ouput ip." - sed -i "s/elasticsearch:9200/$LOGSTASH_OUTPUT:9200/" /usr/share/logstash/pipeline/01-wazuh.conf - sed -i "s/elasticsearch:9200/$LOGSTASH_OUTPUT:9200/" /usr/share/logstash/config/logstash.yml -fi - ############################################################################## # Map environment variables to entries in logstash.yml. # Note that this will mutate logstash.yml in place if any such settings are found. From e954a6486a43cc63989a0c99f0b484f403fbfcc5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 14:56:50 +0200 Subject: [PATCH 02/20] Removed Logstash --- logstash/Dockerfile | 12 ------ logstash/config/01-wazuh.conf | 45 ---------------------- logstash/config/entrypoint.sh | 72 ----------------------------------- 3 files changed, 129 deletions(-) delete mode 100644 logstash/Dockerfile delete mode 100644 logstash/config/01-wazuh.conf delete mode 100644 logstash/config/entrypoint.sh diff --git a/logstash/Dockerfile b/logstash/Dockerfile deleted file mode 100644 index 1aa79f50..00000000 --- a/logstash/Dockerfile +++ /dev/null @@ -1,12 +0,0 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/logstash/logstash:6.7.2 - -COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh - -RUN chmod 755 /entrypoint.sh - -RUN rm -f /usr/share/logstash/pipeline/logstash.conf - -COPY config/01-wazuh.conf /usr/share/logstash/pipeline/01-wazuh.conf - -ENTRYPOINT /entrypoint.sh diff --git a/logstash/config/01-wazuh.conf b/logstash/config/01-wazuh.conf deleted file mode 100644 index 791cfd3f..00000000 --- a/logstash/config/01-wazuh.conf +++ /dev/null @@ -1,45 +0,0 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# Wazuh - Logstash configuration file -## Remote Wazuh Manager - Filebeat input -input { - beats { - port => 5000 - codec => "json_lines" -# ssl => true -# ssl_certificate => "/etc/logstash/logstash.crt" -# ssl_key => "/etc/logstash/logstash.key" - } -} -filter { - if [data][srcip] { - mutate { - add_field => [ "@src_ip", "%{[data][srcip]}" ] - } - } - if [data][aws][sourceIPAddress] { - mutate { - add_field => [ "@src_ip", "%{[data][aws][sourceIPAddress]}" ] - } - } -} -filter { - geoip { - source => "@src_ip" - target => "GeoLocation" - fields => ["city_name", "country_name", "region_name", "location"] - } - date { - match => ["timestamp", "ISO8601"] - target => "@timestamp" - } - mutate { - remove_field => [ "timestamp", "beat", "input_type", "tags", "count", "@version", "log", "offset", "type", "@src_ip", "host"] - } -} -output { - elasticsearch { - hosts => ["elasticsearch:9200"] - index => "wazuh-alerts-3.x-%{+YYYY.MM.dd}" - document_type => "wazuh" - } -} diff --git a/logstash/config/entrypoint.sh b/logstash/config/entrypoint.sh deleted file mode 100644 index 4aaff056..00000000 --- a/logstash/config/entrypoint.sh +++ /dev/null @@ -1,72 +0,0 @@ -#!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# -# OSSEC container bootstrap. See the README for information of the environment -# variables expected by this script. -# - -set -e - -############################################################################## -# Waiting for elasticsearch -############################################################################## - -if [ "x${ELASTICSEARCH_URL}" = "x" ]; then - el_url="http://elasticsearch:9200" -else - el_url="${ELASTICSEARCH_URL}" -fi - -############################################################################## -# Customize logstash output ip -############################################################################## - -if [ "$LOGSTASH_OUTPUT" != "" ]; then - >&2 echo "Customize Logstash ouput ip." - sed -i 's|elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/pipeline/01-wazuh.conf - sed -i 's|http://elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/config/logstash.yml -fi - -until curl -XGET $el_url; do - >&2 echo "Elastic is unavailable - sleeping." - sleep 5 -done - -sleep 2 - ->&2 echo "Elasticsearch is up." - -############################################################################## -# Waiting for wazuh alerts template -############################################################################## - -strlen=0 - -while [[ $strlen -eq 0 ]] -do - template=$(curl $el_url/_cat/templates/wazuh -s) - strlen=${#template} - >&2 echo "Wazuh alerts template not loaded - sleeping." - sleep 2 -done - -sleep 2 - ->&2 echo "Wazuh alerts template is loaded." - -############################################################################## -# Map environment variables to entries in logstash.yml. -# Note that this will mutate logstash.yml in place if any such settings are found. -# This may be undesirable, especially if logstash.yml is bind-mounted from the -# host system. -############################################################################## - -env2yaml /usr/share/logstash/config/logstash.yml - -export LS_JAVA_OPTS="-Dls.cgroup.cpuacct.path.override=/ -Dls.cgroup.cpu.path.override=/ $LS_JAVA_OPTS" - -if [[ -z $1 ]] || [[ ${1:0:1} == '-' ]] ; then - exec logstash "$@" -else - exec "$@" -fi From 20d2891e23d5b30b88098976382c82e77371f31b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:01:19 +0200 Subject: [PATCH 03/20] Correct copyright header --- elasticsearch/config/configure_s3.sh | 1 + elasticsearch/config/entrypoint.sh | 2 +- kibana/config/entrypoint.sh | 2 +- kibana/config/wazuh_app_config.sh | 2 +- kibana/config/welcome_wazuh.sh | 1 + kibana/config/xpack_config.sh | 1 + nginx/Dockerfile | 2 +- nginx/config/entrypoint.sh | 2 +- wazuh/config/entrypoint.sh | 2 +- wazuh/config/filebeat.runit.service | 1 + wazuh/config/init.bash | 4 +--- wazuh/config/postfix.runit.service | 1 + wazuh/config/wazuh-api.runit.service | 1 + wazuh/config/wazuh.runit.service | 1 + 14 files changed, 14 insertions(+), 9 deletions(-) diff --git a/elasticsearch/config/configure_s3.sh b/elasticsearch/config/configure_s3.sh index 49c88a25..5d4e3901 100644 --- a/elasticsearch/config/configure_s3.sh +++ b/elasticsearch/config/configure_s3.sh @@ -1,4 +1,5 @@ #!/bin/bash +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) set -e diff --git a/elasticsearch/config/entrypoint.sh b/elasticsearch/config/entrypoint.sh index c57703f1..38808f76 100644 --- a/elasticsearch/config/entrypoint.sh +++ b/elasticsearch/config/entrypoint.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) # For more information https://github.com/elastic/elasticsearch-docker/blob/6.5.4/build/elasticsearch/bin/docker-entrypoint.sh diff --git a/kibana/config/entrypoint.sh b/kibana/config/entrypoint.sh index f171374f..80cf73cd 100644 --- a/kibana/config/entrypoint.sh +++ b/kibana/config/entrypoint.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) set -e diff --git a/kibana/config/wazuh_app_config.sh b/kibana/config/wazuh_app_config.sh index 6fffd005..5f238325 100644 --- a/kibana/config/wazuh_app_config.sh +++ b/kibana/config/wazuh_app_config.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) kibana_config_file="/usr/share/kibana/plugins/wazuh/config.yml" diff --git a/kibana/config/welcome_wazuh.sh b/kibana/config/welcome_wazuh.sh index 0925d57a..fb90b949 100644 --- a/kibana/config/welcome_wazuh.sh +++ b/kibana/config/welcome_wazuh.sh @@ -1,4 +1,5 @@ #!/bin/bash +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) if [[ $CHANGE_WELCOME == "true" ]] then diff --git a/kibana/config/xpack_config.sh b/kibana/config/xpack_config.sh index 0dbd5ce8..0713dcb8 100644 --- a/kibana/config/xpack_config.sh +++ b/kibana/config/xpack_config.sh @@ -1,4 +1,5 @@ #!/bin/bash +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) kibana_config_file="/usr/share/kibana/config/kibana.yml" if grep -Fq "#xpack features" "$kibana_config_file"; diff --git a/nginx/Dockerfile b/nginx/Dockerfile index 9ed0950e..2ca20d6f 100644 --- a/nginx/Dockerfile +++ b/nginx/Dockerfile @@ -1,4 +1,4 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) FROM nginx:latest ENV DEBIAN_FRONTEND noninteractive diff --git a/nginx/config/entrypoint.sh b/nginx/config/entrypoint.sh index 385d7aa8..468c8a92 100644 --- a/nginx/config/entrypoint.sh +++ b/nginx/config/entrypoint.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) set -e diff --git a/wazuh/config/entrypoint.sh b/wazuh/config/entrypoint.sh index bc07ae4a..d8ae1163 100644 --- a/wazuh/config/entrypoint.sh +++ b/wazuh/config/entrypoint.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) # It will run every .sh script located in entrypoint-scripts folder in lexicographical order for script in `ls /entrypoint-scripts/*.sh | sort -n`; do diff --git a/wazuh/config/filebeat.runit.service b/wazuh/config/filebeat.runit.service index 2a46f7b0..9b048caa 100644 --- a/wazuh/config/filebeat.runit.service +++ b/wazuh/config/filebeat.runit.service @@ -1,3 +1,4 @@ #!/bin/sh +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service filebeat start tail -f /var/log/filebeat/filebeat diff --git a/wazuh/config/init.bash b/wazuh/config/init.bash index cfff523d..e40fab94 100644 --- a/wazuh/config/init.bash +++ b/wazuh/config/init.bash @@ -1,9 +1,7 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# # Initialize the custom data directory layout -# source /data_dirs.env cd /var/ossec diff --git a/wazuh/config/postfix.runit.service b/wazuh/config/postfix.runit.service index 02856a35..e900b5e5 100644 --- a/wazuh/config/postfix.runit.service +++ b/wazuh/config/postfix.runit.service @@ -1,3 +1,4 @@ #!/bin/sh +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service postfix start tail -f /var/log/mail.log diff --git a/wazuh/config/wazuh-api.runit.service b/wazuh/config/wazuh-api.runit.service index e24b8f8d..198fa4a1 100644 --- a/wazuh/config/wazuh-api.runit.service +++ b/wazuh/config/wazuh-api.runit.service @@ -1,4 +1,5 @@ #!/bin/sh +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service wazuh-api start tail -f /var/ossec/data/logs/api.log diff --git a/wazuh/config/wazuh.runit.service b/wazuh/config/wazuh.runit.service index 28a2a5b0..7ab6f1e1 100644 --- a/wazuh/config/wazuh.runit.service +++ b/wazuh/config/wazuh.runit.service @@ -1,4 +1,5 @@ #!/bin/sh +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) service wazuh-manager start tail -f /var/ossec/data/logs/ossec.log From f462dd5846133cdb2cbf085d15a2a18ee7a8fc51 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:01:28 +0200 Subject: [PATCH 04/20] Update README --- README.md | 8 +------- 1 file changed, 1 insertion(+), 7 deletions(-) diff --git a/README.md b/README.md index 1fec5721..c90beccc 100644 --- a/README.md +++ b/README.md @@ -8,7 +8,6 @@ In this repository you will find the containers to run: * wazuh: It runs the Wazuh manager, Wazuh API and Filebeat (for integration with Elastic Stack) -* wazuh-logstash: It is used to receive alerts generated by the manager and feed Elasticsearch using an alerts template * wazuh-kibana: Provides a web user interface to browse through alerts data. It includes Wazuh plugin for Kibana, that allows you to visualize agents configuration and status. * wazuh-nginx: Proxies the Kibana container, adding HTTPS (via self-signed SSL certificate) and [Basic authentication](https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#Basic_authentication_scheme). * wazuh-elasticsearch: An Elasticsearch container (working as a single-node cluster) using Elastic Stack Docker images. **Be aware to increase the `vm.max_map_count` setting, as it's detailed in the [Wazuh documentation](https://documentation.wazuh.com/current/docker/wazuh-container.html#increase-max-map-count-on-your-host-linux).** @@ -33,11 +32,6 @@ In addition, a docker-compose file is provided to launch the containers mentione │   │   └── kibana.yml │   └── Dockerfile ├── LICENSE - ├── logstash - │   ├── config - │   │   ├── 01-wazuh.conf - │   │   └── run.sh - │   └── Dockerfile ├── nginx │   ├── config │   │   └── entrypoint.sh @@ -76,7 +70,7 @@ We thank you them and everyone else who has contributed to this project. ## License and copyright -Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) ## Web references From 1d4161cc02f644708d360c6cc099d315c0a7db5d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:02:21 +0200 Subject: [PATCH 05/20] Temporary using "build" instead of "image" --- docker-compose.yml | 43 +++++++++++++++---------------------------- 1 file changed, 15 insertions(+), 28 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index f45d2b1e..d0a5692c 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,49 +1,36 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) version: '2' services: wazuh: - image: wazuh/wazuh:3.9.0_6.7.2 + build: wazuh hostname: wazuh-manager restart: always ports: - - "1514:1514/udp" - - "1515:1515" - - "514:514/udp" - - "55000:55000" - depends_on: - - logstash - logstash: - image: wazuh/wazuh-logstash:3.9.0_6.7.2 - hostname: logstash - restart: always - links: - - elasticsearch:elasticsearch - ports: - - "5000:5000" - depends_on: - - elasticsearch - environment: - - LS_HEAP_SIZE=2048m + - '1514:1514/udp' + - '1515:1515' + - '514:514/udp' + - '55000:55000' elasticsearch: - image: wazuh/wazuh-elasticsearch:3.9.0_6.7.2 + build: elasticsearch hostname: elasticsearch restart: always ports: - - "9200:9200" + - '9200:9200' environment: - node.name=node-1 - cluster.name=wazuh - - network.host=0.0.0.0 + - network.host=localhost + - discovery.type=single-node - bootstrap.memory_lock=true - - "ES_JAVA_OPTS=-Xms1g -Xmx1g" + - 'ES_JAVA_OPTS=-Xms1g -Xmx1g' ulimits: memlock: soft: -1 hard: -1 mem_limit: 2g kibana: - image: wazuh/wazuh-kibana:3.9.0_6.7.2 + build: kibana hostname: kibana restart: always depends_on: @@ -52,15 +39,15 @@ services: - elasticsearch:elasticsearch - wazuh:wazuh nginx: - image: wazuh/wazuh-nginx:3.9.0_6.7.2 + build: nginx hostname: nginx restart: always environment: - NGINX_PORT=443 - NGINX_CREDENTIALS ports: - - "80:80" - - "443:443" + - '80:80' + - '443:443' depends_on: - kibana links: From 4adb9741e4ad3b27463600cf886361dd666da45d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:02:50 +0200 Subject: [PATCH 06/20] Do not add template in Elasticsearch Dockerfile --- elasticsearch/Dockerfile | 10 +++------- 1 file changed, 3 insertions(+), 7 deletions(-) diff --git a/elasticsearch/Dockerfile b/elasticsearch/Dockerfile index 25e6e30b..111ddf21 100644 --- a/elasticsearch/Dockerfile +++ b/elasticsearch/Dockerfile @@ -1,5 +1,5 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/elasticsearch/elasticsearch:6.7.2 +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) +FROM docker.elastic.co/elasticsearch/elasticsearch:7.0.0 ENV ELASTICSEARCH_URL="http://elasticsearch:9200" @@ -13,8 +13,6 @@ ENV XPACK_ML="true" ENV ENABLE_CONFIGURE_S3="false" -ENV TEMPLATE_VERSION=v3.9.0 - # Elasticearch cluster configuration environment variables # If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration ENV ELASTIC_CLUSTER="false" \ @@ -29,8 +27,6 @@ ENV ELASTIC_CLUSTER="false" \ CLUSTER_MAX_NODES="1" \ CLUSTER_DELAYED_TIMEOUT="1m" -ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/wazuh-elastic6-template-alerts.json /usr/share/elasticsearch/config - COPY config/entrypoint.sh /entrypoint.sh RUN chmod 755 /entrypoint.sh @@ -39,7 +35,7 @@ COPY --chown=elasticsearch:elasticsearch ./config/load_settings.sh ./ RUN chmod +x ./load_settings.sh -RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-6.7.2.zip +RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-7.0.0.zip COPY config/configure_s3.sh ./config/configure_s3.sh RUN chmod 755 ./config/configure_s3.sh From 5799998308d1de6f35c9132f7d633f0325072e27 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:03:20 +0200 Subject: [PATCH 07/20] Temporary fix for Elastic 7 cluster --- elasticsearch/config/config_cluster.sh | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/elasticsearch/config/config_cluster.sh b/elasticsearch/config/config_cluster.sh index b4063825..27260399 100644 --- a/elasticsearch/config/config_cluster.sh +++ b/elasticsearch/config/config_cluster.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) elastic_config_file="/usr/share/elasticsearch/config/elasticsearch.yml" @@ -10,7 +10,7 @@ then # Set the cluster.name and discovery.zen.minimun_master_nodes variables sed -i 's:cluster.name\: "docker-cluster":cluster.name\: "'$CLUSTER_NAME'":g' $elastic_config_file - sed -i 's:discovery.zen.minimum_master_nodes\: 1:discovery.zen.minimum_master_nodes\: '$CLUSTER_NUMBER_OF_MASTERS':g' $elastic_config_file + #sed -i 's:discovery.zen.minimum_master_nodes\: 1:discovery.zen.minimum_master_nodes\: '$CLUSTER_NUMBER_OF_MASTERS':g' $elastic_config_file # Add the cluster configuration echo " @@ -23,11 +23,10 @@ node: max_local_storage_nodes: ${CLUSTER_MAX_NODES} bootstrap: - memory_lock: ${CLUSTER_MEMORY_LOCK} - -discovery: - zen: - ping.unicast.hosts: ${CLUSTER_DISCOVERY_SERVICE} - + memory_lock: ${CLUSTER_MEMORY_LOCK} " >> $elastic_config_file +else + +echo 'cluster.initial_master_nodes: ["elasticsearch"]' >> $elastic_config_file + fi From 6ff836e9fcc80e53600f5575ea6ac315838a43c3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:04:20 +0200 Subject: [PATCH 08/20] Removed template. Fix _type. Fix if condition. --- elasticsearch/config/load_settings.sh | 15 +++++---------- 1 file changed, 5 insertions(+), 10 deletions(-) diff --git a/elasticsearch/config/load_settings.sh b/elasticsearch/config/load_settings.sh index 2a69b36f..b7b3b08c 100644 --- a/elasticsearch/config/load_settings.sh +++ b/elasticsearch/config/load_settings.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) set -e @@ -45,20 +45,15 @@ fi #Insert default templates -sed -i 's| "index.refresh_interval": "5s"| "index.refresh_interval": "5s", "number_of_shards" : '"${ALERTS_SHARDS}"', "number_of_replicas" : '"${ALERTS_REPLICAS}"'|' /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json - -cat /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json | curl -XPUT "$el_url/_template/wazuh" ${auth} -H 'Content-Type: application/json' -d @- -sleep 5 - - API_PASS_Q=`echo "$API_PASS" | tr -d '"'` API_USER_Q=`echo "$API_USER" | tr -d '"'` API_PASSWORD=`echo -n $API_PASS_Q | base64` echo "Setting API credentials into Wazuh APP" -CONFIG_CODE=$(curl -s -o /dev/null -w "%{http_code}" -XGET $el_url/.wazuh/wazuh-configuration/1513629884013 ${auth}) -if [ "x$CONFIG_CODE" = "x404" ]; then - curl -s -XPOST $el_url/.wazuh/wazuh-configuration/1513629884013 ${auth} -H 'Content-Type: application/json' -d' +CONFIG_CODE=$(curl -s -o /dev/null -w "%{http_code}" -XGET $el_url/.wazuh/_doc/1513629884013 ${auth}) + +if [ "x$CONFIG_CODE" != "x200" ]; then + curl -s -XPOST $el_url/.wazuh/_doc/1513629884013 ${auth} -H 'Content-Type: application/json' -d' { "api_user": "'"$API_USER_Q"'", "api_password": "'"$API_PASSWORD"'", From d6074f5f7e9e2f9c1cba2d264f0bdd61f445453d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:04:44 +0200 Subject: [PATCH 09/20] Temporary using staging Wazuh app (testing) --- kibana/Dockerfile | 16 +++++++--------- 1 file changed, 7 insertions(+), 9 deletions(-) diff --git a/kibana/Dockerfile b/kibana/Dockerfile index e6eda42f..17795004 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -1,15 +1,15 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/kibana/kibana:6.7.2 -ARG WAZUH_APP_VERSION=3.9.0_6.7.2 +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) +FROM docker.elastic.co/kibana/kibana:7.0.0 +ARG WAZUH_APP_VERSION=3.9.0_7.0.0-rc5 USER root -ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp +ADD https://packages-dev.wazuh.com/staging/app/kibana/wazuhapp-3.9.0_7.0.0-rc5.zip /tmp -RUN NODE_OPTIONS="--max-old-space-size=3072" /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip &&\ - chown -R kibana:kibana /usr/share/kibana &&\ - rm -rf /tmp/* +RUN /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip +RUN rm -rf /tmp/wazuhapp-${WAZUH_APP_VERSION}.zip COPY config/entrypoint.sh /entrypoint.sh + RUN chmod 755 /entrypoint.sh USER kibana @@ -71,6 +71,4 @@ RUN chmod +x ./welcome_wazuh.sh RUN ./welcome_wazuh.sh -RUN /usr/local/bin/kibana-docker --optimize - ENTRYPOINT /entrypoint.sh From 91d4ec5c4bd161f9efd0f0df4efe42a2d2f8c60f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:05:06 +0200 Subject: [PATCH 10/20] Uncomment "elasticsearch.hosts" setting --- kibana/config/kibana_settings.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/kibana/config/kibana_settings.sh b/kibana/config/kibana_settings.sh index 77b116d7..fec7e289 100644 --- a/kibana/config/kibana_settings.sh +++ b/kibana/config/kibana_settings.sh @@ -1,6 +1,5 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) - +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) WAZUH_MAJOR=3 @@ -19,6 +18,7 @@ WAZUH_MAJOR=3 # Customize elasticsearch ip ############################################################################## if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then + sed -i "s:#elasticsearch.hosts:elasticsearch.hosts:g" /usr/share/kibana/config/kibana.yml sed -i "s/elasticsearch:9200/$ELASTICSEARCH_KIBANA_IP:9200/" /usr/share/kibana/config/kibana.yml fi From ae3734db1803b3120acc1aa91c7815ca7bbc9ef4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:05:49 +0200 Subject: [PATCH 11/20] Adding template. Using "elastic-7-2" branch --- wazuh/Dockerfile | 35 ++++++++++++++++++++--------------- 1 file changed, 20 insertions(+), 15 deletions(-) diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index 454f8ea9..8f89729d 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -1,10 +1,12 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) FROM phusion/baseimage:latest -ARG FILEBEAT_VERSION=6.7.2 +ARG FILEBEAT_VERSION=7.0.0 ARG WAZUH_VERSION=3.9.0-1 ENV API_USER="foo" \ - API_PASS="bar" + API_PASS="bar" + +ENV TEMPLATE_VERSION="elastic-7-2" # Set repositories. RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list && \ @@ -31,12 +33,12 @@ COPY config/00-wazuh.sh /entrypoint-scripts/00-wazuh.sh # Sync calls are due to https://github.com/docker/docker/issues/9547 RUN chmod 755 /init.bash && \ - sync && /init.bash && \ - sync && rm /init.bash && \ - curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-${FILEBEAT_VERSION}-amd64.deb &&\ - dpkg -i filebeat-${FILEBEAT_VERSION}-amd64.deb && rm -f filebeat-${FILEBEAT_VERSION}-amd64.deb && \ - chmod 755 /entrypoint.sh && \ - chmod 755 /entrypoint-scripts/00-wazuh.sh + sync && /init.bash && \ + sync && rm /init.bash && \ + curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-${FILEBEAT_VERSION}-amd64.deb &&\ + dpkg -i filebeat-${FILEBEAT_VERSION}-amd64.deb && rm -f filebeat-${FILEBEAT_VERSION}-amd64.deb && \ + chmod 755 /entrypoint.sh && \ + chmod 755 /entrypoint-scripts/00-wazuh.sh COPY config/filebeat.yml /etc/filebeat/ RUN chmod go-w /etc/filebeat/filebeat.yml @@ -52,9 +54,9 @@ EXPOSE 55000/tcp 1514/udp 1515/tcp 514/udp 1516/tcp # Adding services RUN mkdir /etc/service/wazuh && \ - mkdir /etc/service/wazuh-api && \ - mkdir /etc/service/postfix && \ - mkdir /etc/service/filebeat + mkdir /etc/service/wazuh-api && \ + mkdir /etc/service/postfix && \ + mkdir /etc/service/filebeat COPY config/wazuh.runit.service /etc/service/wazuh/run COPY config/wazuh-api.runit.service /etc/service/wazuh-api/run @@ -62,9 +64,12 @@ COPY config/postfix.runit.service /etc/service/postfix/run COPY config/filebeat.runit.service /etc/service/filebeat/run RUN chmod +x /etc/service/wazuh-api/run && \ - chmod +x /etc/service/wazuh/run && \ - chmod +x /etc/service/postfix/run && \ - chmod +x /etc/service/filebeat/run + chmod +x /etc/service/wazuh/run && \ + chmod +x /etc/service/postfix/run && \ + chmod +x /etc/service/filebeat/run + +ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/wazuh-elastic7-template-alerts.json /etc/filebeat +RUN chmod go-w /etc/filebeat/wazuh-elastic7-template-alerts.json # Run all services ENTRYPOINT ["/entrypoint.sh"] From eadc76586094631986d8b1d7a2f22b73a97b8c85 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:06:00 +0200 Subject: [PATCH 12/20] Remove Logstash output --- wazuh/config/00-wazuh.sh | 22 +++------------------- 1 file changed, 3 insertions(+), 19 deletions(-) diff --git a/wazuh/config/00-wazuh.sh b/wazuh/config/00-wazuh.sh index 5935f8cb..32fdd4f4 100644 --- a/wazuh/config/00-wazuh.sh +++ b/wazuh/config/00-wazuh.sh @@ -1,17 +1,10 @@ #!/bin/bash -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -# -# OSSEC container bootstrap. See the README for information of the environment +# Wazuh container bootstrap. See the README for information of the environment # variables expected by this script. -# -# - -# # Startup the services -# - source /data_dirs.env FIRST_TIME_INSTALLATION=false @@ -139,13 +132,4 @@ echo "Change Wazuh API user credentials" change_user="node htpasswd -b -c user $API_USER $API_PASS" eval $change_user -popd - - -############################################################################## -# Customize filebeat output ip -############################################################################## -if [ "$FILEBEAT_OUTPUT" != "" ]; then - sed -i "s/logstash:5000/$FILEBEAT_OUTPUT:5000/" /etc/filebeat/filebeat.yml -fi - +popd \ No newline at end of file From 780dfe1a5126f61f98edb624dd33206ce3c526a4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jes=C3=BAs=20=C3=81ngel?= Date: Tue, 14 May 2019 15:06:12 +0200 Subject: [PATCH 13/20] Updated Filebeat config for Elastic 7 --- wazuh/config/filebeat.yml | 65 ++++++++++++++++++++++++++++++--------- 1 file changed, 50 insertions(+), 15 deletions(-) diff --git a/wazuh/config/filebeat.yml b/wazuh/config/filebeat.yml index bb02a5d8..ba9a304f 100644 --- a/wazuh/config/filebeat.yml +++ b/wazuh/config/filebeat.yml @@ -1,18 +1,53 @@ -# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) -filebeat: - prospectors: +# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) +filebeat.inputs: - type: log paths: - - "/var/ossec/logs/alerts/alerts.json" - document_type: json - json.message_key: log - json.keys_under_root: true - json.overwrite_keys: true - tail_files: true + - '/var/ossec/logs/alerts/alerts.json' -output: - logstash: - # The Logstash hosts - hosts: ["logstash:5000"] -# ssl: -# certificate_authorities: ["/etc/filebeat/logstash.crt"] +setup.template.json.enabled: true +setup.template.json.path: "/etc/filebeat/wazuh-elastic7-template-alerts.json" +setup.template.json.name: "wazuh" +setup.template.overwrite: true + +processors: + - decode_json_fields: + fields: ['message'] + process_array: true + max_depth: 200 + target: '' + overwrite_keys: true + - drop_fields: + fields: ['message', 'ecs', 'beat', 'input_type', 'tags', 'count', '@version', 'log', 'offset', 'type', 'host'] + - rename: + fields: + - from: "data.aws.sourceIPAddress" + to: "@src_ip" + ignore_missing: true + fail_on_error: false + when: + regexp: + data.aws.sourceIPAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b + - rename: + fields: + - from: "data.srcip" + to: "@src_ip" + ignore_missing: true + fail_on_error: false + when: + regexp: + data.srcip: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b + - rename: + fields: + - from: "data.win.eventdata.ipAddress" + to: "@src_ip" + ignore_missing: true + fail_on_error: false + when: + regexp: + data.win.eventdata.ipAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b + +output.elasticsearch: + hosts: ['http://elasticsearch:9200'] + #pipeline: geoip + indices: + - index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}' From 447c15c8238779dadcc02a67e8e6052d00bd63e4 Mon Sep 17 00:00:00 2001 From: Javier Castro Date: Fri, 17 May 2019 12:56:45 -0700 Subject: [PATCH 14/20] Allow port change for elasticsearch url in kibana --- kibana/config/kibana_settings.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kibana/config/kibana_settings.sh b/kibana/config/kibana_settings.sh index 77b116d7..3255338b 100644 --- a/kibana/config/kibana_settings.sh +++ b/kibana/config/kibana_settings.sh @@ -19,7 +19,7 @@ WAZUH_MAJOR=3 # Customize elasticsearch ip ############################################################################## if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then - sed -i "s/elasticsearch:9200/$ELASTICSEARCH_KIBANA_IP:9200/" /usr/share/kibana/config/kibana.yml + sed -i "s/elasticsearch:9200/$ELASTICSEARCH_KIBANA_IP/" /usr/share/kibana/config/kibana.yml fi if [ "$KIBANA_IP" != "" ]; then From 569d3ee931821be38dc91e9f5f3df3d3d0bd5bdd Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Tue, 21 May 2019 23:18:35 +0200 Subject: [PATCH 15/20] Changed entrypoint copy location --- kibana/Dockerfile | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/kibana/Dockerfile b/kibana/Dockerfile index 92beac63..f72e8093 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -9,8 +9,8 @@ RUN NODE_OPTIONS="--max-old-space-size=3072" /usr/share/kibana/bin/kibana-plugin chown -R kibana:kibana /usr/share/kibana &&\ rm -rf /tmp/* -COPY config/entrypoint.sh /entrypoint.sh -RUN chmod 755 /entrypoint.sh +COPY config/entrypoint.sh ./entrypoint.sh +RUN chmod 755 ./entrypoint.sh USER kibana @@ -73,4 +73,4 @@ RUN ./welcome_wazuh.sh RUN /usr/local/bin/kibana-docker --optimize -ENTRYPOINT /entrypoint.sh +ENTRYPOINT ./entrypoint.sh From f66f986abb355bba95a1cdca1cb9f868140f4096 Mon Sep 17 00:00:00 2001 From: "Manuel J. Bernal" Date: Tue, 21 May 2019 23:18:51 +0200 Subject: [PATCH 16/20] Fixed sed command in kibana_settings --- kibana/config/kibana_settings.sh | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/kibana/config/kibana_settings.sh b/kibana/config/kibana_settings.sh index 3255338b..96e5f35b 100644 --- a/kibana/config/kibana_settings.sh +++ b/kibana/config/kibana_settings.sh @@ -19,7 +19,8 @@ WAZUH_MAJOR=3 # Customize elasticsearch ip ############################################################################## if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then - sed -i "s/elasticsearch:9200/$ELASTICSEARCH_KIBANA_IP/" /usr/share/kibana/config/kibana.yml + sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_KIBANA_IP'|g' /usr/share/kibana/config/kibana.yml + fi if [ "$KIBANA_IP" != "" ]; then From 1922ae145ada18d65f6dacafa00045579213d971 Mon Sep 17 00:00:00 2001 From: Jose M Date: Fri, 24 May 2019 16:35:29 +0200 Subject: [PATCH 17/20] Added 'cluster.initial_master_nodes' and related env variable. --- elasticsearch/config/config_cluster.sh | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/elasticsearch/config/config_cluster.sh b/elasticsearch/config/config_cluster.sh index 27260399..2222099e 100644 --- a/elasticsearch/config/config_cluster.sh +++ b/elasticsearch/config/config_cluster.sh @@ -24,9 +24,18 @@ node: bootstrap: memory_lock: ${CLUSTER_MEMORY_LOCK} + +cluster.initial_master_nodes: + - '${CLUSTER_INITIAL_MASTER_NODES}' + " >> $elastic_config_file else -echo 'cluster.initial_master_nodes: ["elasticsearch"]' >> $elastic_config_file +cat >> $elastic_config_file <<'EOF' +cluster.initial_master_nodes: + - 'elasticsearch' +EOF + +# echo 'discovery.type: single-node' fi From 6a82b98fcf74d8207fb2fb49bd7312c3a22270fd Mon Sep 17 00:00:00 2001 From: Jose M Date: Fri, 24 May 2019 16:39:24 +0200 Subject: [PATCH 18/20] Bump version. --- elasticsearch/Dockerfile | 10 ++++++---- elasticsearch/config/load_settings.sh | 2 +- kibana/Dockerfile | 8 ++++---- wazuh/Dockerfile | 9 +++++---- wazuh/config/filebeat.yml | 2 +- 5 files changed, 17 insertions(+), 14 deletions(-) diff --git a/elasticsearch/Dockerfile b/elasticsearch/Dockerfile index 111ddf21..0833ad93 100644 --- a/elasticsearch/Dockerfile +++ b/elasticsearch/Dockerfile @@ -1,5 +1,5 @@ # Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/elasticsearch/elasticsearch:7.0.0 +FROM docker.elastic.co/elasticsearch/elasticsearch:7.1.0 ENV ELASTICSEARCH_URL="http://elasticsearch:9200" @@ -15,6 +15,7 @@ ENV ENABLE_CONFIGURE_S3="false" # Elasticearch cluster configuration environment variables # If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration +# CLUSTER_INITIAL_MASTER_NODES set to own node by default. ENV ELASTIC_CLUSTER="false" \ CLUSTER_NAME="wazuh" \ CLUSTER_NODE_MASTER="true" \ @@ -25,9 +26,10 @@ ENV ELASTIC_CLUSTER="false" \ CLUSTER_DISCOVERY_SERVICE="wazuh-elasticsearch" \ CLUSTER_NUMBER_OF_MASTERS="2" \ CLUSTER_MAX_NODES="1" \ - CLUSTER_DELAYED_TIMEOUT="1m" + CLUSTER_DELAYED_TIMEOUT="1m" \ + CLUSTER_INITIAL_MASTER_NODES="wazuh-elasticsearch" -COPY config/entrypoint.sh /entrypoint.sh +COPY config/entrypoint.sh /entrypoint.sh RUN chmod 755 /entrypoint.sh @@ -35,7 +37,7 @@ COPY --chown=elasticsearch:elasticsearch ./config/load_settings.sh ./ RUN chmod +x ./load_settings.sh -RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-7.0.0.zip +RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-7.1.0.zip COPY config/configure_s3.sh ./config/configure_s3.sh RUN chmod 755 ./config/configure_s3.sh diff --git a/elasticsearch/config/load_settings.sh b/elasticsearch/config/load_settings.sh index b7b3b08c..65f90a76 100644 --- a/elasticsearch/config/load_settings.sh +++ b/elasticsearch/config/load_settings.sh @@ -11,7 +11,7 @@ else wazuh_url="${WAZUH_API_URL}" fi -if [ ${ENABLED_XPACK} != "true" || "x${ELASTICSEARCH_USERNAME}" = "x" || "x${ELASTICSEARCH_PASSWORD}" = "x" ]; then +if [[ ${ENABLED_XPACK} != "true" || "x${ELASTICSEARCH_USERNAME}" = "x" || "x${ELASTICSEARCH_PASSWORD}" = "x" ]]; then auth="" else auth="--user ${ELASTICSEARCH_USERNAME}:${ELASTICSEARCH_PASSWORD}" diff --git a/kibana/Dockerfile b/kibana/Dockerfile index 17795004..08a4e455 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -1,16 +1,16 @@ # Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) -FROM docker.elastic.co/kibana/kibana:7.0.0 -ARG WAZUH_APP_VERSION=3.9.0_7.0.0-rc5 +FROM docker.elastic.co/kibana/kibana:7.1.0 +ARG WAZUH_APP_VERSION=3.9.1_7.1.0 USER root -ADD https://packages-dev.wazuh.com/staging/app/kibana/wazuhapp-3.9.0_7.0.0-rc5.zip /tmp +ADD https://packages.wazuh.com/wazuhapp/wazuhapp-3.9.1_7.1.0.zip /tmp RUN /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip RUN rm -rf /tmp/wazuhapp-${WAZUH_APP_VERSION}.zip COPY config/entrypoint.sh /entrypoint.sh -RUN chmod 755 /entrypoint.sh +RUN chmod 755 /entrypoint.sh USER kibana diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index 8f89729d..8e3830e5 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -1,7 +1,7 @@ # Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2) FROM phusion/baseimage:latest -ARG FILEBEAT_VERSION=7.0.0 -ARG WAZUH_VERSION=3.9.0-1 +ARG FILEBEAT_VERSION=7.1.0 +ARG WAZUH_VERSION=3.9.1-1 ENV API_USER="foo" \ API_PASS="bar" @@ -68,8 +68,9 @@ RUN chmod +x /etc/service/wazuh-api/run && \ chmod +x /etc/service/postfix/run && \ chmod +x /etc/service/filebeat/run -ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/wazuh-elastic7-template-alerts.json /etc/filebeat -RUN chmod go-w /etc/filebeat/wazuh-elastic7-template-alerts.json + +ADD https://raw.githubusercontent.com/wazuh/wazuh/v3.9.1/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat +RUN chmod go-w /etc/filebeat/wazuh-template.json # Run all services ENTRYPOINT ["/entrypoint.sh"] diff --git a/wazuh/config/filebeat.yml b/wazuh/config/filebeat.yml index ba9a304f..628e4479 100644 --- a/wazuh/config/filebeat.yml +++ b/wazuh/config/filebeat.yml @@ -5,7 +5,7 @@ filebeat.inputs: - '/var/ossec/logs/alerts/alerts.json' setup.template.json.enabled: true -setup.template.json.path: "/etc/filebeat/wazuh-elastic7-template-alerts.json" +setup.template.json.path: "/etc/filebeat/wazuh-template.json" setup.template.json.name: "wazuh" setup.template.overwrite: true From 22ad4360f548e54bb0c5e929f8c84a186ad2ab88 Mon Sep 17 00:00:00 2001 From: manuasir Date: Mon, 3 Jun 2019 17:20:11 +0200 Subject: [PATCH 19/20] Add XPACK_SECURITY_ENABLED and KIBANA_INDEX options to Kibana container. --- kibana/config/kibana_settings.sh | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/kibana/config/kibana_settings.sh b/kibana/config/kibana_settings.sh index 96e5f35b..fb5768e5 100644 --- a/kibana/config/kibana_settings.sh +++ b/kibana/config/kibana_settings.sh @@ -20,7 +20,22 @@ WAZUH_MAJOR=3 ############################################################################## if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_KIBANA_IP'|g' /usr/share/kibana/config/kibana.yml +fi +# If KIBANA_INDEX was set, then change the default index in kibana.yml configuration file. If there was an index, then delete it and recreate. +if [ "$KIBANA_INDEX" != "" ]; then + if grep -q 'kibana.index' /usr/share/kibana/config/kibana.yml; then + sed -i '/kibana.index/d' /usr/share/kibana/config/kibana.yml + fi + echo "kibana.index: $KIBANA_INDEX" >> /usr/share/kibana/config/kibana.yml +fi + +# If XPACK_SECURITY_ENABLED was set, then change the xpack.security.enabled option from true (default) to false. +if [ "$XPACK_SECURITY_ENABLED" != "" ]; then + if grep -q 'xpack.security.enabled' /usr/share/kibana/config/kibana.yml; then + sed -i '/xpack.security.enabled/d' /usr/share/kibana/config/kibana.yml + fi + echo "xpack.security.enabled: $XPACK_SECURITY_ENABLED" >> /usr/share/kibana/config/kibana.yml fi if [ "$KIBANA_IP" != "" ]; then From 4a01fcc01f9b6737fccf6e5df2737c926ced92dc Mon Sep 17 00:00:00 2001 From: manuasir Date: Tue, 4 Jun 2019 15:21:14 +0200 Subject: [PATCH 20/20] Bump version --- CHANGELOG.md | 7 +++++++ VERSION | 4 ++-- kibana/Dockerfile | 2 +- wazuh/Dockerfile | 4 ++-- 4 files changed, 12 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 003c533b..c5972578 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,13 @@ # Change Log All notable changes to this project will be documented in this file. +## Wazuh Docker v3.9.1_7.1.0 + +### Added + +- Support for Elastic v7.1.0 +- New environment variables for Kibana ([@manuasir](https://github.com/manuasir)) [#22ad43](https://github.com/wazuh/wazuh-docker/commit/22ad4360f548e54bb0c5e929f8c84a186ad2ab88) + ## Wazuh Docker v3.9.1_6.8.0 ### Added diff --git a/VERSION b/VERSION index 3e8fc28f..92cf5618 100644 --- a/VERSION +++ b/VERSION @@ -1,2 +1,2 @@ -WAZUH-DOCKER_VERSION="3.9.1_6.8.0" -REVISION="3901" \ No newline at end of file +WAZUH-DOCKER_VERSION="3.9.1_7.1.0" +REVISION="3911" \ No newline at end of file diff --git a/kibana/Dockerfile b/kibana/Dockerfile index b235c9fa..a5e42fd5 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -3,7 +3,7 @@ FROM docker.elastic.co/kibana/kibana:7.1.0 ARG WAZUH_APP_VERSION=3.9.1_7.1.0 USER root -ADD https://packages.wazuh.com/wazuhapp/wazuhapp-3.9.1_7.1.0.zip /tmp +ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp RUN /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip RUN rm -rf /tmp/wazuhapp-${WAZUH_APP_VERSION}.zip diff --git a/wazuh/Dockerfile b/wazuh/Dockerfile index 5b191d97..9f822892 100644 --- a/wazuh/Dockerfile +++ b/wazuh/Dockerfile @@ -6,7 +6,7 @@ ARG WAZUH_VERSION=3.9.1-1 ENV API_USER="foo" \ API_PASS="bar" -ENV TEMPLATE_VERSION="elastic-7-2" +ENV TEMPLATE_VERSION="v3.9.1" # Set repositories. RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list && \ @@ -69,7 +69,7 @@ RUN chmod +x /etc/service/wazuh-api/run && \ chmod +x /etc/service/filebeat/run -ADD https://raw.githubusercontent.com/wazuh/wazuh/v3.9.1/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat +ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat RUN chmod go-w /etc/filebeat/wazuh-template.json # Run all services