fix securityadmin.sh for wazuh-indexer

This commit is contained in:
vcerenu
2022-02-11 16:50:33 -03:00
parent d5bda0896a
commit ac86b6652e
44 changed files with 350 additions and 148 deletions
+8 -17
View File
@@ -12,7 +12,7 @@ services:
- "514:514/udp"
- "55000:55000"
environment:
- ELASTICSEARCH_URL=https://wazuh-indexer:9700
- ELASTICSEARCH_URL=https://wazuh1.indexer:9700
- ELASTIC_USERNAME=admin
- ELASTIC_PASSWORD=admin
- FILEBEAT_SSL_VERIFICATION_MODE=none
@@ -29,19 +29,14 @@ services:
- filebeat_etc:/etc/filebeat
- filebeat_var:/var/lib/filebeat
wazuh-indexer:
image: test-indexer
hostname: node1
wazuh1.indexer:
image: wazuh/wazuh-indexer:4.3.0
hostname: wazuh1.indexer
restart: always
ports:
- "9700:9700"
environment:
- discovery.type=single-node
- cluster.name=wazuh-cluster
- network.host=0.0.0.0
- plugins.security.allow_default_init_securityindex=true
- "OPENSEARCH_JAVA_OPTS=-Xms512m -Xmx512m"
- bootstrap.memory_lock=true
ulimits:
memlock:
soft: -1
@@ -50,9 +45,9 @@ services:
soft: 65536
hard: 65536
kibana:
wazuh.dashboard:
image: wazuh/wazuh-dashboard:4.3.0
hostname: kibana
hostname: wazuh.dashboard
restart: always
ports:
- 5601:5601
@@ -61,12 +56,8 @@ services:
- ELASTICSEARCH_USERNAME=admin
- ELASTICSEARCH_PASSWORD=admin
- SERVER_SSL_ENABLED=false
depends_on:
- wazuh-indexer
links:
- wazuh-indexer:wazuh-indexer
- wazuh:wazuh
#volumes:
# - ./production_cluster/wazuh_dashboard/dashboard.yml:/etc/wazuh-dashboard/dashboard.yml
volumes:
ossec_api_configuration:
+1 -1
View File
@@ -6,7 +6,7 @@ ARG WAZUH_VERSION=4.2.5
ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}"
WORKDIR /usr/share/kibana
RUN ./bin/kibana-plugin install https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana-${WAZUH_APP_VERSION}-1.zip
RUN ./bin/kibana-plugin install https://packages-dev.wazuh.com/pre-release/ui/kibana/wazuh_kibana-${WAZUH_APP_VERSION}-1.zip
WORKDIR /
USER root
+1 -1
View File
@@ -6,7 +6,7 @@ ARG WAZUH_VERSION=4.3.0
ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}"
WORKDIR /usr/share/kibana
RUN ./bin/kibana-plugin install https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana-${WAZUH_APP_VERSION}-1.zip
RUN ./bin/kibana-plugin install https://packages-dev.wazuh.com/pre-release/ui/kibana/wazuh_kibana-${WAZUH_APP_VERSION}-1.zip
ENV PATTERN="" \
CHECKS_PATTERN="" \
+3 -3
View File
@@ -41,7 +41,7 @@ http {
ssl_certificate /etc/nginx/ssl/cert.pem;
ssl_certificate_key /etc/nginx/ssl/key.pem;
location / {
proxy_pass https://kibana:5601/;
proxy_pass https://wazuh.dashboard:5601/;
proxy_ssl_verify off;
proxy_buffer_size 128k;
proxy_buffers 4 256k;
@@ -57,8 +57,8 @@ http {
stream {
upstream mycluster {
hash $remote_addr consistent;
server wazuh-master:1514;
server wazuh-worker:1514;
server wazuh.master:1514;
server wazuh.worker:1514;
}
server {
listen 1514;
+21
View File
@@ -0,0 +1,21 @@
-----BEGIN CERTIFICATE-----
MIIDazCCAlOgAwIBAgIUASe6vu/ElSX7Znaz3NfI/zM6QCEwDQYJKoZIhvcNAQEL
BQAwRTELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoM
GEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMjAyMDgxMjMxNDlaFw0yMzAy
MDgxMjMxNDlaMEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEw
HwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQC36B2fAApuF7OjzvGDGfhOSDoKsemyCCRfQ7ErJXhJ
/aaFyBFmnRpwHWKRm/a+rcjFc2EEFxW6rkwHScoMCkpPPJMuxOw3xd1YKy/hy//e
4L67iAdc2yNlXmkANMUPQldJn2RFf7JSVEMGMLhvEQsIKQ0AKqBaytS+2Cr7ciHv
g1VxNAXvJkyYruEPIuHr9WvZ/BgmxCcI5IM4yLXSLbpbUqajQCAWa/HlDEO0729t
kF8dSJYLrz9kt2dnCgupw4iHCwYH+VjUEOAfAucF8Uj5u13GdovaodRxwftHG3TV
quZCYK77V/lJNOq0eUmZ33r1VvH1VZsAhThX4GV5auULAgMBAAGjUzBRMB0GA1Ud
DgQWBBRAa37ztZ4A+bZ+rO2DmUp5Ew7Q2TAfBgNVHSMEGDAWgBRAa37ztZ4A+bZ+
rO2DmUp5Ew7Q2TAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB0
9qCMnym11g3NUNksnCtrHOo8r5DKU9KPISFOtG03Syxe7K9xi3oOYqaiZPJezoSl
7Z9O6Sobwgah+MtwZ5/9+jsxPgmEcpE6SWYx6KcG44TrC7RToIX7JyILxJujqJT2
LODBmHO2IMGi9htaV8WDqwDKTqtBsmi9VdSOVy1WOsP9lcJoO2Di4cPS5RJjdDAW
sJNAFK+tGv0ZcUZ5bunjIGTEUIAElSPE/LTzuox2R4gVdWx0QYnKLn945C7Blr5d
tPR6EOI/4n5X7nq4XnX60dTAVS8ybZcUHTmHV9bz+KBu08jFn6Aum8mhYm1iFKKL
3P6t5XsQAQMTR37HAhLW
-----END CERTIFICATE-----
+28
View File
@@ -0,0 +1,28 @@
-----BEGIN PRIVATE KEY-----
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQC36B2fAApuF7Oj
zvGDGfhOSDoKsemyCCRfQ7ErJXhJ/aaFyBFmnRpwHWKRm/a+rcjFc2EEFxW6rkwH
ScoMCkpPPJMuxOw3xd1YKy/hy//e4L67iAdc2yNlXmkANMUPQldJn2RFf7JSVEMG
MLhvEQsIKQ0AKqBaytS+2Cr7ciHvg1VxNAXvJkyYruEPIuHr9WvZ/BgmxCcI5IM4
yLXSLbpbUqajQCAWa/HlDEO0729tkF8dSJYLrz9kt2dnCgupw4iHCwYH+VjUEOAf
AucF8Uj5u13GdovaodRxwftHG3TVquZCYK77V/lJNOq0eUmZ33r1VvH1VZsAhThX
4GV5auULAgMBAAECggEAScmo8N28UZXS7tueTULDPO1/1EC0Ckl4Bn0LfctH6zAJ
e03dpXVNYUR5AwE3zCPAFXEIsPJuNnuuZ5I0rgYG8KnWSAKc4HfUKocRbCBEpnE4
NdgLVDdciVSK/pkto8Szbwez3KqyqpPCXJ55sZ599aU64SE5O5R8LaJgBIkzknxK
J2cS6W7M15nwpgmhS5NlXDnykaDa8lPTccqqPF2b1HAgup2Lfg/HIq5U6kB6O87R
mQGd1ZZ13CxNJP6qWfSK34B1novabkOhy6vlfE2HT8uggxjR7B1u++Lr/jccduNY
Mvm9kILWwxrmPNOqt9OJLZYxlKTcsaIZvDuin47hSQKBgQDixjQXGD9bcMyy1z9k
7I98HcEoy3CbXq1zNxaZw4N4zEttVUHexbBs/UDYGXU+O4hRYxmPChKHdTQ4KzWx
RPTNnnzPTsHl6W+a2XS8MnoiF1yMUuE0IwThkS4OlEVakS1I+pyOEQxh0R93KBrW
LFRkBjMDAv7uB+TtXJNpNfRVLwKBgQDPm515DVjO1+MwzGni4TD8EvZl0KWkHASO
VLh8eDOTe+1dPdlHJp98+eOCp+BzfiKFYXDXmeoaZ+wBbyNxRr6ofPGVtHEGp4zp
pWp8BQ8Uw1LojpZB8uji2+LaX+qb7W+dFR8kbWbjTQkuWYU2jjk7WqreUdTnxRtb
sc/nE6fu5QKBgEgiwkkiZm0A6axt+fVxpobVtC703+IccNI4kNDit3yCh+/Ecgqa
Ge/hc3IKTxg3uboh6uxsSM6cArtnS1ITXEfYBV2wcM9gvSaly5Nd/ym/AqqEZqy+
Avx5wQvUMGeJzLztM0WhuK2Y5whxUnAUc9fJfQqVNmCjVDgI/b828XzzAoGBAL0N
CR41sDxTTZifXID07eVt4yCeGmhR9zghIAqAbv8Lp//zlUt8eVmWOL4+315sa0Uo
kVhT2WGIZtp7eTvq3y2Q8XGQ6ifUJbaSImCjPrN6lqIdTejqKXaEI5UWKQ8q7SuP
E1fZpAqymPyzGmKuqqFJFDX1MLqJvDsItbjIJnGdAoGAWnLU4S2CzgtiOeFiKKU9
P+nhTplGV/DH0dMnVa5hZeIP3UDpzR19aQ9OXdRv30M3eSQnIRcL3A/Gci8fSmx/
/5nJp1hoEwL2oawyRcEU6A5djT7zZ0m2+gteu9QLBiq3YlqmJUVKaviIUC4Se7ZP
TrRYjCtxO5XdtyZGZxVrTQk=
-----END PRIVATE KEY-----
@@ -0,0 +1,36 @@
network.host: "0.0.0.0"
node.name: "wazuh1.indexer"
http.port: 9700-9799
transport.tcp.port: 9800-9899
path.data: /var/lib/wazuh-indexer
path.logs: /var/log/wazuh-indexer
discovery.type: single-node
compatibility.override_main_response_version: true
###############################################################################
# #
# WARNING: Insecure demo certificates set up in this file. #
# Please change on production cluster! #
# #
###############################################################################
plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/admin.pem
plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/admin-key.pem
plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/admin.pem
plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/admin-key.pem
plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.http.enabled: true
plugins.security.ssl.transport.enforce_hostname_verification: false
plugins.security.ssl.transport.resolve_hostname: false
plugins.security.audit.type: internal_opensearch
plugins.security.authcz.admin_dn:
- "CN=admin,OU=Demo,O=Wazuh,L=California,C=US"
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.nodes_dn:
- "CN=demo-indexer,OU=Demo,O=Wazuh,L=California,C=US"
plugins.security.restapi.roles_enabled:
- "all_access"
- "security_rest_api_access"
plugins.security.system_indices.enabled: true
plugins.security.system_indices.indices: [".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opendistro-notifications-*", ".opendistro-notebooks", ".opensearch-observability", ".opendistro-asynchronous-search-response*", ".replication-metadata-store"]
@@ -1,14 +1,14 @@
network.host: wazuh1-indexer
node.name: wazuh1-indexer
network.host: wazuh1.indexer
node.name: wazuh1.indexer
cluster.initial_master_nodes:
- wazuh1-indexer
- wazuh2-indexer
- wazuh3-indexer
- wazuh1.indexer
- wazuh2.indexer
- wazuh3.indexer
cluster.name: "wazuh-cluster"
discovery.seed_hosts:
- wazuh1-indexer
- wazuh2-indexer
- wazuh3-indexer
- wazuh1.indexer
- wazuh2.indexer
- wazuh3.indexer
http.port: 9700-9799
transport.tcp.port: 9800-9899
node.max_local_storage_nodes: "3"
@@ -20,11 +20,11 @@ path.logs: /var/log/wazuh-indexer
# Please change on production cluster! #
# #
###############################################################################
plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh1-indexer.pem
plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh1-indexer.key
plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh1.indexer.pem
plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh1.indexer.key
plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh1-indexer.pem
plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh1-indexer.key
plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh1.indexer.pem
plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh1.indexer.key
plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.http.enabled: true
plugins.security.ssl.transport.enforce_hostname_verification: false
@@ -35,9 +35,9 @@ plugins.security.authcz.admin_dn:
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.nodes_dn:
- "CN=wazuh1-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh2-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh3-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh1.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh2.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh3.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=filebeat,OU=Docu,O=Wazuh,L=California,C=US"
plugins.security.restapi.roles_enabled:
- "all_access"
@@ -46,3 +46,4 @@ plugins.security.allow_default_init_securityindex: true
cluster.routing.allocation.disk.threshold_enabled: false
opendistro_security.audit.config.disabled_rest_categories: NONE
opendistro_security.audit.config.disabled_transport_categories: NONE
compatibility.override_main_response_version: true
@@ -1,14 +1,14 @@
network.host: wazuh2-indexer
node.name: wazuh2-indexer
network.host: wazuh2.indexer
node.name: wazuh2.indexer
cluster.initial_master_nodes:
- wazuh1-indexer
- wazuh2-indexer
- wazuh3-indexer
- wazuh1.indexer
- wazuh2.indexer
- wazuh3.indexer
cluster.name: "wazuh-cluster"
discovery.seed_hosts:
- wazuh1-indexer
- wazuh2-indexer
- wazuh3-indexer
- wazuh1.indexer
- wazuh2.indexer
- wazuh3.indexer
http.port: 9700-9799
transport.tcp.port: 9800-9899
node.max_local_storage_nodes: "3"
@@ -20,11 +20,11 @@ path.logs: /var/log/wazuh-indexer
# Please change on production cluster! #
# #
###############################################################################
plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh2-indexer.pem
plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh2-indexer.key
plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh2.indexer.pem
plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh2.indexer.key
plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh2-indexer.pem
plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh2-indexer.key
plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh2.indexer.pem
plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh2.indexer.key
plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.http.enabled: true
plugins.security.ssl.transport.enforce_hostname_verification: false
@@ -35,9 +35,9 @@ plugins.security.authcz.admin_dn:
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.nodes_dn:
- "CN=wazuh1-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh2-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh3-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh1.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh2.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh3.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=filebeat,OU=Docu,O=Wazuh,L=California,C=US"
plugins.security.restapi.roles_enabled:
- "all_access"
@@ -45,4 +45,5 @@ plugins.security.restapi.roles_enabled:
plugins.security.allow_default_init_securityindex: true
cluster.routing.allocation.disk.threshold_enabled: false
opendistro_security.audit.config.disabled_rest_categories: NONE
opendistro_security.audit.config.disabled_transport_categories: NONE
opendistro_security.audit.config.disabled_transport_categories: NONE
compatibility.override_main_response_version: true
@@ -1,14 +1,14 @@
network.host: wazuh3-indexer
node.name: wazuh3-indexer
network.host: wazuh3.indexer
node.name: wazuh3.indexer
cluster.initial_master_nodes:
- wazuh1-indexer
- wazuh2-indexer
- wazuh3-indexer
- wazuh1.indexer
- wazuh2.indexer
- wazuh3.indexer
cluster.name: "wazuh-cluster"
discovery.seed_hosts:
- wazuh1-indexer
- wazuh2-indexer
- wazuh3-indexer
- wazuh1.indexer
- wazuh2.indexer
- wazuh3.indexer
http.port: 9700-9799
transport.tcp.port: 9800-9899
node.max_local_storage_nodes: "3"
@@ -20,11 +20,11 @@ path.logs: /var/log/wazuh-indexer
# Please change on production cluster! #
# #
###############################################################################
plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh3-indexer.pem
plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh3-indexer.key
plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh3.indexer.pem
plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh3.indexer.key
plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh3-indexer.pem
plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh3-indexer.key
plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh3.indexer.pem
plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh3.indexer.key
plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.http.enabled: true
plugins.security.ssl.transport.enforce_hostname_verification: false
@@ -35,9 +35,9 @@ plugins.security.authcz.admin_dn:
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.nodes_dn:
- "CN=wazuh1-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh2-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh3-indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh1.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh2.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=wazuh3.indexer,OU=Docu,O=Wazuh,L=California,C=US"
- "CN=filebeat,OU=Docu,O=Wazuh,L=California,C=US"
plugins.security.restapi.roles_enabled:
- "all_access"
@@ -45,4 +45,5 @@ plugins.security.restapi.roles_enabled:
plugins.security.allow_default_init_securityindex: true
cluster.routing.allocation.disk.threshold_enabled: false
opendistro_security.audit.config.disabled_rest_categories: NONE
opendistro_security.audit.config.disabled_transport_categories: NONE
opendistro_security.audit.config.disabled_transport_categories: NONE
compatibility.override_main_response_version: true
@@ -0,0 +1,14 @@
server.host: 0.0.0.0
server.port: 5601
opensearch.hosts: https://wazuh1.indexer:9700
opensearch.ssl.verificationMode: certificate
opensearch.username: kibanaserver
opensearch.password: kibanaserver
opensearch.requestHeadersWhitelist: ["securitytenant","Authorization"]
opensearch_security.multitenancy.enabled: false
opensearch_security.readonly_mode.roles: ["kibana_read_only"]
server.ssl.enabled: true
server.ssl.key: "/etc/wazuh-dashboard/certs/wazuh-dashboard-key.pem"
server.ssl.certificate: "/etc/wazuh-dashboard/certs/wazuh-dashboard.pem"
opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
uiSettings.overrides.defaultRoute: /app/wazuh?security_tenant=global
@@ -0,0 +1 @@
{"name":"Wazuh App","app-version":"4.3.0","revision":"4301-0","installationDate":"2022-02-10T13:49:45.182Z","lastRestart":"2022-02-10T13:49:45.182Z","hosts":{"default":{"cluster_info":{"status":"enabled","manager":"wazuh.master","node":"manager","cluster":"wazuh"},"extensions":{"pci":true,"gdpr":true,"hipaa":true,"nist":true,"tsc":true,"audit":true,"oscap":false,"ciscat":false,"aws":false,"office":false,"github":false,"gcp":false,"virustotal":false,"osquery":false,"docker":false}}}}
@@ -0,0 +1,8 @@
hosts:
- default:
url: https://wazuh.master
port: 55000
username: acme-user
password: MyS3cr37P450r.*-
run_as: false
@@ -0,0 +1,38 @@
info: 2022/02/10 13:49:44: initialize: Kibana index: .kibana
info: 2022/02/10 13:49:44: initialize: App revision: 4301-0
info: 2022/02/10 13:49:44: initialize: Total RAM: 11928MB
error: 2022/02/10 13:49:45: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check
error: 2022/02/10 13:55:0: cron-scheduler|SaveDocument: resource_already_exists_exception
info: 2022/02/10 18:35:47: initialize: Kibana index: .kibana
info: 2022/02/10 18:35:47: initialize: App revision: 4301-0
info: 2022/02/10 18:35:47: initialize: Total RAM: 11928MB
error: 2022/02/10 18:35:47: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check
error: 2022/02/10 18:40:0: cron-scheduler|SaveDocument: resource_already_exists_exception
info: 2022/02/10 18:42:13: initialize: Kibana index: .kibana
info: 2022/02/10 18:42:13: initialize: App revision: 4301-0
info: 2022/02/10 18:42:13: initialize: Total RAM: 11928MB
error: 2022/02/10 18:42:14: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check
error: 2022/02/10 18:45:0: cron-scheduler|SaveDocument: resource_already_exists_exception
info: 2022/02/10 20:23:3: initialize: Kibana index: .kibana
info: 2022/02/10 20:23:3: initialize: App revision: 4301-0
info: 2022/02/10 20:23:3: initialize: Total RAM: 11928MB
error: 2022/02/10 20:23:4: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check
error: 2022/02/10 20:25:0: cron-scheduler|SaveDocument: resource_already_exists_exception
info: 2022/02/11 18:48:39: initialize: Kibana index: .kibana
info: 2022/02/11 18:48:39: initialize: App revision: 4301-0
info: 2022/02/11 18:48:39: initialize: Total RAM: 11928MB
error: 2022/02/11 18:48:40: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check
error: 2022/02/11 18:50:1: cron-scheduler|SaveDocument: resource_already_exists_exception
info: 2022/02/11 19:23:22: initialize: Kibana index: .kibana
info: 2022/02/11 19:23:22: initialize: App revision: 4301-0
info: 2022/02/11 19:23:22: initialize: Total RAM: 11928MB
error: 2022/02/11 19:23:23: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check
error: 2022/02/11 19:25:0: cron-scheduler|SaveDocument: resource_already_exists_exception
info: 2022/02/11 19:27:28: initialize: Kibana index: .kibana
info: 2022/02/11 19:27:28: initialize: App revision: 4301-0
info: 2022/02/11 19:27:28: initialize: Total RAM: 11928MB
error: 2022/02/11 19:27:28: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check
info: 2022/02/11 19:31:58: initialize: Kibana index: .kibana
info: 2022/02/11 19:31:58: initialize: App revision: 4301-0
info: 2022/02/11 19:31:58: initialize: Total RAM: 11928MB
error: 2022/02/11 19:31:59: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check
@@ -0,0 +1,38 @@
{"date":"2022-02-10T13:49:44.661Z","level":"info","location":"initialize","message":"Kibana index: .kibana"}
{"date":"2022-02-10T13:49:44.661Z","level":"info","location":"initialize","message":"App revision: 4301-0"}
{"date":"2022-02-10T13:49:44.661Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"}
{"date":"2022-02-10T13:49:45.077Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"}
{"date":"2022-02-10T13:55:00.999Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"}
{"date":"2022-02-10T18:35:47.009Z","level":"info","location":"initialize","message":"Kibana index: .kibana"}
{"date":"2022-02-10T18:35:47.010Z","level":"info","location":"initialize","message":"App revision: 4301-0"}
{"date":"2022-02-10T18:35:47.010Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"}
{"date":"2022-02-10T18:35:47.242Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"}
{"date":"2022-02-10T18:40:00.559Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"}
{"date":"2022-02-10T18:42:13.894Z","level":"info","location":"initialize","message":"Kibana index: .kibana"}
{"date":"2022-02-10T18:42:13.894Z","level":"info","location":"initialize","message":"App revision: 4301-0"}
{"date":"2022-02-10T18:42:13.894Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"}
{"date":"2022-02-10T18:42:14.231Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"}
{"date":"2022-02-10T18:45:00.330Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"}
{"date":"2022-02-10T20:23:03.443Z","level":"info","location":"initialize","message":"Kibana index: .kibana"}
{"date":"2022-02-10T20:23:03.443Z","level":"info","location":"initialize","message":"App revision: 4301-0"}
{"date":"2022-02-10T20:23:03.443Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"}
{"date":"2022-02-10T20:23:04.136Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"}
{"date":"2022-02-10T20:25:00.975Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"}
{"date":"2022-02-11T18:48:39.186Z","level":"info","location":"initialize","message":"Kibana index: .kibana"}
{"date":"2022-02-11T18:48:39.187Z","level":"info","location":"initialize","message":"App revision: 4301-0"}
{"date":"2022-02-11T18:48:39.187Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"}
{"date":"2022-02-11T18:48:40.305Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"}
{"date":"2022-02-11T18:50:01.075Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"}
{"date":"2022-02-11T19:23:22.847Z","level":"info","location":"initialize","message":"Kibana index: .kibana"}
{"date":"2022-02-11T19:23:22.848Z","level":"info","location":"initialize","message":"App revision: 4301-0"}
{"date":"2022-02-11T19:23:22.848Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"}
{"date":"2022-02-11T19:23:23.646Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"}
{"date":"2022-02-11T19:25:00.244Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"}
{"date":"2022-02-11T19:27:28.476Z","level":"info","location":"initialize","message":"Kibana index: .kibana"}
{"date":"2022-02-11T19:27:28.477Z","level":"info","location":"initialize","message":"App revision: 4301-0"}
{"date":"2022-02-11T19:27:28.477Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"}
{"date":"2022-02-11T19:27:28.862Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"}
{"date":"2022-02-11T19:31:58.941Z","level":"info","location":"initialize","message":"Kibana index: .kibana"}
{"date":"2022-02-11T19:31:58.942Z","level":"info","location":"initialize","message":"App revision: 4301-0"}
{"date":"2022-02-11T19:31:58.942Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"}
{"date":"2022-02-11T19:31:59.543Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"}
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
+17 -19
View File
@@ -3,7 +3,7 @@ version: '3.7'
services:
wazuh.master:
image: wazuh/wazuh-odfe:4.3.0
image: wazuh/wazuh-odfe:4.3.0-dev
hostname: wazuh.master
restart: always
ports:
@@ -11,9 +11,9 @@ services:
- "514:514/udp"
- "55000:55000"
environment:
- ELASTICSEARCH_URL=https://wazuh.indexer:9700
- ELASTICSEARCH_URL=https://wazuh1.indexer:9700
- ELASTIC_USERNAME=admin
- ELASTIC_PASSWORD=admin
- ELASTIC_PASSWORD=SecretPassword
- FILEBEAT_SSL_VERIFICATION_MODE=full
- SSL_CERTIFICATE_AUTHORITIES=/etc/ssl/root-ca.pem
- SSL_CERTIFICATE=/etc/ssl/filebeat.pem
@@ -38,13 +38,13 @@ services:
- ./production_cluster/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf
wazuh.worker:
image: wazuh/wazuh-odfe:4.3.0
image: wazuh/wazuh-odfe:4.3.0-dev
hostname: wazuh.worker
restart: always
environment:
- ELASTICSEARCH_URL=https://wazuh.indexer:9700
- ELASTICSEARCH_URL=https://wazuh1.indexer:9700
- ELASTIC_USERNAME=admin
- ELASTIC_PASSWORD=admin
- ELASTIC_PASSWORD=SecretPassword
- FILEBEAT_SSL_VERIFICATION_MODE=full
- SSL_CERTIFICATE_AUTHORITIES=/etc/ssl/root-ca.pem
- SSL_CERTIFICATE=/etc/ssl/filebeat.pem
@@ -67,7 +67,7 @@ services:
- ./production_cluster/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf
wazuh1.indexer:
image: test-indexer
image: wazuh/wazuh-indexer:4.3.0
hostname: wazuh1.indexer
restart: always
ports:
@@ -93,7 +93,7 @@ services:
- ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/internal_users.yml
wazuh2.indexer:
image: test-indexer
image: wazuh/wazuh-indexer:4.3.0
hostname: wazuh2.indexer
restart: always
environment:
@@ -112,10 +112,10 @@ services:
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh2.indexer-key.pem:/etc/wazuh-indexer/certs/wazuh2.indexer.key
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh2.indexer.pem:/etc/wazuh-indexer/certs/wazuh2.indexer.pem
- ./production_cluster/wazuh-indexer/wazuh2.indexer.yml:/etc/wazuh-indexer/opensearch.yml
- ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml
- ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/internal_users.yml
wazuh3.indexer:
image: test-indexer
image: wazuh/wazuh-indexer:4.3.0
hostname: wazuh3.indexer
restart: always
environment:
@@ -134,7 +134,7 @@ services:
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh3.indexer-key.pem:/etc/wazuh-indexer/certs/wazuh3.indexer.key
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh3.indexer.pem:/etc/wazuh-indexer/certs/wazuh3.indexer.pem
- ./production_cluster/wazuh-indexer/wazuh3.indexer.yml:/etc/wazuh-indexer/opensearch.yml
- ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml
- ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/internal_users.yml
wazuh.dashboard:
image: wazuh/wazuh-dashboard:4.3.0
@@ -143,18 +143,16 @@ services:
ports:
- 5601:5601
environment:
- ELASTICSEARCH_USERNAME=admin
- ELASTICSEARCH_PASSWORD=admin
- SERVER_SSL_ENABLED=true
- SERVER_SSL_CERTIFICATE=/etc/wazuh-dashboard/certs/cert.pem
- SERVER_SSL_KEY=/etc/wazuh-dashboard/certs/key.pem
- OPENSEARCH_HOSTS="https://wazuh1.indexer:9700"
- WAZUH_API_URL="https://wazuh.master"
- API_USERNAME=acme-user
- API_PASSWORD=MyS3cr37P450r.*-
volumes:
- ./production_cluster/wazuh_dashboard_ssl/cert.pem:/etc/wazuh-dashboard/certs/cert.pem
- ./production_cluster/wazuh_dashboard_ssl/key.pem:/etc/wazuh-dashboard/certs/key.pem
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh.dashboard.pem:/etc/wazuh-dashboard/certs/wazuh-dashboard.pem
- ./production_cluster/wazuh_indexer_ssl_certs/wazuh.dashboard-key.pem:/etc/wazuh-dashboard/certs/wazuh-dashboard-key.pem
- ./production_cluster/wazuh_indexer_ssl_certs/root-ca.pem:/etc/wazuh-dashboard/certs/root-ca.pem
- ./production_cluster/wazuh_dashboard/dashboard.yml:/etc/wazuh-dashboard/dashboard.yml
- ./production_cluster/wazuh_dashboard/wazuh:/usr/share/wazuh-dashboard/data/wazuh
depends_on:
- wazuh1.indexer
links:
+8
View File
@@ -13,8 +13,16 @@ RUN curl https://s3.us-west-1.amazonaws.com/packages-dev.wazuh.com/pre-release/a
COPY config/entrypoint.sh /
COPY config/wazuh_app_config.sh /
COPY config/dashboard.yml /etc/wazuh-dashboard/
RUN chmod 700 /entrypoint.sh
RUN chmod 700 /wazuh_app_config.sh
RUN chown 101:101 /etc/wazuh-dashboard/dashboard.yml && chmod 664 /etc/wazuh-dashboard/dashboard.yml
# Services ports
EXPOSE 5601
+14
View File
@@ -0,0 +1,14 @@
server.host: 0.0.0.0
server.port: 5601
opensearch.hosts: https://wazuh1.indexer:9700
opensearch.ssl.verificationMode: certificate
opensearch.username: kibanaserver
opensearch.password: kibanaserver
opensearch.requestHeadersWhitelist: ["securitytenant","Authorization"]
opensearch_security.multitenancy.enabled: false
opensearch_security.readonly_mode.roles: ["kibana_read_only"]
server.ssl.enabled: false
server.ssl.key: "/etc/wazuh-dashboard/certs/demo-dashboard-key.pem"
server.ssl.certificate: "/etc/wazuh-dashboard/certs/demo-dashboard.pem"
opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"]
uiSettings.overrides.defaultRoute: /app/wazuh?security_tenant=global
+1 -3
View File
@@ -5,8 +5,6 @@
# Start Wazuh dashboard
##############################################################################
sed -i 's/localhost:9700/wazuh-indexer:9700/' /etc/wazuh-dashboard/dashboard.yml
sed -i 's/<wazuh-dashboard-ip>/0.0.0.0/' /etc/wazuh-dashboard/dashboard.yml
sed -i '/logging.dest:/d' /etc/wazuh-dashboard/dashboard.yml
#/wazuh_app_config.sh
runuser wazuh-dashboard --shell="/bin/bash" --command="/usr/share/wazuh-dashboard/bin/opensearch-dashboards -c /etc/wazuh-dashboard/dashboard.yml"
+1 -47
View File
@@ -6,51 +6,8 @@ wazuh_port="${API_PORT:-55000}"
api_username="${API_USERNAME:-wazuh-wui}"
api_password="${API_PASSWORD:-wazuh-wui}"
kibana_config_file="/etc/wazuh-dashboard/wazuh-dashboard.yml"
kibana_config_file="/usr/share/wazuh-dashboard/data/wazuh/config/wazuh.yml"
sed 's/9700/9200/' /etc/wazuh-dashboard/wazuh-dashboard.yml
declare -A CONFIG_MAP=(
[pattern]=$PATTERN
[checks.pattern]=$CHECKS_PATTERN
[checks.template]=$CHECKS_TEMPLATE
[checks.api]=$CHECKS_API
[checks.setup]=$CHECKS_SETUP
[extensions.pci]=$EXTENSIONS_PCI
[extensions.gdpr]=$EXTENSIONS_GDPR
[extensions.hipaa]=$EXTENSIONS_HIPAA
[extensions.nist]=$EXTENSIONS_NIST
[extensions.tsc]=$EXTENSIONS_TSC
[extensions.audit]=$EXTENSIONS_AUDIT
[extensions.oscap]=$EXTENSIONS_OSCAP
[extensions.ciscat]=$EXTENSIONS_CISCAT
[extensions.aws]=$EXTENSIONS_AWS
[extensions.gcp]=$EXTENSIONS_GCP
[extensions.virustotal]=$EXTENSIONS_VIRUSTOTAL
[extensions.osquery]=$EXTENSIONS_OSQUERY
[extensions.docker]=$EXTENSIONS_DOCKER
[timeout]=$APP_TIMEOUT
[api.selector]=$API_SELECTOR
[ip.selector]=$IP_SELECTOR
[ip.ignore]=$IP_IGNORE
[wazuh.monitoring.enabled]=$WAZUH_MONITORING_ENABLED
[wazuh.monitoring.creation]=$WAZUH_MONITORING_CREATION
[wazuh.monitoring.frequency]=$WAZUH_MONITORING_FREQUENCY
[wazuh.monitoring.shards]=$WAZUH_MONITORING_SHARDS
[wazuh.monitoring.replicas]=$WAZUH_MONITORING_REPLICAS
[admin]=$ADMIN_PRIVILEGES
)
for i in "${!CONFIG_MAP[@]}"
do
if [ "${CONFIG_MAP[$i]}" != "" ]; then
sed -i 's/.*#'"$i"'.*/'"$i"': '"${CONFIG_MAP[$i]}"'/' $kibana_config_file
fi
done
CONFIG_CODE=$(curl ${auth} -s -o /dev/null -w "%{http_code}" -XGET $el_url/.wazuh/_doc/1513629884013)
if [[ "x$CONFIG_CODE" != "x200" ]] && ! grep -q 1513629884013 $kibana_config_file ; then
cat << EOF >> $kibana_config_file
hosts:
- 1513629884013:
@@ -59,6 +16,3 @@ hosts:
username: $api_username
password: $api_password
EOF
else
echo "Wazuh APP already configured"
fi
+6 -3
View File
@@ -52,7 +52,9 @@ WORKDIR $INSTALL_DIR
COPY config/entrypoint.sh /
RUN chmod 700 /entrypoint.sh
COPY config/securityadmin.sh /
RUN chmod 700 /entrypoint.sh && chmod 700 /securityadmin.sh
COPY --from=builder --chown=1000:1000 /debian/wazuh-indexer/usr/share/wazuh-indexer /usr/share/wazuh-indexer
COPY --from=builder --chown=0:0 /tini /tini
@@ -60,7 +62,9 @@ COPY --from=builder --chown=0:0 /debian/wazuh-indexer/etc/init.d/wazuh-indexer /
COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/systemd /usr/lib/systemd
COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/sysctl.d /usr/lib/sysctl.d
COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/tmpfiles.d /usr/lib/tmpfiles.d
COPY --from=builder --chown=1000:10000 /debian/wazuh-indexer/etc/wazuh-indexer /etc/wazuh-indexer
COPY --from=builder --chown=1000:1000 /debian/wazuh-indexer/etc/wazuh-indexer /etc/wazuh-indexer
COPY config/opensearch.yml /etc/wazuh-indexer/
RUN chmod 660 /etc/wazuh-indexer/opensearch.yml && chown 1000:1000 /etc/wazuh-indexer/opensearch.yml
RUN mkdir -p /var/lib/wazuh-indexer && chown 1000:1000 /var/lib/wazuh-indexer && \
mkdir -p /usr/share/wazuh-indexer/logs && chown 1000:1000 /usr/share/wazuh-indexer/logs && \
@@ -70,7 +74,6 @@ RUN mkdir -p /var/lib/wazuh-indexer && chown 1000:1000 /var/lib/wazuh-indexer &&
# Services ports
EXPOSE 9700
#ENTRYPOINT [ "/entrypoint.sh" ]
ENTRYPOINT ["/tini", "--", "/entrypoint.sh"]
# Dummy overridable parameter parsed by entrypoint
+9 -3
View File
@@ -8,7 +8,10 @@ export USER=wazuh-indexer
export INSTALLATION_DIR=/usr/share/wazuh-indexer
export OPENSEARCH_PATH_CONF=/etc/wazuh-indexer
export JAVA_HOME=${INSTALLATION_DIR}/jdk
export FILE=${INSTALLATION_DIR}/start
export DISCOVERY=$(grep -oP "(?<=discovery.type: ).*" /etc/wazuh-indexer/opensearch.yml)
export CACERT=$(grep -oP "(?<=plugins.security.ssl.transport.pemtrustedcas_filepath: ).*" /etc/wazuh-indexer/opensearch.yml)
export CERT="/etc/wazuh-indexer/certs/admin.pem"
export KEY="/etc/wazuh-indexer/certs/admin-key.pem"
run_as_other_user_if_needed() {
if [[ "$(id -u)" == "0" ]]; then
@@ -26,8 +29,6 @@ run_as_other_user_if_needed() {
# or simply to run /bin/bash to check the image
if [[ "$1" != "opensearchwrapper" ]]; then
if [[ "$(id -u)" == "0" && $(basename "$1") == "opensearch" ]]; then
# centos:7 chroot doesn't have the `--skip-chdir` option and
# changes our CWD.
# Rewrite CMD args to replace $1 with `opensearch` explicitly,
# so that we are backwards compatible with the docs
# from the previous Elasticsearch versions<6
@@ -86,4 +87,9 @@ if [[ "$(id -u)" == "0" ]]; then
fi
fi
if [[ "$DISCOVERY" == "single-node" ]]; then
# run securityadmin.sh for single node
nohup /securityadmin.sh &
fi
run_as_other_user_if_needed /usr/share/wazuh-indexer/bin/opensearch <<<"$KEYSTORE_PASSWORD"
+36
View File
@@ -0,0 +1,36 @@
network.host: "0.0.0.0"
node.name: "wazuh1.indexer"
http.port: 9700-9799
transport.tcp.port: 9800-9899
path.data: /var/lib/wazuh-indexer
path.logs: /var/log/wazuh-indexer
discovery.type: single-node
compatibility.override_main_response_version: true
###############################################################################
# #
# WARNING: Insecure demo certificates set up in this file. #
# Please change on production cluster! #
# #
###############################################################################
plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/demo-indexer.pem
plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/demo-indexer-key.pem
plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/demo-indexer.pem
plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/demo-indexer-key.pem
plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem
plugins.security.ssl.http.enabled: true
plugins.security.ssl.transport.enforce_hostname_verification: false
plugins.security.ssl.transport.resolve_hostname: false
plugins.security.audit.type: internal_opensearch
plugins.security.authcz.admin_dn:
- "CN=admin,OU=Demo,O=Wazuh,L=California,C=US"
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.nodes_dn:
- "CN=demo-indexer,OU=Demo,O=Wazuh,L=California,C=US"
plugins.security.restapi.roles_enabled:
- "all_access"
- "security_rest_api_access"
plugins.security.system_indices.enabled: true
plugins.security.system_indices.indices: [".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opendistro-notifications-*", ".opendistro-notebooks", ".opensearch-observability", ".opendistro-asynchronous-search-response*", ".replication-metadata-store"]
+2
View File
@@ -0,0 +1,2 @@
sleep 50
bash /usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh -cd /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/ -nhnv -cacert $CACERT -cert $CERT -key $KEY -p 9800 -icl
+2 -2
View File
@@ -3,12 +3,12 @@ FROM centos:7
ARG FILEBEAT_CHANNEL=filebeat-oss
ARG FILEBEAT_VERSION=7.10.2
ARG WAZUH_VERSION=4.2.5-1
ARG WAZUH_VERSION=4.3.0-1
ARG TEMPLATE_VERSION="master"
ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.1.tar.gz"
# Set repositories.
RUN rpm --import https://packages.wazuh.com/key/GPG-KEY-WAZUH
RUN rpm --import https://packages-dev.wazuh.com/key/GPG-KEY-WAZUH
COPY config/wazuh.repo /etc/yum.repos.d/wazuh.repo
+5
View File
@@ -13,6 +13,7 @@ SPECIAL_CHARS = "@$!%*?&-_"
try:
from wazuh.rbac.orm import create_rbac_db
from wazuh.security import (
create_user,
get_users,
@@ -66,6 +67,10 @@ if __name__ == "__main__":
# abort if no user file detected
sys.exit(0)
username, password = read_user_file()
# create RBAC database
create_rbac_db()
initial_users = db_users()
if username not in initial_users:
# create a new user
+2 -2
View File
@@ -1,7 +1,7 @@
[wazuh_repo]
gpgcheck=1
gpgkey=https://packages.wazuh.com/key/GPG-KEY-WAZUH
gpgkey=https://packages-dev.wazuh.com/key/GPG-KEY-WAZUH
enabled=1
name=Wazuh repository
baseurl=https://packages.wazuh.com/4.x/yum/
baseurl=https://packages-dev.wazuh.com/pre-release/yum/
protect=1