diff --git a/docker-compose.yml b/docker-compose.yml index 58513581..5ce264b9 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -12,7 +12,7 @@ services: - "514:514/udp" - "55000:55000" environment: - - ELASTICSEARCH_URL=https://wazuh-indexer:9700 + - ELASTICSEARCH_URL=https://wazuh1.indexer:9700 - ELASTIC_USERNAME=admin - ELASTIC_PASSWORD=admin - FILEBEAT_SSL_VERIFICATION_MODE=none @@ -29,19 +29,14 @@ services: - filebeat_etc:/etc/filebeat - filebeat_var:/var/lib/filebeat - wazuh-indexer: - image: test-indexer - hostname: node1 + wazuh1.indexer: + image: wazuh/wazuh-indexer:4.3.0 + hostname: wazuh1.indexer restart: always ports: - "9700:9700" environment: - - discovery.type=single-node - - cluster.name=wazuh-cluster - - network.host=0.0.0.0 - - plugins.security.allow_default_init_securityindex=true - "OPENSEARCH_JAVA_OPTS=-Xms512m -Xmx512m" - - bootstrap.memory_lock=true ulimits: memlock: soft: -1 @@ -50,9 +45,9 @@ services: soft: 65536 hard: 65536 - kibana: + wazuh.dashboard: image: wazuh/wazuh-dashboard:4.3.0 - hostname: kibana + hostname: wazuh.dashboard restart: always ports: - 5601:5601 @@ -61,12 +56,8 @@ services: - ELASTICSEARCH_USERNAME=admin - ELASTICSEARCH_PASSWORD=admin - SERVER_SSL_ENABLED=false - - depends_on: - - wazuh-indexer - links: - - wazuh-indexer:wazuh-indexer - - wazuh:wazuh + #volumes: + # - ./production_cluster/wazuh_dashboard/dashboard.yml:/etc/wazuh-dashboard/dashboard.yml volumes: ossec_api_configuration: diff --git a/kibana-odfe/Dockerfile b/kibana-odfe/Dockerfile index 3cad99ba..23f897d8 100644 --- a/kibana-odfe/Dockerfile +++ b/kibana-odfe/Dockerfile @@ -6,7 +6,7 @@ ARG WAZUH_VERSION=4.2.5 ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}" WORKDIR /usr/share/kibana -RUN ./bin/kibana-plugin install https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana-${WAZUH_APP_VERSION}-1.zip +RUN ./bin/kibana-plugin install https://packages-dev.wazuh.com/pre-release/ui/kibana/wazuh_kibana-${WAZUH_APP_VERSION}-1.zip WORKDIR / USER root diff --git a/kibana/Dockerfile b/kibana/Dockerfile index d98443ae..76f39d0d 100644 --- a/kibana/Dockerfile +++ b/kibana/Dockerfile @@ -6,7 +6,7 @@ ARG WAZUH_VERSION=4.3.0 ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}" WORKDIR /usr/share/kibana -RUN ./bin/kibana-plugin install https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana-${WAZUH_APP_VERSION}-1.zip +RUN ./bin/kibana-plugin install https://packages-dev.wazuh.com/pre-release/ui/kibana/wazuh_kibana-${WAZUH_APP_VERSION}-1.zip ENV PATTERN="" \ CHECKS_PATTERN="" \ diff --git a/production_cluster/nginx/nginx.conf b/production_cluster/nginx/nginx.conf index 8cd13ca2..c68c6f2d 100644 --- a/production_cluster/nginx/nginx.conf +++ b/production_cluster/nginx/nginx.conf @@ -41,7 +41,7 @@ http { ssl_certificate /etc/nginx/ssl/cert.pem; ssl_certificate_key /etc/nginx/ssl/key.pem; location / { - proxy_pass https://kibana:5601/; + proxy_pass https://wazuh.dashboard:5601/; proxy_ssl_verify off; proxy_buffer_size 128k; proxy_buffers 4 256k; @@ -57,8 +57,8 @@ http { stream { upstream mycluster { hash $remote_addr consistent; - server wazuh-master:1514; - server wazuh-worker:1514; + server wazuh.master:1514; + server wazuh.worker:1514; } server { listen 1514; diff --git a/production_cluster/nginx/ssl/cert.pem b/production_cluster/nginx/ssl/cert.pem new file mode 100644 index 00000000..d5bbb656 --- /dev/null +++ b/production_cluster/nginx/ssl/cert.pem @@ -0,0 +1,21 @@ +-----BEGIN CERTIFICATE----- +MIIDazCCAlOgAwIBAgIUASe6vu/ElSX7Znaz3NfI/zM6QCEwDQYJKoZIhvcNAQEL +BQAwRTELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoM +GEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMjAyMDgxMjMxNDlaFw0yMzAy +MDgxMjMxNDlaMEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEw +HwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwggEiMA0GCSqGSIb3DQEB +AQUAA4IBDwAwggEKAoIBAQC36B2fAApuF7OjzvGDGfhOSDoKsemyCCRfQ7ErJXhJ +/aaFyBFmnRpwHWKRm/a+rcjFc2EEFxW6rkwHScoMCkpPPJMuxOw3xd1YKy/hy//e +4L67iAdc2yNlXmkANMUPQldJn2RFf7JSVEMGMLhvEQsIKQ0AKqBaytS+2Cr7ciHv +g1VxNAXvJkyYruEPIuHr9WvZ/BgmxCcI5IM4yLXSLbpbUqajQCAWa/HlDEO0729t +kF8dSJYLrz9kt2dnCgupw4iHCwYH+VjUEOAfAucF8Uj5u13GdovaodRxwftHG3TV +quZCYK77V/lJNOq0eUmZ33r1VvH1VZsAhThX4GV5auULAgMBAAGjUzBRMB0GA1Ud +DgQWBBRAa37ztZ4A+bZ+rO2DmUp5Ew7Q2TAfBgNVHSMEGDAWgBRAa37ztZ4A+bZ+ +rO2DmUp5Ew7Q2TAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQB0 +9qCMnym11g3NUNksnCtrHOo8r5DKU9KPISFOtG03Syxe7K9xi3oOYqaiZPJezoSl +7Z9O6Sobwgah+MtwZ5/9+jsxPgmEcpE6SWYx6KcG44TrC7RToIX7JyILxJujqJT2 +LODBmHO2IMGi9htaV8WDqwDKTqtBsmi9VdSOVy1WOsP9lcJoO2Di4cPS5RJjdDAW +sJNAFK+tGv0ZcUZ5bunjIGTEUIAElSPE/LTzuox2R4gVdWx0QYnKLn945C7Blr5d +tPR6EOI/4n5X7nq4XnX60dTAVS8ybZcUHTmHV9bz+KBu08jFn6Aum8mhYm1iFKKL +3P6t5XsQAQMTR37HAhLW +-----END CERTIFICATE----- diff --git a/production_cluster/nginx/ssl/key.pem b/production_cluster/nginx/ssl/key.pem new file mode 100644 index 00000000..5dc0986b --- /dev/null +++ b/production_cluster/nginx/ssl/key.pem @@ -0,0 +1,28 @@ +-----BEGIN PRIVATE KEY----- +MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQC36B2fAApuF7Oj +zvGDGfhOSDoKsemyCCRfQ7ErJXhJ/aaFyBFmnRpwHWKRm/a+rcjFc2EEFxW6rkwH +ScoMCkpPPJMuxOw3xd1YKy/hy//e4L67iAdc2yNlXmkANMUPQldJn2RFf7JSVEMG +MLhvEQsIKQ0AKqBaytS+2Cr7ciHvg1VxNAXvJkyYruEPIuHr9WvZ/BgmxCcI5IM4 +yLXSLbpbUqajQCAWa/HlDEO0729tkF8dSJYLrz9kt2dnCgupw4iHCwYH+VjUEOAf +AucF8Uj5u13GdovaodRxwftHG3TVquZCYK77V/lJNOq0eUmZ33r1VvH1VZsAhThX +4GV5auULAgMBAAECggEAScmo8N28UZXS7tueTULDPO1/1EC0Ckl4Bn0LfctH6zAJ +e03dpXVNYUR5AwE3zCPAFXEIsPJuNnuuZ5I0rgYG8KnWSAKc4HfUKocRbCBEpnE4 +NdgLVDdciVSK/pkto8Szbwez3KqyqpPCXJ55sZ599aU64SE5O5R8LaJgBIkzknxK +J2cS6W7M15nwpgmhS5NlXDnykaDa8lPTccqqPF2b1HAgup2Lfg/HIq5U6kB6O87R +mQGd1ZZ13CxNJP6qWfSK34B1novabkOhy6vlfE2HT8uggxjR7B1u++Lr/jccduNY +Mvm9kILWwxrmPNOqt9OJLZYxlKTcsaIZvDuin47hSQKBgQDixjQXGD9bcMyy1z9k +7I98HcEoy3CbXq1zNxaZw4N4zEttVUHexbBs/UDYGXU+O4hRYxmPChKHdTQ4KzWx +RPTNnnzPTsHl6W+a2XS8MnoiF1yMUuE0IwThkS4OlEVakS1I+pyOEQxh0R93KBrW +LFRkBjMDAv7uB+TtXJNpNfRVLwKBgQDPm515DVjO1+MwzGni4TD8EvZl0KWkHASO +VLh8eDOTe+1dPdlHJp98+eOCp+BzfiKFYXDXmeoaZ+wBbyNxRr6ofPGVtHEGp4zp +pWp8BQ8Uw1LojpZB8uji2+LaX+qb7W+dFR8kbWbjTQkuWYU2jjk7WqreUdTnxRtb +sc/nE6fu5QKBgEgiwkkiZm0A6axt+fVxpobVtC703+IccNI4kNDit3yCh+/Ecgqa +Ge/hc3IKTxg3uboh6uxsSM6cArtnS1ITXEfYBV2wcM9gvSaly5Nd/ym/AqqEZqy+ +Avx5wQvUMGeJzLztM0WhuK2Y5whxUnAUc9fJfQqVNmCjVDgI/b828XzzAoGBAL0N +CR41sDxTTZifXID07eVt4yCeGmhR9zghIAqAbv8Lp//zlUt8eVmWOL4+315sa0Uo +kVhT2WGIZtp7eTvq3y2Q8XGQ6ifUJbaSImCjPrN6lqIdTejqKXaEI5UWKQ8q7SuP +E1fZpAqymPyzGmKuqqFJFDX1MLqJvDsItbjIJnGdAoGAWnLU4S2CzgtiOeFiKKU9 +P+nhTplGV/DH0dMnVa5hZeIP3UDpzR19aQ9OXdRv30M3eSQnIRcL3A/Gci8fSmx/ +/5nJp1hoEwL2oawyRcEU6A5djT7zZ0m2+gteu9QLBiq3YlqmJUVKaviIUC4Se7ZP +TrRYjCtxO5XdtyZGZxVrTQk= +-----END PRIVATE KEY----- diff --git a/production_cluster/wazuh-indexer/opensearch.yml b/production_cluster/wazuh-indexer/opensearch.yml new file mode 100644 index 00000000..bfd2aba6 --- /dev/null +++ b/production_cluster/wazuh-indexer/opensearch.yml @@ -0,0 +1,36 @@ +network.host: "0.0.0.0" +node.name: "wazuh1.indexer" +http.port: 9700-9799 +transport.tcp.port: 9800-9899 +path.data: /var/lib/wazuh-indexer +path.logs: /var/log/wazuh-indexer +discovery.type: single-node +compatibility.override_main_response_version: true +############################################################################### +# # +# WARNING: Insecure demo certificates set up in this file. # +# Please change on production cluster! # +# # +############################################################################### +plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/admin.pem +plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/admin-key.pem +plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem +plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/admin.pem +plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/admin-key.pem +plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem +plugins.security.ssl.http.enabled: true +plugins.security.ssl.transport.enforce_hostname_verification: false +plugins.security.ssl.transport.resolve_hostname: false +plugins.security.audit.type: internal_opensearch +plugins.security.authcz.admin_dn: +- "CN=admin,OU=Demo,O=Wazuh,L=California,C=US" +plugins.security.check_snapshot_restore_write_privileges: true +plugins.security.enable_snapshot_restore_privilege: true +plugins.security.nodes_dn: +- "CN=demo-indexer,OU=Demo,O=Wazuh,L=California,C=US" +plugins.security.restapi.roles_enabled: +- "all_access" +- "security_rest_api_access" +plugins.security.system_indices.enabled: true +plugins.security.system_indices.indices: [".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opendistro-notifications-*", ".opendistro-notebooks", ".opensearch-observability", ".opendistro-asynchronous-search-response*", ".replication-metadata-store"] + diff --git a/production_cluster/wazuh-indexer/wazuh1.indexer.yml b/production_cluster/wazuh-indexer/wazuh1.indexer.yml index 35241b9a..d4860983 100644 --- a/production_cluster/wazuh-indexer/wazuh1.indexer.yml +++ b/production_cluster/wazuh-indexer/wazuh1.indexer.yml @@ -1,14 +1,14 @@ -network.host: wazuh1-indexer -node.name: wazuh1-indexer +network.host: wazuh1.indexer +node.name: wazuh1.indexer cluster.initial_master_nodes: - - wazuh1-indexer - - wazuh2-indexer - - wazuh3-indexer + - wazuh1.indexer + - wazuh2.indexer + - wazuh3.indexer cluster.name: "wazuh-cluster" discovery.seed_hosts: - - wazuh1-indexer - - wazuh2-indexer - - wazuh3-indexer + - wazuh1.indexer + - wazuh2.indexer + - wazuh3.indexer http.port: 9700-9799 transport.tcp.port: 9800-9899 node.max_local_storage_nodes: "3" @@ -20,11 +20,11 @@ path.logs: /var/log/wazuh-indexer # Please change on production cluster! # # # ############################################################################### -plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh1-indexer.pem -plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh1-indexer.key +plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh1.indexer.pem +plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh1.indexer.key plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem -plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh1-indexer.pem -plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh1-indexer.key +plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh1.indexer.pem +plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh1.indexer.key plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem plugins.security.ssl.http.enabled: true plugins.security.ssl.transport.enforce_hostname_verification: false @@ -35,9 +35,9 @@ plugins.security.authcz.admin_dn: plugins.security.check_snapshot_restore_write_privileges: true plugins.security.enable_snapshot_restore_privilege: true plugins.security.nodes_dn: -- "CN=wazuh1-indexer,OU=Docu,O=Wazuh,L=California,C=US" -- "CN=wazuh2-indexer,OU=Docu,O=Wazuh,L=California,C=US" -- "CN=wazuh3-indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh1.indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh2.indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh3.indexer,OU=Docu,O=Wazuh,L=California,C=US" - "CN=filebeat,OU=Docu,O=Wazuh,L=California,C=US" plugins.security.restapi.roles_enabled: - "all_access" @@ -46,3 +46,4 @@ plugins.security.allow_default_init_securityindex: true cluster.routing.allocation.disk.threshold_enabled: false opendistro_security.audit.config.disabled_rest_categories: NONE opendistro_security.audit.config.disabled_transport_categories: NONE +compatibility.override_main_response_version: true diff --git a/production_cluster/wazuh-indexer/wazuh2.indexer.yml b/production_cluster/wazuh-indexer/wazuh2.indexer.yml index 988b3d0e..a9d4aff3 100644 --- a/production_cluster/wazuh-indexer/wazuh2.indexer.yml +++ b/production_cluster/wazuh-indexer/wazuh2.indexer.yml @@ -1,14 +1,14 @@ -network.host: wazuh2-indexer -node.name: wazuh2-indexer +network.host: wazuh2.indexer +node.name: wazuh2.indexer cluster.initial_master_nodes: - - wazuh1-indexer - - wazuh2-indexer - - wazuh3-indexer + - wazuh1.indexer + - wazuh2.indexer + - wazuh3.indexer cluster.name: "wazuh-cluster" discovery.seed_hosts: - - wazuh1-indexer - - wazuh2-indexer - - wazuh3-indexer + - wazuh1.indexer + - wazuh2.indexer + - wazuh3.indexer http.port: 9700-9799 transport.tcp.port: 9800-9899 node.max_local_storage_nodes: "3" @@ -20,11 +20,11 @@ path.logs: /var/log/wazuh-indexer # Please change on production cluster! # # # ############################################################################### -plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh2-indexer.pem -plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh2-indexer.key +plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh2.indexer.pem +plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh2.indexer.key plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem -plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh2-indexer.pem -plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh2-indexer.key +plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh2.indexer.pem +plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh2.indexer.key plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem plugins.security.ssl.http.enabled: true plugins.security.ssl.transport.enforce_hostname_verification: false @@ -35,9 +35,9 @@ plugins.security.authcz.admin_dn: plugins.security.check_snapshot_restore_write_privileges: true plugins.security.enable_snapshot_restore_privilege: true plugins.security.nodes_dn: -- "CN=wazuh1-indexer,OU=Docu,O=Wazuh,L=California,C=US" -- "CN=wazuh2-indexer,OU=Docu,O=Wazuh,L=California,C=US" -- "CN=wazuh3-indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh1.indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh2.indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh3.indexer,OU=Docu,O=Wazuh,L=California,C=US" - "CN=filebeat,OU=Docu,O=Wazuh,L=California,C=US" plugins.security.restapi.roles_enabled: - "all_access" @@ -45,4 +45,5 @@ plugins.security.restapi.roles_enabled: plugins.security.allow_default_init_securityindex: true cluster.routing.allocation.disk.threshold_enabled: false opendistro_security.audit.config.disabled_rest_categories: NONE -opendistro_security.audit.config.disabled_transport_categories: NONE \ No newline at end of file +opendistro_security.audit.config.disabled_transport_categories: NONE +compatibility.override_main_response_version: true \ No newline at end of file diff --git a/production_cluster/wazuh-indexer/wazuh3.indexer.yml b/production_cluster/wazuh-indexer/wazuh3.indexer.yml index 7024a8da..57e92e55 100644 --- a/production_cluster/wazuh-indexer/wazuh3.indexer.yml +++ b/production_cluster/wazuh-indexer/wazuh3.indexer.yml @@ -1,14 +1,14 @@ -network.host: wazuh3-indexer -node.name: wazuh3-indexer +network.host: wazuh3.indexer +node.name: wazuh3.indexer cluster.initial_master_nodes: - - wazuh1-indexer - - wazuh2-indexer - - wazuh3-indexer + - wazuh1.indexer + - wazuh2.indexer + - wazuh3.indexer cluster.name: "wazuh-cluster" discovery.seed_hosts: - - wazuh1-indexer - - wazuh2-indexer - - wazuh3-indexer + - wazuh1.indexer + - wazuh2.indexer + - wazuh3.indexer http.port: 9700-9799 transport.tcp.port: 9800-9899 node.max_local_storage_nodes: "3" @@ -20,11 +20,11 @@ path.logs: /var/log/wazuh-indexer # Please change on production cluster! # # # ############################################################################### -plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh3-indexer.pem -plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh3-indexer.key +plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh3.indexer.pem +plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh3.indexer.key plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem -plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh3-indexer.pem -plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh3-indexer.key +plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/wazuh3.indexer.pem +plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/wazuh3.indexer.key plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem plugins.security.ssl.http.enabled: true plugins.security.ssl.transport.enforce_hostname_verification: false @@ -35,9 +35,9 @@ plugins.security.authcz.admin_dn: plugins.security.check_snapshot_restore_write_privileges: true plugins.security.enable_snapshot_restore_privilege: true plugins.security.nodes_dn: -- "CN=wazuh1-indexer,OU=Docu,O=Wazuh,L=California,C=US" -- "CN=wazuh2-indexer,OU=Docu,O=Wazuh,L=California,C=US" -- "CN=wazuh3-indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh1.indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh2.indexer,OU=Docu,O=Wazuh,L=California,C=US" +- "CN=wazuh3.indexer,OU=Docu,O=Wazuh,L=California,C=US" - "CN=filebeat,OU=Docu,O=Wazuh,L=California,C=US" plugins.security.restapi.roles_enabled: - "all_access" @@ -45,4 +45,5 @@ plugins.security.restapi.roles_enabled: plugins.security.allow_default_init_securityindex: true cluster.routing.allocation.disk.threshold_enabled: false opendistro_security.audit.config.disabled_rest_categories: NONE -opendistro_security.audit.config.disabled_transport_categories: NONE \ No newline at end of file +opendistro_security.audit.config.disabled_transport_categories: NONE +compatibility.override_main_response_version: true \ No newline at end of file diff --git a/production_cluster/wazuh_dashboard/dashboard.yml b/production_cluster/wazuh_dashboard/dashboard.yml new file mode 100644 index 00000000..8b0c332b --- /dev/null +++ b/production_cluster/wazuh_dashboard/dashboard.yml @@ -0,0 +1,14 @@ +server.host: 0.0.0.0 +server.port: 5601 +opensearch.hosts: https://wazuh1.indexer:9700 +opensearch.ssl.verificationMode: certificate +opensearch.username: kibanaserver +opensearch.password: kibanaserver +opensearch.requestHeadersWhitelist: ["securitytenant","Authorization"] +opensearch_security.multitenancy.enabled: false +opensearch_security.readonly_mode.roles: ["kibana_read_only"] +server.ssl.enabled: true +server.ssl.key: "/etc/wazuh-dashboard/certs/wazuh-dashboard-key.pem" +server.ssl.certificate: "/etc/wazuh-dashboard/certs/wazuh-dashboard.pem" +opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"] +uiSettings.overrides.defaultRoute: /app/wazuh?security_tenant=global diff --git a/production_cluster/wazuh_dashboard/wazuh/config/wazuh-registry.json b/production_cluster/wazuh_dashboard/wazuh/config/wazuh-registry.json new file mode 100644 index 00000000..5c393051 --- /dev/null +++ b/production_cluster/wazuh_dashboard/wazuh/config/wazuh-registry.json @@ -0,0 +1 @@ +{"name":"Wazuh App","app-version":"4.3.0","revision":"4301-0","installationDate":"2022-02-10T13:49:45.182Z","lastRestart":"2022-02-10T13:49:45.182Z","hosts":{"default":{"cluster_info":{"status":"enabled","manager":"wazuh.master","node":"manager","cluster":"wazuh"},"extensions":{"pci":true,"gdpr":true,"hipaa":true,"nist":true,"tsc":true,"audit":true,"oscap":false,"ciscat":false,"aws":false,"office":false,"github":false,"gcp":false,"virustotal":false,"osquery":false,"docker":false}}}} \ No newline at end of file diff --git a/production_cluster/wazuh_dashboard/wazuh/config/wazuh.yml b/production_cluster/wazuh_dashboard/wazuh/config/wazuh.yml new file mode 100644 index 00000000..f37a7aca --- /dev/null +++ b/production_cluster/wazuh_dashboard/wazuh/config/wazuh.yml @@ -0,0 +1,8 @@ +hosts: + - default: + url: https://wazuh.master + port: 55000 + username: acme-user + password: MyS3cr37P450r.*- + run_as: false + diff --git a/production_cluster/wazuh_dashboard/wazuh/logs/wazuhapp-plain.log b/production_cluster/wazuh_dashboard/wazuh/logs/wazuhapp-plain.log new file mode 100644 index 00000000..67e659fb --- /dev/null +++ b/production_cluster/wazuh_dashboard/wazuh/logs/wazuhapp-plain.log @@ -0,0 +1,38 @@ +info: 2022/02/10 13:49:44: initialize: Kibana index: .kibana +info: 2022/02/10 13:49:44: initialize: App revision: 4301-0 +info: 2022/02/10 13:49:44: initialize: Total RAM: 11928MB +error: 2022/02/10 13:49:45: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check +error: 2022/02/10 13:55:0: cron-scheduler|SaveDocument: resource_already_exists_exception +info: 2022/02/10 18:35:47: initialize: Kibana index: .kibana +info: 2022/02/10 18:35:47: initialize: App revision: 4301-0 +info: 2022/02/10 18:35:47: initialize: Total RAM: 11928MB +error: 2022/02/10 18:35:47: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check +error: 2022/02/10 18:40:0: cron-scheduler|SaveDocument: resource_already_exists_exception +info: 2022/02/10 18:42:13: initialize: Kibana index: .kibana +info: 2022/02/10 18:42:13: initialize: App revision: 4301-0 +info: 2022/02/10 18:42:13: initialize: Total RAM: 11928MB +error: 2022/02/10 18:42:14: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check +error: 2022/02/10 18:45:0: cron-scheduler|SaveDocument: resource_already_exists_exception +info: 2022/02/10 20:23:3: initialize: Kibana index: .kibana +info: 2022/02/10 20:23:3: initialize: App revision: 4301-0 +info: 2022/02/10 20:23:3: initialize: Total RAM: 11928MB +error: 2022/02/10 20:23:4: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check +error: 2022/02/10 20:25:0: cron-scheduler|SaveDocument: resource_already_exists_exception +info: 2022/02/11 18:48:39: initialize: Kibana index: .kibana +info: 2022/02/11 18:48:39: initialize: App revision: 4301-0 +info: 2022/02/11 18:48:39: initialize: Total RAM: 11928MB +error: 2022/02/11 18:48:40: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check +error: 2022/02/11 18:50:1: cron-scheduler|SaveDocument: resource_already_exists_exception +info: 2022/02/11 19:23:22: initialize: Kibana index: .kibana +info: 2022/02/11 19:23:22: initialize: App revision: 4301-0 +info: 2022/02/11 19:23:22: initialize: Total RAM: 11928MB +error: 2022/02/11 19:23:23: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check +error: 2022/02/11 19:25:0: cron-scheduler|SaveDocument: resource_already_exists_exception +info: 2022/02/11 19:27:28: initialize: Kibana index: .kibana +info: 2022/02/11 19:27:28: initialize: App revision: 4301-0 +info: 2022/02/11 19:27:28: initialize: Total RAM: 11928MB +error: 2022/02/11 19:27:28: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check +info: 2022/02/11 19:31:58: initialize: Kibana index: .kibana +info: 2022/02/11 19:31:58: initialize: App revision: 4301-0 +info: 2022/02/11 19:31:58: initialize: Total RAM: 11928MB +error: 2022/02/11 19:31:59: initialize:checkKibanaStatus: Could not check if the index .wazuh exists due to no permissions for create, delete or check diff --git a/production_cluster/wazuh_dashboard/wazuh/logs/wazuhapp.log b/production_cluster/wazuh_dashboard/wazuh/logs/wazuhapp.log new file mode 100644 index 00000000..fffe806c --- /dev/null +++ b/production_cluster/wazuh_dashboard/wazuh/logs/wazuhapp.log @@ -0,0 +1,38 @@ +{"date":"2022-02-10T13:49:44.661Z","level":"info","location":"initialize","message":"Kibana index: .kibana"} +{"date":"2022-02-10T13:49:44.661Z","level":"info","location":"initialize","message":"App revision: 4301-0"} +{"date":"2022-02-10T13:49:44.661Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"} +{"date":"2022-02-10T13:49:45.077Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"} +{"date":"2022-02-10T13:55:00.999Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"} +{"date":"2022-02-10T18:35:47.009Z","level":"info","location":"initialize","message":"Kibana index: .kibana"} +{"date":"2022-02-10T18:35:47.010Z","level":"info","location":"initialize","message":"App revision: 4301-0"} +{"date":"2022-02-10T18:35:47.010Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"} +{"date":"2022-02-10T18:35:47.242Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"} +{"date":"2022-02-10T18:40:00.559Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"} +{"date":"2022-02-10T18:42:13.894Z","level":"info","location":"initialize","message":"Kibana index: .kibana"} +{"date":"2022-02-10T18:42:13.894Z","level":"info","location":"initialize","message":"App revision: 4301-0"} +{"date":"2022-02-10T18:42:13.894Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"} +{"date":"2022-02-10T18:42:14.231Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"} +{"date":"2022-02-10T18:45:00.330Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"} +{"date":"2022-02-10T20:23:03.443Z","level":"info","location":"initialize","message":"Kibana index: .kibana"} +{"date":"2022-02-10T20:23:03.443Z","level":"info","location":"initialize","message":"App revision: 4301-0"} +{"date":"2022-02-10T20:23:03.443Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"} +{"date":"2022-02-10T20:23:04.136Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"} +{"date":"2022-02-10T20:25:00.975Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"} +{"date":"2022-02-11T18:48:39.186Z","level":"info","location":"initialize","message":"Kibana index: .kibana"} +{"date":"2022-02-11T18:48:39.187Z","level":"info","location":"initialize","message":"App revision: 4301-0"} +{"date":"2022-02-11T18:48:39.187Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"} +{"date":"2022-02-11T18:48:40.305Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"} +{"date":"2022-02-11T18:50:01.075Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"} +{"date":"2022-02-11T19:23:22.847Z","level":"info","location":"initialize","message":"Kibana index: .kibana"} +{"date":"2022-02-11T19:23:22.848Z","level":"info","location":"initialize","message":"App revision: 4301-0"} +{"date":"2022-02-11T19:23:22.848Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"} +{"date":"2022-02-11T19:23:23.646Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"} +{"date":"2022-02-11T19:25:00.244Z","level":"error","location":"cron-scheduler|SaveDocument","message":"resource_already_exists_exception"} +{"date":"2022-02-11T19:27:28.476Z","level":"info","location":"initialize","message":"Kibana index: .kibana"} +{"date":"2022-02-11T19:27:28.477Z","level":"info","location":"initialize","message":"App revision: 4301-0"} +{"date":"2022-02-11T19:27:28.477Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"} +{"date":"2022-02-11T19:27:28.862Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"} +{"date":"2022-02-11T19:31:58.941Z","level":"info","location":"initialize","message":"Kibana index: .kibana"} +{"date":"2022-02-11T19:31:58.942Z","level":"info","location":"initialize","message":"App revision: 4301-0"} +{"date":"2022-02-11T19:31:58.942Z","level":"info","location":"initialize","message":"Total RAM: 11928MB"} +{"date":"2022-02-11T19:31:59.543Z","level":"error","location":"initialize:checkKibanaStatus","message":"Could not check if the index .wazuh exists due to no permissions for create, delete or check"} diff --git a/production_cluster/wazuh_indexer_ssl_certs/admin-key.pem b/production_cluster/wazuh_indexer_ssl_certs/admin-key.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/admin.pem b/production_cluster/wazuh_indexer_ssl_certs/admin.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/certs.yml b/production_cluster/wazuh_indexer_ssl_certs/certs.yml old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/root-ca.key b/production_cluster/wazuh_indexer_ssl_certs/root-ca.key old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/root-ca.pem b/production_cluster/wazuh_indexer_ssl_certs/root-ca.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh.dashboard-key.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh.dashboard-key.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh.dashboard.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh.dashboard.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh.master-key.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh.master-key.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh.master.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh.master.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh.worker-key.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh.worker-key.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh.worker.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh.worker.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh1.indexer-key.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh1.indexer-key.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh1.indexer.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh1.indexer.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh2.indexer-key.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh2.indexer-key.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh2.indexer.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh2.indexer.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh3.indexer-key.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh3.indexer-key.pem old mode 100644 new mode 100755 diff --git a/production_cluster/wazuh_indexer_ssl_certs/wazuh3.indexer.pem b/production_cluster/wazuh_indexer_ssl_certs/wazuh3.indexer.pem old mode 100644 new mode 100755 diff --git a/test-cluster.yml b/test-cluster.yml index b61eebf7..c2f7f3bb 100644 --- a/test-cluster.yml +++ b/test-cluster.yml @@ -3,7 +3,7 @@ version: '3.7' services: wazuh.master: - image: wazuh/wazuh-odfe:4.3.0 + image: wazuh/wazuh-odfe:4.3.0-dev hostname: wazuh.master restart: always ports: @@ -11,9 +11,9 @@ services: - "514:514/udp" - "55000:55000" environment: - - ELASTICSEARCH_URL=https://wazuh.indexer:9700 + - ELASTICSEARCH_URL=https://wazuh1.indexer:9700 - ELASTIC_USERNAME=admin - - ELASTIC_PASSWORD=admin + - ELASTIC_PASSWORD=SecretPassword - FILEBEAT_SSL_VERIFICATION_MODE=full - SSL_CERTIFICATE_AUTHORITIES=/etc/ssl/root-ca.pem - SSL_CERTIFICATE=/etc/ssl/filebeat.pem @@ -38,13 +38,13 @@ services: - ./production_cluster/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.worker: - image: wazuh/wazuh-odfe:4.3.0 + image: wazuh/wazuh-odfe:4.3.0-dev hostname: wazuh.worker restart: always environment: - - ELASTICSEARCH_URL=https://wazuh.indexer:9700 + - ELASTICSEARCH_URL=https://wazuh1.indexer:9700 - ELASTIC_USERNAME=admin - - ELASTIC_PASSWORD=admin + - ELASTIC_PASSWORD=SecretPassword - FILEBEAT_SSL_VERIFICATION_MODE=full - SSL_CERTIFICATE_AUTHORITIES=/etc/ssl/root-ca.pem - SSL_CERTIFICATE=/etc/ssl/filebeat.pem @@ -67,7 +67,7 @@ services: - ./production_cluster/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf wazuh1.indexer: - image: test-indexer + image: wazuh/wazuh-indexer:4.3.0 hostname: wazuh1.indexer restart: always ports: @@ -93,7 +93,7 @@ services: - ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/internal_users.yml wazuh2.indexer: - image: test-indexer + image: wazuh/wazuh-indexer:4.3.0 hostname: wazuh2.indexer restart: always environment: @@ -112,10 +112,10 @@ services: - ./production_cluster/wazuh_indexer_ssl_certs/wazuh2.indexer-key.pem:/etc/wazuh-indexer/certs/wazuh2.indexer.key - ./production_cluster/wazuh_indexer_ssl_certs/wazuh2.indexer.pem:/etc/wazuh-indexer/certs/wazuh2.indexer.pem - ./production_cluster/wazuh-indexer/wazuh2.indexer.yml:/etc/wazuh-indexer/opensearch.yml - - ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml + - ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/internal_users.yml wazuh3.indexer: - image: test-indexer + image: wazuh/wazuh-indexer:4.3.0 hostname: wazuh3.indexer restart: always environment: @@ -134,7 +134,7 @@ services: - ./production_cluster/wazuh_indexer_ssl_certs/wazuh3.indexer-key.pem:/etc/wazuh-indexer/certs/wazuh3.indexer.key - ./production_cluster/wazuh_indexer_ssl_certs/wazuh3.indexer.pem:/etc/wazuh-indexer/certs/wazuh3.indexer.pem - ./production_cluster/wazuh-indexer/wazuh3.indexer.yml:/etc/wazuh-indexer/opensearch.yml - - ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml + - ./production_cluster/wazuh-indexer/internal_users.yml:/usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/internal_users.yml wazuh.dashboard: image: wazuh/wazuh-dashboard:4.3.0 @@ -143,18 +143,16 @@ services: ports: - 5601:5601 environment: - - ELASTICSEARCH_USERNAME=admin - - ELASTICSEARCH_PASSWORD=admin - - SERVER_SSL_ENABLED=true - - SERVER_SSL_CERTIFICATE=/etc/wazuh-dashboard/certs/cert.pem - - SERVER_SSL_KEY=/etc/wazuh-dashboard/certs/key.pem + - OPENSEARCH_HOSTS="https://wazuh1.indexer:9700" - WAZUH_API_URL="https://wazuh.master" - API_USERNAME=acme-user - API_PASSWORD=MyS3cr37P450r.*- volumes: - - ./production_cluster/wazuh_dashboard_ssl/cert.pem:/etc/wazuh-dashboard/certs/cert.pem - - ./production_cluster/wazuh_dashboard_ssl/key.pem:/etc/wazuh-dashboard/certs/key.pem - + - ./production_cluster/wazuh_indexer_ssl_certs/wazuh.dashboard.pem:/etc/wazuh-dashboard/certs/wazuh-dashboard.pem + - ./production_cluster/wazuh_indexer_ssl_certs/wazuh.dashboard-key.pem:/etc/wazuh-dashboard/certs/wazuh-dashboard-key.pem + - ./production_cluster/wazuh_indexer_ssl_certs/root-ca.pem:/etc/wazuh-dashboard/certs/root-ca.pem + - ./production_cluster/wazuh_dashboard/dashboard.yml:/etc/wazuh-dashboard/dashboard.yml + - ./production_cluster/wazuh_dashboard/wazuh:/usr/share/wazuh-dashboard/data/wazuh depends_on: - wazuh1.indexer links: diff --git a/wazuh-dashboard/Dockerfile b/wazuh-dashboard/Dockerfile index 97d72ab1..bf2c6443 100644 --- a/wazuh-dashboard/Dockerfile +++ b/wazuh-dashboard/Dockerfile @@ -13,8 +13,16 @@ RUN curl https://s3.us-west-1.amazonaws.com/packages-dev.wazuh.com/pre-release/a COPY config/entrypoint.sh / +COPY config/wazuh_app_config.sh / + +COPY config/dashboard.yml /etc/wazuh-dashboard/ + RUN chmod 700 /entrypoint.sh +RUN chmod 700 /wazuh_app_config.sh + +RUN chown 101:101 /etc/wazuh-dashboard/dashboard.yml && chmod 664 /etc/wazuh-dashboard/dashboard.yml + # Services ports EXPOSE 5601 diff --git a/wazuh-dashboard/config/dashboard.yml b/wazuh-dashboard/config/dashboard.yml new file mode 100644 index 00000000..7aec4657 --- /dev/null +++ b/wazuh-dashboard/config/dashboard.yml @@ -0,0 +1,14 @@ +server.host: 0.0.0.0 +server.port: 5601 +opensearch.hosts: https://wazuh1.indexer:9700 +opensearch.ssl.verificationMode: certificate +opensearch.username: kibanaserver +opensearch.password: kibanaserver +opensearch.requestHeadersWhitelist: ["securitytenant","Authorization"] +opensearch_security.multitenancy.enabled: false +opensearch_security.readonly_mode.roles: ["kibana_read_only"] +server.ssl.enabled: false +server.ssl.key: "/etc/wazuh-dashboard/certs/demo-dashboard-key.pem" +server.ssl.certificate: "/etc/wazuh-dashboard/certs/demo-dashboard.pem" +opensearch.ssl.certificateAuthorities: ["/etc/wazuh-dashboard/certs/root-ca.pem"] +uiSettings.overrides.defaultRoute: /app/wazuh?security_tenant=global diff --git a/wazuh-dashboard/config/entrypoint.sh b/wazuh-dashboard/config/entrypoint.sh index c0d98a53..0294d4ca 100644 --- a/wazuh-dashboard/config/entrypoint.sh +++ b/wazuh-dashboard/config/entrypoint.sh @@ -5,8 +5,6 @@ # Start Wazuh dashboard ############################################################################## -sed -i 's/localhost:9700/wazuh-indexer:9700/' /etc/wazuh-dashboard/dashboard.yml -sed -i 's//0.0.0.0/' /etc/wazuh-dashboard/dashboard.yml -sed -i '/logging.dest:/d' /etc/wazuh-dashboard/dashboard.yml +#/wazuh_app_config.sh runuser wazuh-dashboard --shell="/bin/bash" --command="/usr/share/wazuh-dashboard/bin/opensearch-dashboards -c /etc/wazuh-dashboard/dashboard.yml" diff --git a/wazuh-dashboard/config/wazuh_app_config.sh b/wazuh-dashboard/config/wazuh_app_config.sh index ca6e1a6a..c63c55c9 100644 --- a/wazuh-dashboard/config/wazuh_app_config.sh +++ b/wazuh-dashboard/config/wazuh_app_config.sh @@ -6,51 +6,8 @@ wazuh_port="${API_PORT:-55000}" api_username="${API_USERNAME:-wazuh-wui}" api_password="${API_PASSWORD:-wazuh-wui}" -kibana_config_file="/etc/wazuh-dashboard/wazuh-dashboard.yml" +kibana_config_file="/usr/share/wazuh-dashboard/data/wazuh/config/wazuh.yml" -sed 's/9700/9200/' /etc/wazuh-dashboard/wazuh-dashboard.yml - -declare -A CONFIG_MAP=( - [pattern]=$PATTERN - [checks.pattern]=$CHECKS_PATTERN - [checks.template]=$CHECKS_TEMPLATE - [checks.api]=$CHECKS_API - [checks.setup]=$CHECKS_SETUP - [extensions.pci]=$EXTENSIONS_PCI - [extensions.gdpr]=$EXTENSIONS_GDPR - [extensions.hipaa]=$EXTENSIONS_HIPAA - [extensions.nist]=$EXTENSIONS_NIST - [extensions.tsc]=$EXTENSIONS_TSC - [extensions.audit]=$EXTENSIONS_AUDIT - [extensions.oscap]=$EXTENSIONS_OSCAP - [extensions.ciscat]=$EXTENSIONS_CISCAT - [extensions.aws]=$EXTENSIONS_AWS - [extensions.gcp]=$EXTENSIONS_GCP - [extensions.virustotal]=$EXTENSIONS_VIRUSTOTAL - [extensions.osquery]=$EXTENSIONS_OSQUERY - [extensions.docker]=$EXTENSIONS_DOCKER - [timeout]=$APP_TIMEOUT - [api.selector]=$API_SELECTOR - [ip.selector]=$IP_SELECTOR - [ip.ignore]=$IP_IGNORE - [wazuh.monitoring.enabled]=$WAZUH_MONITORING_ENABLED - [wazuh.monitoring.creation]=$WAZUH_MONITORING_CREATION - [wazuh.monitoring.frequency]=$WAZUH_MONITORING_FREQUENCY - [wazuh.monitoring.shards]=$WAZUH_MONITORING_SHARDS - [wazuh.monitoring.replicas]=$WAZUH_MONITORING_REPLICAS - [admin]=$ADMIN_PRIVILEGES -) - -for i in "${!CONFIG_MAP[@]}" -do - if [ "${CONFIG_MAP[$i]}" != "" ]; then - sed -i 's/.*#'"$i"'.*/'"$i"': '"${CONFIG_MAP[$i]}"'/' $kibana_config_file - fi -done - -CONFIG_CODE=$(curl ${auth} -s -o /dev/null -w "%{http_code}" -XGET $el_url/.wazuh/_doc/1513629884013) - -if [[ "x$CONFIG_CODE" != "x200" ]] && ! grep -q 1513629884013 $kibana_config_file ; then cat << EOF >> $kibana_config_file hosts: - 1513629884013: @@ -59,6 +16,3 @@ hosts: username: $api_username password: $api_password EOF -else - echo "Wazuh APP already configured" -fi diff --git a/wazuh-indexer/Dockerfile b/wazuh-indexer/Dockerfile index 17243898..bb4d533b 100644 --- a/wazuh-indexer/Dockerfile +++ b/wazuh-indexer/Dockerfile @@ -52,7 +52,9 @@ WORKDIR $INSTALL_DIR COPY config/entrypoint.sh / -RUN chmod 700 /entrypoint.sh +COPY config/securityadmin.sh / + +RUN chmod 700 /entrypoint.sh && chmod 700 /securityadmin.sh COPY --from=builder --chown=1000:1000 /debian/wazuh-indexer/usr/share/wazuh-indexer /usr/share/wazuh-indexer COPY --from=builder --chown=0:0 /tini /tini @@ -60,7 +62,9 @@ COPY --from=builder --chown=0:0 /debian/wazuh-indexer/etc/init.d/wazuh-indexer / COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/systemd /usr/lib/systemd COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/sysctl.d /usr/lib/sysctl.d COPY --from=builder --chown=0:0 /debian/wazuh-indexer/usr/lib/tmpfiles.d /usr/lib/tmpfiles.d -COPY --from=builder --chown=1000:10000 /debian/wazuh-indexer/etc/wazuh-indexer /etc/wazuh-indexer +COPY --from=builder --chown=1000:1000 /debian/wazuh-indexer/etc/wazuh-indexer /etc/wazuh-indexer +COPY config/opensearch.yml /etc/wazuh-indexer/ +RUN chmod 660 /etc/wazuh-indexer/opensearch.yml && chown 1000:1000 /etc/wazuh-indexer/opensearch.yml RUN mkdir -p /var/lib/wazuh-indexer && chown 1000:1000 /var/lib/wazuh-indexer && \ mkdir -p /usr/share/wazuh-indexer/logs && chown 1000:1000 /usr/share/wazuh-indexer/logs && \ @@ -70,7 +74,6 @@ RUN mkdir -p /var/lib/wazuh-indexer && chown 1000:1000 /var/lib/wazuh-indexer && # Services ports EXPOSE 9700 -#ENTRYPOINT [ "/entrypoint.sh" ] ENTRYPOINT ["/tini", "--", "/entrypoint.sh"] # Dummy overridable parameter parsed by entrypoint diff --git a/wazuh-indexer/config/entrypoint.sh b/wazuh-indexer/config/entrypoint.sh index 69736c1e..81ca3188 100644 --- a/wazuh-indexer/config/entrypoint.sh +++ b/wazuh-indexer/config/entrypoint.sh @@ -8,7 +8,10 @@ export USER=wazuh-indexer export INSTALLATION_DIR=/usr/share/wazuh-indexer export OPENSEARCH_PATH_CONF=/etc/wazuh-indexer export JAVA_HOME=${INSTALLATION_DIR}/jdk -export FILE=${INSTALLATION_DIR}/start +export DISCOVERY=$(grep -oP "(?<=discovery.type: ).*" /etc/wazuh-indexer/opensearch.yml) +export CACERT=$(grep -oP "(?<=plugins.security.ssl.transport.pemtrustedcas_filepath: ).*" /etc/wazuh-indexer/opensearch.yml) +export CERT="/etc/wazuh-indexer/certs/admin.pem" +export KEY="/etc/wazuh-indexer/certs/admin-key.pem" run_as_other_user_if_needed() { if [[ "$(id -u)" == "0" ]]; then @@ -26,8 +29,6 @@ run_as_other_user_if_needed() { # or simply to run /bin/bash to check the image if [[ "$1" != "opensearchwrapper" ]]; then if [[ "$(id -u)" == "0" && $(basename "$1") == "opensearch" ]]; then - # centos:7 chroot doesn't have the `--skip-chdir` option and - # changes our CWD. # Rewrite CMD args to replace $1 with `opensearch` explicitly, # so that we are backwards compatible with the docs # from the previous Elasticsearch versions<6 @@ -86,4 +87,9 @@ if [[ "$(id -u)" == "0" ]]; then fi fi +if [[ "$DISCOVERY" == "single-node" ]]; then + # run securityadmin.sh for single node + nohup /securityadmin.sh & +fi + run_as_other_user_if_needed /usr/share/wazuh-indexer/bin/opensearch <<<"$KEYSTORE_PASSWORD" \ No newline at end of file diff --git a/wazuh-indexer/config/opensearch.yml b/wazuh-indexer/config/opensearch.yml new file mode 100644 index 00000000..9793012d --- /dev/null +++ b/wazuh-indexer/config/opensearch.yml @@ -0,0 +1,36 @@ +network.host: "0.0.0.0" +node.name: "wazuh1.indexer" +http.port: 9700-9799 +transport.tcp.port: 9800-9899 +path.data: /var/lib/wazuh-indexer +path.logs: /var/log/wazuh-indexer +discovery.type: single-node +compatibility.override_main_response_version: true +############################################################################### +# # +# WARNING: Insecure demo certificates set up in this file. # +# Please change on production cluster! # +# # +############################################################################### +plugins.security.ssl.http.pemcert_filepath: /etc/wazuh-indexer/certs/demo-indexer.pem +plugins.security.ssl.http.pemkey_filepath: /etc/wazuh-indexer/certs/demo-indexer-key.pem +plugins.security.ssl.http.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem +plugins.security.ssl.transport.pemcert_filepath: /etc/wazuh-indexer/certs/demo-indexer.pem +plugins.security.ssl.transport.pemkey_filepath: /etc/wazuh-indexer/certs/demo-indexer-key.pem +plugins.security.ssl.transport.pemtrustedcas_filepath: /etc/wazuh-indexer/certs/root-ca.pem +plugins.security.ssl.http.enabled: true +plugins.security.ssl.transport.enforce_hostname_verification: false +plugins.security.ssl.transport.resolve_hostname: false +plugins.security.audit.type: internal_opensearch +plugins.security.authcz.admin_dn: +- "CN=admin,OU=Demo,O=Wazuh,L=California,C=US" +plugins.security.check_snapshot_restore_write_privileges: true +plugins.security.enable_snapshot_restore_privilege: true +plugins.security.nodes_dn: +- "CN=demo-indexer,OU=Demo,O=Wazuh,L=California,C=US" +plugins.security.restapi.roles_enabled: +- "all_access" +- "security_rest_api_access" +plugins.security.system_indices.enabled: true +plugins.security.system_indices.indices: [".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opendistro-notifications-*", ".opendistro-notebooks", ".opensearch-observability", ".opendistro-asynchronous-search-response*", ".replication-metadata-store"] + diff --git a/wazuh-indexer/config/securityadmin.sh b/wazuh-indexer/config/securityadmin.sh new file mode 100644 index 00000000..1fe6af34 --- /dev/null +++ b/wazuh-indexer/config/securityadmin.sh @@ -0,0 +1,2 @@ +sleep 50 +bash /usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh -cd /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/ -nhnv -cacert $CACERT -cert $CERT -key $KEY -p 9800 -icl \ No newline at end of file diff --git a/wazuh-odfe/Dockerfile b/wazuh-odfe/Dockerfile index 143e1e11..c7a9cf83 100644 --- a/wazuh-odfe/Dockerfile +++ b/wazuh-odfe/Dockerfile @@ -3,12 +3,12 @@ FROM centos:7 ARG FILEBEAT_CHANNEL=filebeat-oss ARG FILEBEAT_VERSION=7.10.2 -ARG WAZUH_VERSION=4.2.5-1 +ARG WAZUH_VERSION=4.3.0-1 ARG TEMPLATE_VERSION="master" ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.1.tar.gz" # Set repositories. -RUN rpm --import https://packages.wazuh.com/key/GPG-KEY-WAZUH +RUN rpm --import https://packages-dev.wazuh.com/key/GPG-KEY-WAZUH COPY config/wazuh.repo /etc/yum.repos.d/wazuh.repo diff --git a/wazuh-odfe/config/create_user.py b/wazuh-odfe/config/create_user.py index 40a1e04d..cc492398 100644 --- a/wazuh-odfe/config/create_user.py +++ b/wazuh-odfe/config/create_user.py @@ -13,6 +13,7 @@ SPECIAL_CHARS = "@$!%*?&-_" try: + from wazuh.rbac.orm import create_rbac_db from wazuh.security import ( create_user, get_users, @@ -66,6 +67,10 @@ if __name__ == "__main__": # abort if no user file detected sys.exit(0) username, password = read_user_file() + + # create RBAC database + create_rbac_db() + initial_users = db_users() if username not in initial_users: # create a new user diff --git a/wazuh-odfe/config/wazuh.repo b/wazuh-odfe/config/wazuh.repo index e230d6a9..4b673ff0 100644 --- a/wazuh-odfe/config/wazuh.repo +++ b/wazuh-odfe/config/wazuh.repo @@ -1,7 +1,7 @@ [wazuh_repo] gpgcheck=1 -gpgkey=https://packages.wazuh.com/key/GPG-KEY-WAZUH +gpgkey=https://packages-dev.wazuh.com/key/GPG-KEY-WAZUH enabled=1 name=Wazuh repository -baseurl=https://packages.wazuh.com/4.x/yum/ +baseurl=https://packages-dev.wazuh.com/pre-release/yum/ protect=1