diff --git a/wazuh-opendistro/Dockerfile b/wazuh-opendistro/Dockerfile new file mode 100644 index 00000000..1add03c0 --- /dev/null +++ b/wazuh-opendistro/Dockerfile @@ -0,0 +1,59 @@ +# Wazuh Docker Copyright (C) 2020 Wazuh Inc. (License GPLv2) +FROM centos:7 + +ARG FILEBEAT_VERSION=7.8.0 +ARG WAZUH_VERSION=3.13.1-1 +ARG TEMPLATE_VERSION="v3.13.1" +ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.1.tar.gz" + +ENV API_USER="foo" \ + API_PASS="bar" + + +# Set repositories. +RUN rpm --import https://packages.wazuh.com/key/GPG-KEY-WAZUH + +COPY config/wazuh.repo /etc/yum.repos.d/wazuh.repo + +RUN yum --enablerepo=updates clean metadata && \ + yum -y install openssl which && yum -y install wazuh-manager-${WAZUH_VERSION} -y && \ + curl --silent --location https://rpm.nodesource.com/setup_10.x | bash - && \ + yum -y install nodejs && yum -y install wazuh-api-${WAZUH_VERSION} && \ + sed -i "s/^enabled=1/enabled=0/" /etc/yum.repos.d/wazuh.repo && \ + yum clean all && rm -rf /var/cache/yum + +RUN curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-oss-${FILEBEAT_VERSION}-x86_64.rpm &&\ + rpm -i filebeat-oss-${FILEBEAT_VERSION}-x86_64.rpm && rm -f filebeat-oss-${FILEBEAT_VERSION}-x86_64.rpm + +RUN curl -so /etc/filebeat/wazuh-template.json https://raw.githubusercontent.com/wazuh/wazuh/${TEMPLATE_VERSION}/extensions/elasticsearch/7.x/wazuh-template.json &&\ + chmod go+r /etc/filebeat/wazuh-template.json + +RUN curl -s https://packages.wazuh.com/3.x/filebeat/${WAZUH_FILEBEAT_MODULE} | tar -xvz -C /usr/share/filebeat/module + +ARG S6_VERSION="v2.0.0.1" +RUN curl --fail --silent -L https://github.com/just-containers/s6-overlay/releases/download/${S6_VERSION}/s6-overlay-amd64.tar.gz \ + -o /tmp/s6-overlay-amd64.tar.gz && \ + tar xzf /tmp/s6-overlay-amd64.tar.gz -C / --exclude="./bin" && \ + tar xzf /tmp/s6-overlay-amd64.tar.gz -C /usr ./bin && \ + rm /tmp/s6-overlay-amd64.tar.gz + +COPY config/filebeat.yml /etc/filebeat/ + +RUN chmod go-w /etc/filebeat/filebeat.yml + +ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat +RUN chmod go-w /etc/filebeat/wazuh-template.json + +COPY config/etc/ /etc/ + +# Prepare permanent data +# Sync calls are due to https://github.com/docker/docker/issues/9547 +COPY config/permanent_data.env config/permanent_data.sh / +RUN chmod 755 /permanent_data.sh && \ + sync && /permanent_data.sh && \ + sync && rm /permanent_data.sh + +# Services ports +EXPOSE 55000/tcp 1514/udp 1515/tcp 514/udp 1516/tcp + +ENTRYPOINT [ "/init" ] diff --git a/wazuh-opendistro/config/etc/cont-init.d/0-wazuh-init b/wazuh-opendistro/config/etc/cont-init.d/0-wazuh-init new file mode 100644 index 00000000..b0cbd001 --- /dev/null +++ b/wazuh-opendistro/config/etc/cont-init.d/0-wazuh-init @@ -0,0 +1,232 @@ +#!/usr/bin/with-contenv bash +# Wazuh App Copyright (C) 2020 Wazuh Inc. (License GPLv2) + +# Variables +source /permanent_data.env + +WAZUH_INSTALL_PATH=/var/ossec +WAZUH_CONFIG_MOUNT=/wazuh-config-mount +AUTO_ENROLLMENT_ENABLED=${AUTO_ENROLLMENT_ENABLED:-true} +API_GENERATE_CERTS=${API_GENERATE_CERTS:-true} + + +############################################################################## +# Aux functions +############################################################################## +print() { + echo -e $1 +} + +error_and_exit() { + echo "Error executing command: '$1'." + echo 'Exiting.' + exit 1 +} + +exec_cmd() { + eval $1 > /dev/null 2>&1 || error_and_exit "$1" +} + +exec_cmd_stdout() { + eval $1 2>&1 || error_and_exit "$1" +} + + +############################################################################## +# Edit configuration +############################################################################## + +edit_configuration() { # $1 -> setting, $2 -> value + sed -i "s/^config.$1\s=.*/config.$1 = \"$2\";/g" "${WAZUH_INSTALL_PATH}/api/configuration/config.js" || error_and_exit "sed (editing configuration)" +} + +############################################################################## +# This function will attempt to mount every directory in PERMANENT_DATA +# into the respective path. +# If the path is empty means permanent data volume is also empty, so a backup +# will be copied into it. Otherwise it will not be copied because there is +# already data inside the volume for the specified path. +############################################################################## + +mount_permanent_data() { + for permanent_dir in "${PERMANENT_DATA[@]}"; do + # Check if the path is not empty + if find ${permanent_dir} -mindepth 1 | read; then + print "The path ${permanent_dir} is already mounted" + else + print "Installing ${permanent_dir}" + exec_cmd "cp -a ${WAZUH_INSTALL_PATH}/data_tmp/permanent${permanent_dir}/. ${permanent_dir}" + fi + done +} + +############################################################################## +# This function will replace from the permanent data volume every file +# contained in PERMANENT_DATA_EXCP +# Some files as 'internal_options.conf' are saved as permanent data, but +# they must be updated to work properly if wazuh version is changed. +############################################################################## + +apply_exclusion_data() { + for exclusion_file in "${PERMANENT_DATA_EXCP[@]}"; do + if [ -e ${WAZUH_INSTALL_PATH}/data_tmp/exclusion/${exclusion_file} ] + then + DIR=$(dirname "${exclusion_file}") + if [ ! -e ${DIR} ] + then + mkdir -p ${DIR} + fi + + print "Updating ${exclusion_file}" + exec_cmd "cp -p ${WAZUH_INSTALL_PATH}/data_tmp/exclusion/${exclusion_file} ${exclusion_file}" + fi + done +} + +############################################################################## +# This function will delete from the permanent data volume every file +# contained in PERMANENT_DATA_DEL +############################################################################## + +remove_data_files() { + for del_file in "${PERMANENT_DATA_DEL[@]}"; do + if [ -e ${del_file} ] + then + print "Removing ${del_file}" + exec_cmd "rm ${del_file}" + fi + done +} + +############################################################################## +# Create certificates: Manager +############################################################################## + +create_ossec_key_cert() { + print "Creating ossec-authd key and cert" + exec_cmd "openssl genrsa -out ${WAZUH_INSTALL_PATH}/etc/sslmanager.key 4096" + exec_cmd "openssl req -new -x509 -key ${WAZUH_INSTALL_PATH}/etc/sslmanager.key -out ${WAZUH_INSTALL_PATH}/etc/sslmanager.cert -days 3650 -subj /CN=${HOSTNAME}/" +} + +############################################################################## +# Create certificates: API +############################################################################## + +create_api_key_cert() { + print "Enabling Wazuh API HTTPS" + edit_configuration "https" "yes" + print "Create Wazuh API key and cert" + exec_cmd "openssl genrsa -out ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.key 4096" + exec_cmd "openssl req -new -x509 -key ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.key -out ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.crt -days 3650 -subj /CN=${HOSTNAME}/" + + # Granting proper permissions + chmod 400 ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.key + chmod 400 ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.crt +} + +############################################################################## +# Copy all files from $WAZUH_CONFIG_MOUNT to $WAZUH_INSTALL_PATH and respect +# destination files permissions +# +# For example, to mount the file /var/ossec/data/etc/ossec.conf, mount it at +# $WAZUH_CONFIG_MOUNT/etc/ossec.conf in your container and this code will +# replace the ossec.conf file in /var/ossec/data/etc with yours. +############################################################################## + +mount_files() { + if [ -e "$WAZUH_CONFIG_MOUNT" ] + then + print "Identified Wazuh configuration files to mount..." + exec_cmd_stdout "cp --verbose -r $WAZUH_CONFIG_MOUNT/* $WAZUH_INSTALL_PATH" + else + print "No Wazuh configuration files to mount..." + fi +} + +############################################################################## +# Stop OSSEC +############################################################################## + +function ossec_shutdown(){ + ${WAZUH_INSTALL_PATH}/bin/ossec-control stop; +} + +############################################################################## +# Interpret any passed arguments (via docker command to this entrypoint) as +# paths or commands, and execute them. +# +# This can be useful for actions that need to be run before the services are +# started, such as "/var/ossec/bin/ossec-control enable agentless". +############################################################################## + +docker_custom_args() { + for CUSTOM_COMMAND in "$@" + do + echo "Executing command \`${CUSTOM_COMMAND}\`" + exec_cmd_stdout "${CUSTOM_COMMAND}" + done +} + +############################################################################## +# Change Wazuh API user credentials. +############################################################################## + +change_api_user_credentials() { + pushd /var/ossec/api/configuration/auth/ + echo "Change Wazuh API user credentials" + change_user="node htpasswd -b -c user $API_USER $API_PASS" + eval $change_user + popd +} + + +############################################################################## +# Main function +############################################################################## + +main() { + # Mount permanent data (i.e. ossec.conf) + mount_permanent_data + + # Restore files stored in permanent data that are not permanent (i.e. internal_options.conf) + apply_exclusion_data + + # Remove some files in permanent_data (i.e. .template.db) + remove_data_files + + # Generate ossec-authd certs if AUTO_ENROLLMENT_ENABLED is true and does not exist + if [ $AUTO_ENROLLMENT_ENABLED == true ] + then + if [ ! -e ${WAZUH_INSTALL_PATH}/etc/sslmanager.key ] + then + create_ossec_key_cert + fi + fi + + # Generate API certs if API_GENERATE_CERTS is true and does not exist + if [ $API_GENERATE_CERTS == true ] + then + if [ ! -e ${WAZUH_INSTALL_PATH}/api/configuration/ssl/server.crt ] + then + create_api_key_cert + fi + fi + + # Mount selected files (WAZUH_CONFIG_MOUNT) to container + mount_files + + # Trap exit signals and do a proper shutdown + trap "ossec_shutdown; exit" SIGINT SIGTERM + + # Execute custom args + docker_custom_args + + # Change API user credentials + change_api_user_credentials + + # Delete temporary data folder + rm -rf ${WAZUH_INSTALL_PATH}/data_tmp + +} + +main diff --git a/wazuh-opendistro/config/etc/cont-init.d/1-config-filebeat b/wazuh-opendistro/config/etc/cont-init.d/1-config-filebeat new file mode 100644 index 00000000..2f744915 --- /dev/null +++ b/wazuh-opendistro/config/etc/cont-init.d/1-config-filebeat @@ -0,0 +1,29 @@ +#!/usr/bin/with-contenv bash +# Wazuh App Copyright (C) 2020 Wazuh Inc. (License GPLv2) + +set -e + +if [ "$ELASTICSEARCH_URL" != "" ]; then + >&2 echo "Customize Elasticsearch ouput IP" + sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_URL'|g' /etc/filebeat/filebeat.yml +fi + +# Configure filebeat.yml security settings + +if [ "$SSL_CERTIFICATE_AUTHORITIES" != "" ]; then + >&2 echo "Configuring Certificate Authorities." + sed -i 's|#ssl.certificate_authorities:|'ssl.certificate_authorities:\ [\"$SSL_CERTIFICATE_AUTHORITIES\"]'|g' /etc/filebeat/filebeat.yml +fi + +if [ "$USERNAME" != "" ]; then + >&2 echo "Configuring username." + sed -i 's|#username:|'username:\ \"$USERNAME\"'|g' /etc/filebeat/filebeat.yml +fi + +if [ "$PASSWORD" != "" ]; then + >&2 echo "Configuring password." + sed -i 's|#password:|'password:\ \"$PASSWORD\"'|g' /etc/filebeat/filebeat.yml +fi + +chmod go-w /etc/filebeat/filebeat.yml || true +chown root: /etc/filebeat/filebeat.yml || true diff --git a/wazuh-opendistro/config/etc/cont-init.d/2-manager b/wazuh-opendistro/config/etc/cont-init.d/2-manager new file mode 100644 index 00000000..e548e8b1 --- /dev/null +++ b/wazuh-opendistro/config/etc/cont-init.d/2-manager @@ -0,0 +1,3 @@ +#!/usr/bin/with-contenv bash + +/var/ossec/bin/ossec-control start diff --git a/wazuh-opendistro/config/etc/services.d/api/finish b/wazuh-opendistro/config/etc/services.d/api/finish new file mode 100644 index 00000000..38d744d1 --- /dev/null +++ b/wazuh-opendistro/config/etc/services.d/api/finish @@ -0,0 +1,6 @@ +#!/usr/bin/env sh +echo >&2 "API exited. code=${1}" + +# terminate other services to exit from the container +exec s6-svscanctl -t /var/run/s6/services + diff --git a/wazuh-opendistro/config/etc/services.d/api/run b/wazuh-opendistro/config/etc/services.d/api/run new file mode 100644 index 00000000..e6e3e831 --- /dev/null +++ b/wazuh-opendistro/config/etc/services.d/api/run @@ -0,0 +1,4 @@ +#!/usr/bin/with-contenv sh +echo >&2 "starting API" + +exec /bin/node /var/ossec/api/app.js diff --git a/wazuh-opendistro/config/etc/services.d/filebeat/finish b/wazuh-opendistro/config/etc/services.d/filebeat/finish new file mode 100644 index 00000000..8813eb67 --- /dev/null +++ b/wazuh-opendistro/config/etc/services.d/filebeat/finish @@ -0,0 +1,6 @@ +#!/usr/bin/env sh +echo >&2 "Filebeat exited. code=${1}" + +# terminate other services to exit from the container +exec s6-svscanctl -t /var/run/s6/services + diff --git a/wazuh-opendistro/config/etc/services.d/filebeat/run b/wazuh-opendistro/config/etc/services.d/filebeat/run new file mode 100644 index 00000000..706ee5af --- /dev/null +++ b/wazuh-opendistro/config/etc/services.d/filebeat/run @@ -0,0 +1,4 @@ +#!/usr/bin/with-contenv sh +echo >&2 "starting Filebeat" + +exec /usr/share/filebeat/bin/filebeat -e -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat diff --git a/wazuh-opendistro/config/filebeat.yml b/wazuh-opendistro/config/filebeat.yml new file mode 100644 index 00000000..0d04bac8 --- /dev/null +++ b/wazuh-opendistro/config/filebeat.yml @@ -0,0 +1,21 @@ + +# Wazuh - Filebeat configuration file +filebeat.modules: + - module: wazuh + alerts: + enabled: true + archives: + enabled: false + +setup.template.json.enabled: true +setup.template.json.path: '/etc/filebeat/wazuh-template.json' +setup.template.json.name: 'wazuh' +setup.template.overwrite: true +setup.ilm.enabled: false +output.elasticsearch: + hosts: ['http://elasticsearch:9200'] + #ssl.certificate_authorities: + #ssl.certificate: + #ssl.key: + #username: + #password: diff --git a/wazuh-opendistro/config/permanent_data.env b/wazuh-opendistro/config/permanent_data.env new file mode 100644 index 00000000..ca461d63 --- /dev/null +++ b/wazuh-opendistro/config/permanent_data.env @@ -0,0 +1,74 @@ +# Permanent data mounted in volumes +i=0 +PERMANENT_DATA[((i++))]="/var/ossec/api/configuration" +PERMANENT_DATA[((i++))]="/var/ossec/etc" +PERMANENT_DATA[((i++))]="/var/ossec/logs" +PERMANENT_DATA[((i++))]="/var/ossec/queue" +PERMANENT_DATA[((i++))]="/var/ossec/agentless" +PERMANENT_DATA[((i++))]="/var/ossec/var/multigroups" +PERMANENT_DATA[((i++))]="/var/ossec/integrations" +PERMANENT_DATA[((i++))]="/var/ossec/active-response/bin" +PERMANENT_DATA[((i++))]="/var/ossec/wodles" +PERMANENT_DATA[((i++))]="/etc/filebeat" +export PERMANENT_DATA + +# Files mounted in a volume that should not be permanent +i=0 +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/etc/internal_options.conf" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/pagerduty" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/slack" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/slack.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/virustotal" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/integrations/virustotal.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/default-firewall-drop.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/disable-account.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/firewalld-drop.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/firewall-drop.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/host-deny.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ip-customblock.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ipfw_mac.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ipfw.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/kaspersky.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/kaspersky.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/npf.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ossec-slack.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/ossec-tweeter.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/pf.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/restart-ossec.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/restart.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/active-response/bin/route-null.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/sshlogin.exp" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/ssh_pixconfig_diff" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/ssh_asa-fwsmconfig_diff" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/ssh_integrity_check_bsd" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/main.exp" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/su.exp" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/ssh_integrity_check_linux" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/register_host.sh" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/ssh_generic_diff" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/ssh_foundry_diff" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/ssh_nopass.exp" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/agentless/ssh.exp" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/aws/aws-s3" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/aws/aws-s3.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/azure/azure-logs" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/azure/azure-logs.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/docker/DockerListener" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/docker/DockerListener.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/oscap" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/oscap.py" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/template_oval.xsl" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/template_xccdf.xsl" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/content/cve-redhat-6-ds.xml" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/content/cve-redhat-7-ds.xml" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/content/ssg-centos-6-ds.xml" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/content/ssg-centos-7-ds.xml" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/content/ssg-fedora-24-ds.xml" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/content/ssg-rhel-6-ds.xml" +PERMANENT_DATA_EXCP[((i++))]="/var/ossec/wodles/oscap/content/ssg-rhel-7-ds.xml" +export PERMANENT_DATA_EXCP + +# Files mounted in a volume that should be deleted +i=0 +PERMANENT_DATA_DEL[((i++))]="/var/ossec/queue/db/.template.db" +export PERMANENT_DATA_DEL diff --git a/wazuh-opendistro/config/permanent_data.sh b/wazuh-opendistro/config/permanent_data.sh new file mode 100644 index 00000000..7dfaa647 --- /dev/null +++ b/wazuh-opendistro/config/permanent_data.sh @@ -0,0 +1,40 @@ +#!/bin/bash +# Wazuh App Copyright (C) 2020 Wazuh Inc. (License GPLv2) + +# Variables +source /permanent_data.env + +WAZUH_INSTALL_PATH=/var/ossec +DATA_TMP_PATH=${WAZUH_INSTALL_PATH}/data_tmp +mkdir ${DATA_TMP_PATH} + +# Move exclusion files to EXCLUSION_PATH +EXCLUSION_PATH=${DATA_TMP_PATH}/exclusion +mkdir ${EXCLUSION_PATH} + +for exclusion_file in "${PERMANENT_DATA_EXCP[@]}"; do + # Create the directory for the exclusion file if it does not exist + DIR=$(dirname "${exclusion_file}") + if [ ! -e ${EXCLUSION_PATH}/${DIR} ] + then + mkdir -p ${EXCLUSION_PATH}/${DIR} + fi + + mv ${exclusion_file} ${EXCLUSION_PATH}/${exclusion_file} +done + +# Move permanent files to PERMANENT_PATH +PERMANENT_PATH=${DATA_TMP_PATH}/permanent +mkdir ${PERMANENT_PATH} + +for permanent_dir in "${PERMANENT_DATA[@]}"; do + # Create the directory for the permanent file if it does not exist + DIR=$(dirname "${permanent_dir}") + if [ ! -e ${PERMANENT_PATH}${DIR} ] + then + mkdir -p ${PERMANENT_PATH}${DIR} + fi + + mv ${permanent_dir} ${PERMANENT_PATH}${permanent_dir} + +done diff --git a/wazuh-opendistro/config/wazuh.repo b/wazuh-opendistro/config/wazuh.repo new file mode 100644 index 00000000..ae462c62 --- /dev/null +++ b/wazuh-opendistro/config/wazuh.repo @@ -0,0 +1,7 @@ +[wazuh_repo] +gpgcheck=1 +gpgkey=https://packages.wazuh.com/key/GPG-KEY-WAZUH +enabled=1 +name=Wazuh repository +baseurl=https://packages.wazuh.com/3.x/yum/ +protect=1