forked from wazuh/wazuh-docker
Compare commits
11
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
61d3f460be | ||
|
|
9ed503b6e8 | ||
|
|
274d6248d3 | ||
|
|
b47f723285 | ||
|
|
b99d54eb25 | ||
|
|
2b0f2955d0 | ||
|
|
38644d380c | ||
|
|
86bc43a494 | ||
|
|
8e5ad87619 | ||
|
|
2bd0138d6f | ||
|
|
b06e4c4a5e |
@@ -1,6 +1,24 @@
|
|||||||
# Change Log
|
# Change Log
|
||||||
All notable changes to this project will be documented in this file.
|
All notable changes to this project will be documented in this file.
|
||||||
|
|
||||||
|
## Wazuh Docker v3.8.2_6.7.0
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Update Elastic Stack version to 6.7.0. ([#144](https://github.com/wazuh/wazuh-docker/pull/144))
|
||||||
|
|
||||||
|
## Wazuh Docker v3.8.2_6.6.2
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Update Elastic Stack version to 6.6.2. ([#130](https://github.com/wazuh/wazuh-docker/pull/130))
|
||||||
|
|
||||||
|
## Wazuh Docker v3.8.2_6.6.1
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Update Elastic Stack version to 6.6.1. ([#129](https://github.com/wazuh/wazuh-docker/pull/129))
|
||||||
|
|
||||||
## Wazuh Docker v3.8.2_6.5.4
|
## Wazuh Docker v3.8.2_6.5.4
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
@@ -11,8 +11,9 @@ In this repository you will find the containers to run:
|
|||||||
* wazuh-logstash: It is used to receive alerts generated by the manager and feed Elasticsearch using an alerts template
|
* wazuh-logstash: It is used to receive alerts generated by the manager and feed Elasticsearch using an alerts template
|
||||||
* wazuh-kibana: Provides a web user interface to browse through alerts data. It includes Wazuh plugin for Kibana, that allows you to visualize agents configuration and status.
|
* wazuh-kibana: Provides a web user interface to browse through alerts data. It includes Wazuh plugin for Kibana, that allows you to visualize agents configuration and status.
|
||||||
* wazuh-nginx: Proxies the Kibana container, adding HTTPS (via self-signed SSL certificate) and [Basic authentication](https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#Basic_authentication_scheme).
|
* wazuh-nginx: Proxies the Kibana container, adding HTTPS (via self-signed SSL certificate) and [Basic authentication](https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#Basic_authentication_scheme).
|
||||||
|
* wazuh-elasticsearch: An Elasticsearch container (working as a single-node cluster) using Elastic Stack Docker images. **Be aware to increase the `vm.max_map_count` setting, as it's detailed in the [Wazuh documentation](https://documentation.wazuh.com/current/docker/wazuh-container.html#increase-max-map-count-on-your-host-linux).**
|
||||||
|
|
||||||
In addition, a docker-compose file is provided to launch the containers mentioned above. It also launches an Elasticsearch container (working as a single-node cluster) using Elastic Stack Docker images.
|
In addition, a docker-compose file is provided to launch the containers mentioned above.
|
||||||
|
|
||||||
## Documentation
|
## Documentation
|
||||||
|
|
||||||
@@ -58,9 +59,9 @@ In addition, a docker-compose file is provided to launch the containers mentione
|
|||||||
|
|
||||||
## Branches
|
## Branches
|
||||||
|
|
||||||
* `stable` branch on correspond to the last Wazuh-Docker stable version.
|
* `stable` branch on correspond to the latest Wazuh-Docker stable version.
|
||||||
* `master` branch contains the latest code, be aware of possible bugs on this branch.
|
* `master` branch contains the latest code, be aware of possible bugs on this branch.
|
||||||
* `Wazuh.Version_ElasticStack.Version` (for example 3.7.0_6.4.3) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch.
|
* `Wazuh.Version_ElasticStack.Version` (for example 3.8.2_6.7.0) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch.
|
||||||
|
|
||||||
## Credits and Thank you
|
## Credits and Thank you
|
||||||
|
|
||||||
|
|||||||
@@ -1,2 +1,2 @@
|
|||||||
WAZUH-DOCKER_VERSION="3.8.2_6.5.4"
|
WAZUH-DOCKER_VERSION="3.8.2_6.7.0"
|
||||||
REVISION="3802"
|
REVISION="3803"
|
||||||
|
|||||||
+5
-5
@@ -3,7 +3,7 @@ version: '2'
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
wazuh:
|
wazuh:
|
||||||
image: wazuh/wazuh:3.8.2_6.5.4
|
image: wazuh/wazuh:3.8.2_6.7.0
|
||||||
hostname: wazuh-manager
|
hostname: wazuh-manager
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
@@ -14,7 +14,7 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
- logstash
|
- logstash
|
||||||
logstash:
|
logstash:
|
||||||
image: wazuh/wazuh-logstash:3.8.2_6.5.4
|
image: wazuh/wazuh-logstash:3.8.2_6.7.0
|
||||||
hostname: logstash
|
hostname: logstash
|
||||||
restart: always
|
restart: always
|
||||||
links:
|
links:
|
||||||
@@ -26,7 +26,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- LS_HEAP_SIZE=2048m
|
- LS_HEAP_SIZE=2048m
|
||||||
elasticsearch:
|
elasticsearch:
|
||||||
image: wazuh/wazuh-elasticsearch:3.8.2_6.5.4
|
image: wazuh/wazuh-elasticsearch:3.8.2_6.7.0
|
||||||
hostname: elasticsearch
|
hostname: elasticsearch
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
@@ -43,7 +43,7 @@ services:
|
|||||||
hard: -1
|
hard: -1
|
||||||
mem_limit: 2g
|
mem_limit: 2g
|
||||||
kibana:
|
kibana:
|
||||||
image: wazuh/wazuh-kibana:3.8.2_6.5.4
|
image: wazuh/wazuh-kibana:3.8.2_6.7.0
|
||||||
hostname: kibana
|
hostname: kibana
|
||||||
restart: always
|
restart: always
|
||||||
depends_on:
|
depends_on:
|
||||||
@@ -52,7 +52,7 @@ services:
|
|||||||
- elasticsearch:elasticsearch
|
- elasticsearch:elasticsearch
|
||||||
- wazuh:wazuh
|
- wazuh:wazuh
|
||||||
nginx:
|
nginx:
|
||||||
image: wazuh/wazuh-nginx:3.8.2_6.5.4
|
image: wazuh/wazuh-nginx:3.8.2_6.7.0
|
||||||
hostname: nginx
|
hostname: nginx
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
||||||
FROM docker.elastic.co/elasticsearch/elasticsearch:6.5.4
|
FROM docker.elastic.co/elasticsearch/elasticsearch:6.7.0
|
||||||
|
|
||||||
ENV ALERTS_SHARDS="1" \
|
ENV ALERTS_SHARDS="1" \
|
||||||
ALERTS_REPLICAS="0"
|
ALERTS_REPLICAS="0"
|
||||||
@@ -23,7 +23,7 @@ COPY --chown=elasticsearch:elasticsearch ./config/load_settings.sh ./
|
|||||||
|
|
||||||
RUN chmod +x ./load_settings.sh
|
RUN chmod +x ./load_settings.sh
|
||||||
|
|
||||||
RUN elasticsearch-plugin install --batch repository-s3
|
RUN bin/elasticsearch-plugin install --batch https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-6.7.0.zip
|
||||||
|
|
||||||
COPY config/configure_s3.sh ./config/configure_s3.sh
|
COPY config/configure_s3.sh ./config/configure_s3.sh
|
||||||
RUN chmod 755 ./config/configure_s3.sh
|
RUN chmod 755 ./config/configure_s3.sh
|
||||||
|
|||||||
+25
-13
@@ -1,10 +1,16 @@
|
|||||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
||||||
FROM docker.elastic.co/kibana/kibana-oss:6.5.4
|
FROM docker.elastic.co/kibana/kibana:6.7.0
|
||||||
ARG WAZUH_APP_VERSION=3.8.2_6.5.4
|
ARG WAZUH_APP_VERSION=3.8.2_6.7.0
|
||||||
USER root
|
USER root
|
||||||
|
|
||||||
COPY config/entrypoint.sh ./entrypoint.sh
|
ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp
|
||||||
RUN chmod 755 ./entrypoint.sh
|
|
||||||
|
RUN NODE_OPTIONS="--max-old-space-size=3072" /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip &&\
|
||||||
|
chown -R kibana:kibana /usr/share/kibana &&\
|
||||||
|
rm -rf /tmp/*
|
||||||
|
|
||||||
|
COPY config/entrypoint.sh /entrypoint.sh
|
||||||
|
RUN chmod 755 /entrypoint.sh
|
||||||
|
|
||||||
USER kibana
|
USER kibana
|
||||||
|
|
||||||
@@ -35,6 +41,14 @@ ENV PATTERN="" \
|
|||||||
WAZUH_MONITORING_REPLICAS="" \
|
WAZUH_MONITORING_REPLICAS="" \
|
||||||
ADMIN_PRIVILEGES=""
|
ADMIN_PRIVILEGES=""
|
||||||
|
|
||||||
|
ARG XPACK_CANVAS="true"
|
||||||
|
ARG XPACK_LOGS="true"
|
||||||
|
ARG XPACK_INFRA="true"
|
||||||
|
ARG XPACK_ML="true"
|
||||||
|
ARG XPACK_DEVTOOLS="true"
|
||||||
|
ARG XPACK_MONITORING="true"
|
||||||
|
ARG XPACK_APM="true"
|
||||||
|
|
||||||
ARG CHANGE_WELCOME="false"
|
ARG CHANGE_WELCOME="false"
|
||||||
|
|
||||||
COPY --chown=kibana:kibana ./config/wazuh_app_config.sh ./
|
COPY --chown=kibana:kibana ./config/wazuh_app_config.sh ./
|
||||||
@@ -45,6 +59,12 @@ COPY --chown=kibana:kibana ./config/kibana_settings.sh ./
|
|||||||
|
|
||||||
RUN chmod +x ./kibana_settings.sh
|
RUN chmod +x ./kibana_settings.sh
|
||||||
|
|
||||||
|
COPY --chown=kibana:kibana ./config/xpack_config.sh ./
|
||||||
|
|
||||||
|
RUN chmod +x ./xpack_config.sh
|
||||||
|
|
||||||
|
RUN ./xpack_config.sh
|
||||||
|
|
||||||
COPY --chown=kibana:kibana ./config/welcome_wazuh.sh ./
|
COPY --chown=kibana:kibana ./config/welcome_wazuh.sh ./
|
||||||
|
|
||||||
RUN chmod +x ./welcome_wazuh.sh
|
RUN chmod +x ./welcome_wazuh.sh
|
||||||
@@ -53,12 +73,4 @@ RUN ./welcome_wazuh.sh
|
|||||||
|
|
||||||
RUN /usr/local/bin/kibana-docker --optimize
|
RUN /usr/local/bin/kibana-docker --optimize
|
||||||
|
|
||||||
ENTRYPOINT ./entrypoint.sh
|
ENTRYPOINT /entrypoint.sh
|
||||||
|
|
||||||
USER root
|
|
||||||
|
|
||||||
ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp
|
|
||||||
|
|
||||||
RUN NODE_OPTIONS="--max-old-space-size=3072" /usr/share/kibana/bin/kibana-plugin install file:///tmp/wazuhapp-${WAZUH_APP_VERSION}.zip &&\
|
|
||||||
chown -R kibana:kibana /usr/share/kibana &&\
|
|
||||||
rm -rf /tmp/*
|
|
||||||
|
|||||||
@@ -19,15 +19,7 @@ WAZUH_MAJOR=3
|
|||||||
# Customize elasticsearch ip
|
# Customize elasticsearch ip
|
||||||
##############################################################################
|
##############################################################################
|
||||||
if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then
|
if [ "$ELASTICSEARCH_KIBANA_IP" != "" ]; then
|
||||||
sed -i 's|http://elasticsearch:9200|'$ELASTICSEARCH_KIBANA_IP'|g' /usr/share/kibana/config/kibana.yml
|
sed -i "s/elasticsearch:9200/$ELASTICSEARCH_KIBANA_IP:9200/" /usr/share/kibana/config/kibana.yml
|
||||||
fi
|
|
||||||
|
|
||||||
# If KIBANA_INDEX was set, then change the default index in kibana.yml configuration file. If there was an index, then delete it and recreate.
|
|
||||||
if [ "$KIBANA_INDEX" != "" ]; then
|
|
||||||
if grep -q 'kibana.index' /usr/share/kibana/config/kibana.yml; then
|
|
||||||
sed -i '/kibana.index/d' /usr/share/kibana/config/kibana.yml
|
|
||||||
fi
|
|
||||||
echo "kibana.index: $KIBANA_INDEX" >> /usr/share/kibana/config/kibana.yml
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ "$KIBANA_IP" != "" ]; then
|
if [ "$KIBANA_IP" != "" ]; then
|
||||||
|
|||||||
@@ -0,0 +1,36 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
kibana_config_file="/usr/share/kibana/config/kibana.yml"
|
||||||
|
if grep -Fq "#xpack features" "$kibana_config_file";
|
||||||
|
then
|
||||||
|
declare -A CONFIG_MAP=(
|
||||||
|
[xpack.apm.ui.enabled]=$XPACK_APM
|
||||||
|
[xpack.grokdebugger.enabled]=$XPACK_DEVTOOLS
|
||||||
|
[xpack.searchprofiler.enabled]=$XPACK_DEVTOOLS
|
||||||
|
[xpack.ml.enabled]=$XPACK_ML
|
||||||
|
[xpack.canvas.enabled]=$XPACK_CANVAS
|
||||||
|
[xpack.logstash.enabled]=$XPACK_LOGS
|
||||||
|
[xpack.infra.enabled]=$XPACK_INFRA
|
||||||
|
[xpack.monitoring.enabled]=$XPACK_MONITORING
|
||||||
|
[console.enabled]=$XPACK_DEVTOOLS
|
||||||
|
)
|
||||||
|
for i in "${!CONFIG_MAP[@]}"
|
||||||
|
do
|
||||||
|
if [ "${CONFIG_MAP[$i]}" != "" ]; then
|
||||||
|
sed -i 's/.'"$i"'.*/'"$i"': '"${CONFIG_MAP[$i]}"'/' $kibana_config_file
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
else
|
||||||
|
echo "
|
||||||
|
#xpack features
|
||||||
|
xpack.apm.ui.enabled: $XPACK_APM
|
||||||
|
xpack.grokdebugger.enabled: $XPACK_DEVTOOLS
|
||||||
|
xpack.searchprofiler.enabled: $XPACK_DEVTOOLS
|
||||||
|
xpack.ml.enabled: $XPACK_ML
|
||||||
|
xpack.canvas.enabled: $XPACK_CANVAS
|
||||||
|
xpack.logstash.enabled: $XPACK_LOGS
|
||||||
|
xpack.infra.enabled: $XPACK_INFRA
|
||||||
|
xpack.monitoring.enabled: $XPACK_MONITORING
|
||||||
|
console.enabled: $XPACK_DEVTOOLS
|
||||||
|
" >> $kibana_config_file
|
||||||
|
fi
|
||||||
+1
-1
@@ -1,5 +1,5 @@
|
|||||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
||||||
FROM docker.elastic.co/logstash/logstash:6.5.4
|
FROM docker.elastic.co/logstash/logstash:6.7.0
|
||||||
|
|
||||||
COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh
|
COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh
|
||||||
|
|
||||||
|
|||||||
@@ -17,16 +17,6 @@ else
|
|||||||
el_url="${ELASTICSEARCH_URL}"
|
el_url="${ELASTICSEARCH_URL}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
##############################################################################
|
|
||||||
# Customize logstash output ip
|
|
||||||
##############################################################################
|
|
||||||
|
|
||||||
if [ "$LOGSTASH_OUTPUT" != "" ]; then
|
|
||||||
>&2 echo "Customize Logstash ouput ip."
|
|
||||||
sed -i 's|elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/pipeline/01-wazuh.conf
|
|
||||||
sed -i 's|http://elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/config/logstash.yml
|
|
||||||
fi
|
|
||||||
|
|
||||||
until curl -XGET $el_url; do
|
until curl -XGET $el_url; do
|
||||||
>&2 echo "Elastic is unavailable - sleeping."
|
>&2 echo "Elastic is unavailable - sleeping."
|
||||||
sleep 5
|
sleep 5
|
||||||
@@ -54,6 +44,16 @@ sleep 2
|
|||||||
|
|
||||||
>&2 echo "Wazuh alerts template is loaded."
|
>&2 echo "Wazuh alerts template is loaded."
|
||||||
|
|
||||||
|
##############################################################################
|
||||||
|
# Customize logstash output ip
|
||||||
|
##############################################################################
|
||||||
|
|
||||||
|
if [ "$LOGSTASH_OUTPUT" != "" ]; then
|
||||||
|
>&2 echo "Customize Logstash ouput ip."
|
||||||
|
sed -i "s/elasticsearch:9200/$LOGSTASH_OUTPUT:9200/" /usr/share/logstash/pipeline/01-wazuh.conf
|
||||||
|
sed -i "s/elasticsearch:9200/$LOGSTASH_OUTPUT:9200/" /usr/share/logstash/config/logstash.yml
|
||||||
|
fi
|
||||||
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
# Map environment variables to entries in logstash.yml.
|
# Map environment variables to entries in logstash.yml.
|
||||||
# Note that this will mutate logstash.yml in place if any such settings are found.
|
# Note that this will mutate logstash.yml in place if any such settings are found.
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
||||||
FROM phusion/baseimage:latest
|
FROM phusion/baseimage:latest
|
||||||
ARG FILEBEAT_VERSION=6.5.4
|
ARG FILEBEAT_VERSION=6.7.0
|
||||||
ARG WAZUH_VERSION=3.8.2-1
|
ARG WAZUH_VERSION=3.8.2-1
|
||||||
|
|
||||||
ENV API_USER="foo" \
|
ENV API_USER="foo" \
|
||||||
|
|||||||
Reference in New Issue
Block a user