Difference between revisions of "Wazuh"

From UVOO Tech Wiki
Jump to navigation Jump to search
Line 51: Line 51:
 
systemctl restart wazuh-manager
 
systemctl restart wazuh-manager
 
```
 
```
 +
### Agent Install with reg pass
 +
- https://documentation.wazuh.com/current/user-manual/deployment-variables/deployment-variables-linux.html
  
 
## Get token for agent
 
## Get token for agent

Revision as of 13:22, 23 January 2024

https://documentation.wazuh.com/current/installation-guide/wazuh-server/step-by-step.html

https://documentation.wazuh.com/current/installation-guide/wazuh-agent/wazuh-agent-package-windows.html

https://packages.wazuh.com/4.x/windows/wazuh-agent-4.7.2-1.msi

https://documentation.wazuh.com/current/user-manual/api/getting-started.html

https://documentation.wazuh.com/current/user-manual/agent-enrollment/via-manager-API/requesting-the-key.html

CPu & Memory Requirements

Compare

https://logz.io/blog/open-source-hids/

Install Server/Manager

1

apt-get install gnupg apt-transport-https && curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg && echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee -a /etc/apt/sources.list.d/wazuh.list && apt-get update && apt-get -y install wazuh-manager

2

systemctl daemon-reload
systemctl enable wazuh-manager
systemctl start wazuh-manager

3

systemctl status wazuh-manager

Install Agent

Download

Windows

https://packages.wazuh.com/4.x/windows/wazuh-agent-4.7.2-1.msi

Auto Registration with pass

echo "secretregpass" > /var/ossec/etc/authd.pass
chmod 640 /var/ossec/etc/authd.pass
chown root:wazuh /var/ossec/etc/authd.pass
systemctl restart wazuh-manager

Agent Install with reg pass

Get token for agent

domain=example.com
TOKEN=$(curl -u wazuh:wazuh -k -X POST "https://wazuh.$domain:55000/security/user/authenticate?raw=true")
curl -k -X POST -d '{"name":"ws-w10"}' "https://wazuh.$domain:55000/agents?pretty=true" -H "Content-Type:application/json" -H "Authorization: Bearer $TOKEN"
/var/ossec/bin/agent_control -l

File integrity