āĻĒā§āϰāϤāĻŋāύāĻŋāϝāĻŧāϤ āϏāĻžāĻāĻŦāĻžāϰ āĻ ā§āϝāĻāĻžāĻā§āϰ āϏāĻāĻā§āϝāĻž āĻŦā§āĻĻā§āϧāĻŋāϰ āĻĢāϞ⧠āĻāĻŽāĻžāĻĻā§āϰ āύāĻŋāϰāĻžāĻĒāϤā§āϤāĻž āĻŦā§āϝāĻŦāϏā§āĻĨāĻžāϰ āĻāύā§āύāϤāĻŋāϰ āĻĒā§āϰāϝāĻŧā§āĻāύā§āϝāĻŧāϤāĻž āĻāĻĒāϞāĻŦā§āϧāĻŋ āĻāϰāϤ⧠āĻĒāĻžāϰāĻŋāĨ¤ āĻŦāϰā§āϤāĻŽāĻžāύ āϏāĻžāĻāĻŦāĻžāϰ āĻāϝāĻŧāĻžāϰā§āϞā§āĻĄā§ āύāĻŋāϰāĻžāĻĒāĻĻ āĻĨāĻžāĻāϤ⧠āĻĒā§āϰāϝāĻŧā§āĻāύ âāϏāĻ āĻŋāĻ āύāĻŋāϰāĻžāĻĒāϤā§āϤāĻž āĻŦā§āϝāĻŦāϏā§āĻĨāĻž āĻāĻŦāĻ āĻŽāύāĻŋāĻāϰāĻŋāĻ āϏāĻŋāϏāĻā§āĻŽāĨ¤ āĻāĻāĻāĻŋ āĻāύāĻĢā§āϰāĻžāϏā§āĻā§āϰāĻžāĻāĻāĻžāϰ āĻāϰ āϏāĻŋāĻāĻŋāĻāϰāĻŋāĻāĻŋ āĻŽāύāĻŋāĻāϰāĻŋāĻ āĻā§āϰā§āϤā§āϤāĻĒā§āϰā§āĻŖ āĻāĻāĻāĻŋ āĻāĻžāĻāĨ¤ āĻāĻŽāϰāĻž āĻāĻāĻāĻŋ Open-Source SIEM Solution āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰ⧠Log Analysis āĻāϰāĻŦ āĻāĻŦāĻ āĻāϰ Installation Process āĻĻā§āĻāĻŦāĨ¤
āĻ āĻĒāϰā§āĻŦā§ āĻāĻŽāϰāĻž āĻļā§āϧ⧠Wazuh āĻāύāϏā§āĻāϞā§āĻļāύ āϏā§āĻā§āϰāĻžāĻāĻāĻžāϰ āϏāĻŽā§āĻĒāϰā§āĻā§ āĻāĻžāύāĻŦ, āĻāĻŋāĻāĻžāĻŦā§ āĻāĻžāĻ āĻāϰā§, āĻāĻŋāĻāĻžāĻŦā§ āĻāύā§āϏāĻāϞ āĻāϰāϤ⧠āĻšāϝāĻŧ āĻāϤā§āϝāĻžāĻĻāĻŋ āĻŦāĻŋāώāϝāĻŧā§ āϧāĻžāϰāĻŖāĻž āύāĻŋāĻŦā§āĨ¤
Wazuh āĻšāϞ⧠OSSEC āĻāϰ SIEM Solution based āĻāĻāĻāĻŋ Opensource SIEM Solution. āĻĒā§āϰ⧠SIEM Solution āĻ Wazuh-manager, Wazuh-agent, Filebeat, Kibana, Elasticsearch āĻāϰ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰāĻž āĻšāϝāĻŧāĨ¤ āĻ āϏāĻžāϰā§āĻāĻŋāϏāĻā§āϞ⧠āĻĒā§āϰāϤāĻŋāĻāĻŋ āĻāϞāĻžāĻĻāĻž āĻāϞāĻžāĻĻāĻžāĻāĻžāĻŦā§ āĻāύāϏā§āĻāϞ āĻāϰ⧠āĻāĻāĻāĻŋāϰ āϏāĻžāĻĨā§ āĻāϰā§āĻāĻāĻŋāϰ āϏāĻŽāύā§āĻŦāϝāĻŧ āĻāϰāϤ⧠āĻšāϝāĻŧāĨ¤
āĻāĻŽāϰāĻž āϏāĻāϞ āϏāĻžāϰā§āĻāĻŋāϏ āĻāĻāĻāĻŋ āĻŽā§āĻļāĻŋāύ⧠āĻāύāϏā§āĻāϞ āĻāϰāĻŦā§ āĻāĻŦāĻ āĻāĻāĻāĻŋ āĻāĻā§āύā§āĻ āĻ āύā§āϝ āĻāĻāĻāĻŋ āĻŽā§āĻļāĻŋāύ⧠āĻāύāϏā§āĻāϞ āĻāϰāĻŦā§āĨ¤

āĻāĻ āĻĒā§āϰāϏā§āϏāĻāĻŋāϰ āύāĻžāĻŽ āĻ āϞ āĻāύ āĻāϝāĻŧāĻžāύ āĻĄāĻŋāĻĒā§āϞāϝāĻŧāĻŽā§āύā§āĻāĨ¤ āĻāĻŽāϰāĻž āĻāύāϏā§āĻāϞā§āĻļāύ āĻāϰ āĻāύā§āϝ Wazuh āĻāϰ āĻ āĻĢāĻŋāϏāĻŋāϝāĻŧāĻžāϞ āĻĄāĻā§āĻŽā§āύā§āĻ āĻ āύā§āϏāϰāĻŖ āĻāϰāĻŦā§āĨ¤ āϏāĻŽā§āĻĒā§āϰā§āĻŖ āĻāύā§āϏāĻāϞā§āĻļāύā§āϰ āĻāύā§āϝ āĻāĻžāϰā§āĻā§āϝāĻŧāĻžāϞāĻŦāĻā§āϏ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰāĻŦāĨ¤ āĻāĻĒāϰ⧠āĻĄāĻŋāĻāĻžāĻāύ āĻāϰā§āĻāĻŋāĻā§āĻāĻāĻžāϰ āĻĻā§āĻā§ āĻŦā§āĻāĻž āϝāĻžāĻā§āĻā§, āϏāĻāϞ āϏāĻžāϰā§āĻāĻŋāϏ āĻāύā§āϏāĻāϞā§āĻļāύā§āϰ āĻāύā§āϝ āĻāĻāĻāĻŋ āĻŽāĻžāϤā§āϰ āĻ āĻĒāĻžāϰā§āĻāĻŋāĻ āϏāĻŋāϏā§āĻā§āĻŽ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰāĻž āĻšāĻŦā§āĨ¤ āϏāĻŽā§āĻĒā§āϰā§āĻŖ āĻĒā§āϰāϏā§āϏāĻāĻŋ āĻāĻŽāϰāĻž āĻāĻžāϰā§āĻā§āϝāĻŧāĻžāϞāĻŦāĻā§āϏ⧠āϏāĻŋāĻŽā§āϞā§āĻ āĻāϰāĻŦāĨ¤ āϝāĻĻāĻŋāĻ āĻšā§āϏā§āĻ āĻŽā§āĻļāĻŋāύ⧠āĻāĻ āϏāĻžāĻĨā§ āϏāĻāϞ āϏāĻžāϰā§āĻāĻŋāϏ āĻāύā§āϏāĻāϞ āĻāϰāĻŦ, āϤāĻĻā§āĻĒāϰāĻŋ āĻāϰ āĻŽāĻžāĻā§ āĻāĻŋāĻā§ āĻĒā§āϰāϏā§āϏ āϧāĻžāĻĒā§ āϧāĻžāĻĒā§ āϏāĻŽā§āĻĒāύā§āύ āĻšāϝāĻŧā§ āĻĨāĻžāĻā§āĨ¤ āĻ āϰā§āĻĨāĻžā§, āĻāĻā§āύā§āĻ āĻĨā§āĻā§ āϞāĻ āĻāĻžāϞā§āĻāĻļāύ āĻāϰ⧠Wazuh-Manager āĻāϰ āĻāĻžāĻā§ āϞāĻ āĻĒāĻžāĻ āĻžāύ⧠āĻāĻŦāĻ āϞāĻ Visualization āĻāϰ āĻŽāĻžāĻā§ āϝ⧠āĻĒā§āϰāϏā§āϏāĻā§āϞ⧠āĻšāϝāĻŧ āϤāĻžāϰ āĻāĻāĻāĻŋ āϏāĻžāĻŽāĻžāϰāĻŋ āϤā§āϞ⧠āϧāϰāĻāĻŋāĨ¤

Wazuh-Agent āĻĨā§āĻā§ āϞāĻ āύāĻŋāϝāĻŧā§ Wazuh-manager āĻ āĻĒāĻžāĻ āĻžāύ⧠āĻšāϝāĻŧ, Wazuh-manager āĻ āϏā§āĻ āĻāϰāĻž āϰā§āϞāϏ āĻ āύā§āϝāĻžāϝāĻŧā§ āϞāĻ āĻā§āϞ⧠āĻĒā§āϰāϏā§āϏ āĻāϰ⧠Filebeat āĻāϰ āϏāĻžāĻšāĻžāϝā§āϝ⧠Elasticsearch āĻāϰ āĻāĻžāĻā§ āĻĒāĻžāĻ āĻžāύ⧠āĻšāϝāĻŧāĨ¤ Elasticsearch āĻāĻāĻžāύ⧠Database āĻāϰ āĻŽāϤ āĻāĻžāĻ āĻāϰā§āĨ¤ Elasticsearch āϞāĻ āĻā§āϞ⧠Kibana āϤ⧠āĻĒāĻžāĻ āĻžāϝāĻŧ, āĻāϰ āĻĒāϰ Kibana āĻāϰ āĻŽāĻžāϧā§āϝāĻŽā§ āϞāĻ āĻā§āϞ⧠āĻĄā§āϝāĻžāĻļāĻŦā§āϰā§āĻĄ āĻ āĻŦā§āϧāĻāĻŽā§āϝāĻāĻžāĻŦā§ āĻāĻĒāϏā§āĻĨāĻžāĻĒāύ āĻāϰāĻž āĻšāϝāĻŧāĨ¤
āϏāĻŽā§āĻĒā§āϰā§āĻŖ āĻĒā§āϰā§āϏā§āϏāĻāĻŋ āϏāĻŋāĻŽā§āϞā§āĻ āĻāϰāϤ⧠Operating System āĻšāĻŋāϏā§āĻŦā§ Ubuntu āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰāĻŦāĨ¤
Ubuntu āĻāĻŽāϰāĻž āĻšā§āϏā§āĻ āĻŽā§āĻļāĻŋāύ āĻšāĻŋāϏā§āĻŦā§ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰāĻŦāĨ¤ āĻāĻžāϰā§āĻā§āϝāĻŧāĻžāϞ āĻŦāĻā§āϏ⧠OS āĻāĻŋāϤ⧠Minimum 2 GB RAM, 1 āĻāĻŋ CPU āĻĻāĻŋāϤ⧠āĻšāĻŦā§, āϝā§āĻšā§āϤ⧠āϏā§āĻāĻžāύ⧠āϏāĻāϞ Service Install āĻšāĻŦā§āĨ¤ Network Adapter āĻ Bridge Adapter (Host/main OS āĻāϰ āϏāĻžāĻĨā§ Communicate āĻāϰāϤ⧠āĻāĻžāĻāϞā§) āĻ āĻĨāĻŦāĻž Nat-Network āϰā§āĻā§, Allow VMs āĻ āĻĨāĻŦāĻž Allow All āĻāϰāϤ⧠āĻšāĻŦā§āĨ¤
āĻāĻ āϧāĻžāĻĒā§ āĻāĻŽāϰāĻž āĻļā§āϧ⧠āĻšā§āϏā§āĻ āĻŽā§āĻļāĻŋāύ āϰā§āĻĄāĻŋ āĻāϰāĻŦāĨ¤ āĻ āϰā§āĻĨāĻžā§ Wazuh-Manager, Filebeat, Elasticsearch, Kibana āĻāĻā§āϞ⧠install āĻāϰ⧠āĻšā§āϏā§āĻ āĻŽā§āĻļāĻŋāύ āϰā§āĻĄāĻŋ āĻāϰāĻŦāĨ¤
āĻāύā§āϏāĻāϞā§āĻļāύā§āϰ āĻĒā§āϰāĻĨāĻŽ āϧāĻžāĻĒā§, Ubuntu āĻŽā§āĻļāĻŋāύ āĻāĻĒāĻĄā§āĻ āĻāϰ⧠āύāĻŋāϤ⧠āĻšāĻŦā§, āĻāϰ āĻĒāϰ āϏāĻŋāϰāĻŋāϝāĻŧāĻžāϞ āĻ āύā§āϝāĻžāϝāĻŧā§ āĻāĻāĻāĻžāϰ āĻĒāϰ āĻāĻāĻāĻž Command āĻĻāĻŋāϝāĻŧā§ āϝā§āϤ⧠āĻšāĻŦā§āĨ¤
Command āĻā§āϞ⧠Run āĻāϰāĻžāϰ āϏāĻŽāϝāĻŧ Administrative privilege āĻĒā§āϰāϝāĻŧā§āĻāύ āĻšāĻŦā§āĨ¤
āĻĒā§āϰāĻĨāĻŽā§ āĻāĻŽāϰāĻž Elasticsearch āĻāύā§āϏāĻāϞ āĻāϰāĻŦ
Installation āĻāϰ āĻļā§āϰā§āϤ⧠āĻĒā§āϝāĻžāĻā§āĻāĻā§āϞ⧠Install āĻāϰ⧠āύāĻŋāϤ⧠āĻšāĻŦā§
apt-get install apt-transport-https zip unzip lsb-release curl gnupg
ā§§āĨ¤ Install GPG Key
curl -s https://artifacts.elastic.co/GPG-KEY-elasticsearch | gpg âno-default-keyring âkeyring gnupg-ring:/usr/share/keyrings/elasticsearch.gpg âimport && chmod 644 /usr/share/keyrings/elasticsearch.gpg
2. Repo Add āĻāϰāĻŦāĨ¤
echo âdeb [signed-by=/usr/share/keyrings/elasticsearch.gpg] https://artifacts.elastic.co/packages/7.x/apt stable mainâ | tee /etc/apt/sources.list.d/elastic-7.x.list
ā§ŠāĨ¤ āĻāĻĒāĻĄā§āĻ āĻāϰ⧠āύāĻŋāĻŦāĨ¤
apt-get update
āĻāĻŽāĻžāĻĻā§āϰ āĻŽā§āĻļāĻŋāύ āĻāĻāύ Elasticsearch Install āĻāϰ āĻāύā§āϝ āĻĒā§āϰāϏā§āϤā§āϤāĨ¤
āĻāĻāύ Elasticsearch Install āĻāĻŦāĻ Configure āĻāϰāĻŦāĨ¤
ā§§āĨ¤ Elasticsearch āĻĒāĻžāĻā§āĻāĻā§āϞ⧠āĻāύā§āϏāĻāϞ āĻāϰ⧠āύāĻŋāĻāĨ¤
apt-get install elasticsearch=7.17.9
⧍āĨ¤ Configuration file download āĻāϰāĻŋāĨ¤
curl -so /etc/elasticsearch/elasticsearch.yml https://packages.wazuh.com/4.4/tpl/elastic-basic/elasticsearch_all_in_one.yml
āĻāĻ āĻ āĻāĻļā§ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻ Create āĻāϰāĻž āĻāĻŦāĻ Deploy āĻāϰāĻž āĻĻā§āĻāĻŦ
ā§§āĨ¤ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻ āϤā§āϰā§āϰ āĻāύā§āϝ Configuration āĻĢāĻžāĻāϞ Download āĻāϰāĻŋāĨ¤
curl -so /usr/share/elasticsearch/instances.yml https://packages.wazuh.com/4.4/tpl/elastic-basic/instances_aio.yml
⧍āĨ¤ āύāĻŋāĻā§āϰ āĻāĻŽāĻžāύā§āĻĄ āϰāĻžāύ āĻāϰāϞ⧠elasticsearch-certutil tool āĻāϰ āĻŽāĻžāϧā§āϝāĻŽā§ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻ āϤā§āϰ⧠āĻšāĻŦā§āĨ¤
/usr/share/elasticsearch/bin/elasticsearch-certutil cert ca âpem âin instances.yml âkeep-ca-key âout ~/certs.zip
ā§ŠāĨ¤ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻ āϰā§āĻĄāĻŋ! āĻāĻāύ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻ āĻāϰ zip āĻĢāĻžāĻāϞ unzip āĻāϰāϤ⧠āĻšāĻŦā§āĨ¤
unzip ~/certs.zip -d ~/certs
ā§ĒāĨ¤ āĻāĻ āϧāĻžāĻĒā§ Elasticsearch āĻāϰ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻā§āϰ āĻāύā§āϝ āĻāĻāĻāĻŋ directory āϤā§āϰ⧠āĻāϰāĻŦ āĻāĻŦāĻ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻāĻā§āϞ⧠Directory āϤ⧠āϰāĻžāĻāĻŦāĨ¤
mkdir /etc/elasticsearch/certs/ca -p
cp -R ~/certs/ca/ ~/certs/elasticsearch/* /etc/elasticsearch/certs/
chown -R elasticsearch: /etc/elasticsearch/certs
chmod -R 500 /etc/elasticsearch/certs
chmod 400 /etc/elasticsearch/certs/ca/ca.* /etc/elasticsearch/certs/elasticsearch.*
rm -rf ~/certs/ ~/certs.zip
ā§ĢāĨ¤ āĻāĻāύ Elasticsearch service enable āĻāϰāĻŦ āĻāĻŦāĻ service start āĻāϰāĻŦāĨ¤
systemctl daemon-reload
systemctl enable elasticsearch
systemctl start elasticsearch
ā§ŦāĨ¤ Elasticsearch āĻāϰ āϏāĻāϞ User āĻāĻŦāĻ āĻĒā§āϰāϝāĻŧā§āĻāύā§āϝāĻŧ āϰā§āϞāϏā§āϰ āĻāύā§āϝ credential āϤā§āϰ⧠āĻāϰāĻŦāĨ¤
/usr/share/elasticsearch/bin/elasticsearch-setup-passwords auto
āĻāĻ āĻāĻŽāĻžāύā§āĻĄāĻāĻŋ āύāĻŋāĻā§āϰ āĻŽāϤ āĻāĻāĻāĻĒā§āĻ āĻĻāĻŋāĻŦā§, āĻāĻā§āϞ⧠āϏā§āĻ āĻāϰ⧠āϰāĻžāĻāϤ⧠āĻšāĻŦā§, āĻĒāϰāĻŦāϰā§āϤā§āϤ⧠āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻāϰāĻžāϰ āĻāύā§āϝāĨ¤
Changed password for user apm_system
PASSWORD apm_system = 4w3qt8Q7fC4bs956W84r
Changed password for user kibana_system
PASSWORD kibana_system = CUANVQIaChV6P6U86Ups
Changed password for user kibana
PASSWORD kibana = CUANVQIaChV6P6U86Ups
Changed password for user logstash_system
PASSWORD logstash_system = gz3lCnmLZWsZUQ6uw0F3
Changed password for user beats_system
PASSWORD beats_system = H2Qfc1UUqCvxYSfJcoR2
Changed password for user remote_monitoring_user
PASSWORD remote_monitoring_user = AwbIMfrafL1aM1GKrMQc
Changed password for user elastic
PASSWORD elastic = dQYzrlwVZPhdKANPlHOB
āĻāĻāύ āĻā§āĻ āĻāϰāĻž āϝā§āϤ⧠āĻĒāĻžāϰā§, āϏāĻžāϰā§āĻāĻŋāϏāĻā§āϞ⧠āĻ āĻŋāĻāĻāĻžāĻŦā§ āĻāύā§āϏāĻāϞ āĻšāϞ⧠āĻāĻŋ āύāĻžāĨ¤
[<pass> āĻāϰ āϏā§āĻĨāĻžāύ⧠āϏāĻžāϰā§āĻāĻŋāϏ āĻā§āϞā§āϰ Password āĻĻāĻŋāϤ⧠āĻšāĻŦā§, āϝā§āĻā§āϞ⧠āĻāĻāĻā§ āĻāĻā§ āĻāĻŽāϰāĻž āĻāĻĒāĻŋ āĻāϰ⧠āϰāĻžāĻāϞāĻžāĻŽ (āĻāĻĒāύāĻžāϰ password āĻāĻĒāύāĻŋ āϏā§āĻ āĻāϰ⧠āϰā§āĻā§āĻā§āύ)]
elastic
curl -XGET -u -k
remote monitoring user
curl -XGET -u -k
beast system
curl -XGET -u -k
logsthash system
curl -XGET -u -k
kibana
curl -XGET -u -k
kibana system
curl -XGET -u -k
apm system
curl -XGET -u -k
āĻāĻĒāϰāĻā§āϤ āĻāĻŽāĻžāύā§āĻĄ āĻĻāĻŋāϞ⧠āϏāĻžāϰā§āĻāĻŋāϏāĻā§āϞ⧠āĻāĻžāϞ⧠āĻĨāĻžāĻāϞ⧠āĻāĻŽāύ āĻāĻāĻāĻĒā§āĻ āĻāϏāĻŦā§āĨ¤
root@nayem-VirtualBox:/home/nayem# curl -XGET https://localhost:9200 -u elastic:dQYzrlwVZPhdKANPlHOB -k
{
ânameâ : âelasticsearchâ,
âcluster_nameâ : âelasticsearchâ,
âcluster_uuidâ : âQoGKtHL0QoyPP_IYkw0s-Qâ,
âversionâ : {
ânumberâ : â7.17.9â,
âbuild_flavorâ : âdefaultâ,
âbuild_typeâ : âdebâ,
âbuild_hashâ : âef48222227ee6b9e70e502f0f0daa52435ee634dâ,
âbuild_dateâ : â2023-01-31T05:34:43.305517834Zâ,
âbuild_snapshotâ : false,
âlucene_versionâ : â8.11.1â,
âminimum_wire_compatibility_versionâ : â6.8.0â,
âminimum_index_compatibility_versionâ : â6.0.0-beta1â
},
âtaglineâ : âYou Know, for Searchâ
}
Wazuh-Server āĻāύā§āϏāĻāϞ āĻĒāϰā§āĻŦ
Wazuh repository āĻ ā§āϝāĻžāĻĄ āĻāϰāĻžāϰ āĻ āĻāĻļ
ā§§āĨ¤ GPG Key Install āĻāϰāĻŋāĨ¤
curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg âno-default-keyring âkeyring gnupg-ring:/usr/share/keyrings/wazuh.gpg âimport && chmod 644 /usr/share/keyrings/wazuh.gpg
⧍āĨ¤ Add Repo.
echo âdeb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable mainâ | tee -a /etc/apt/sources.list.d/wazuh.list
ā§ŠāĨ¤ Update āĻāϰ⧠āύāĻŋāĻ
apt-get updat
Wazuh-manager āĻāύā§āϏāĻāϞ āĻĒāϰā§āĻŦ
ā§§āĨ¤ Wazuh-manager āĻĒā§āϝāĻžāĻā§āĻ āĻāύā§āϏāĻāϞ āĻāϰāĻŋ
apt-get install wazuh-manager
⧍āĨ¤ Wazuh-manager āϏāĻžāϰā§āĻāĻŋāϏ Enable & Start
systemctl daemon-reload
systemctl enable wazuh-manager
systemctl start wazuh-manager
ā§ŠāĨ¤ Wazuh-manager āϏāĻžāϰā§āĻāĻŋāϏ āĻāĻžāϞ⧠āĻāĻā§ āĻāĻŋ āύāĻž āĻā§āĻ āĻāϰāĻŋ
systemctl status wazuh-manager
āĻāĻļāĻž āĻāϰāĻāĻŋ Wazuh-manager running āĻāĻā§ āĻāĻŦāĻ āϏāĻŦ āĻāĻŋāĻā§ āĻ āĻŋāĻ āĻ āĻžāĻ Install āĻāϰāϤ⧠āĻĒā§āϰā§āĻā§āύāĨ¤ āĻāĻŦāĻžāϰ āĻĒāϰā§āϰ āϧāĻžāĻĒā§ āĻāĻŽāϰāĻž Fileeat āĻāύā§āϏāĻāϞ āĻāϰāĻŦāĨ¤
Filebeat āĻāύā§āϏāĻāϞ āĻĒāϰā§āĻŦ
ā§§āĨ¤ āύāĻŋāĻā§āϰ āĻāĻŽāĻžāύā§āĻĄā§āϰ āĻŽāĻžāϧā§āϝāĻŽā§ Filebeat āĻĒāĻžāĻā§āĻ āĻāύā§āϏāĻāϞ āĻāϰāĻŋāĨ¤
apt-get install filebeat=7.17.9
⧍āĨ¤ āĻĒā§āϰā§āĻŦā§ āĻĨā§āĻā§ āĻāύāĻĢāĻŋāĻāĻžāϰ āĻāϰāĻž Filebeat āĻāϰ config āĻĢāĻžāĻāϞ āĻāύā§āϏāĻāϞ āĻāϰāĻŦāĨ¤ āĻāϰ āĻŽāĻžāϧā§āϝāĻŽā§ āĻĢāĻžāĻāϞāĻŦāĻŋāĻ Wazuh alert Elasticsearch āĻāϰ āĻāĻžāĻā§ āĻĒāĻžāĻ āĻžāϝāĻŧāĨ¤
curl -so /etc/filebeat/filebeat.yml https://packages.wazuh.com/4.4/tpl/elastic-basic/filebeat_all_in_one.yml
ā§ŠāĨ¤ Elasticsearch āĻāϰ āĻāύā§āϝ Alert Sample āĻĄāĻžāĻāύāϞā§āĻĄ āĻāĻŦāĻ Permission āĻĻā§āĻāϝāĻŧāĻž
curl -so /etc/filebeat/wazuh-template.json https://raw.githubusercontent.com/wazuh/wazuh/4.4/extensions/elasticsearch/7.x/wazuh-template.json
chmod go+r /etc/filebeat/wazuh-template.json
ā§ĒāĨ¤ Filebeat āĻāϰ āĻāύā§āϝ Wazuh Module āĻĄāĻžāĻāύāϞā§āĻĄ
curl -s https://packages.wazuh.com/4.x/filebeat/wazuh-filebeat-0.2.tar.gz | tar -xvz -C /usr/share/filebeat/module
ā§ĢāĨ¤ filebeat.yml āĻĢāĻžāĻāϞāĻāĻŋ āĻāĻĄāĻŋāĻ āĻāϰāĻžāϰ āĻāύā§āϝ āύāĻŋāϰā§āĻĻāĻŋāώā§āĻ āϞā§āĻā§āĻļāĻžāύ⧠āϝā§āϤ⧠āĻšāĻŦā§ āĻāĻŦāĻ āĻĢāĻžāĻāϞāĻāĻŋ āĻāĻĄāĻŋāĻ āĻāϰāϤ⧠āĻšāĻŦā§
nano /etc/filebeat/filebeat.yml
ā§ŦāĨ¤ āĻāĻ āϞāĻžāĻāύāĻāĻŋ āĻāĻĄāĻŋāĻ āĻāϰāϤ⧠āĻšāĻŦā§ <pass> āĻāϰ âāϏā§āĻĨāĻžāύ⧠āĻāĻĒāύāĻžāϰ Elastic password āĻĻāĻŋāϤ⧠āĻšāĻŦā§
output.elasticsearch.password:
āĻāϰ āĻĒāϰ āϏā§āĻ āĻāϰāĻžāϰ āĻāύā§āϝ
[ctrl + o] + enter >> to save
[ctrl + x] >> to exit
ā§āĨ¤ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻāĻā§āϞ⧠āĻāĻĒāĻŋ āĻāϰāĻžāϰ āĻāύā§āϝ
cp -r /etc/elasticsearch/certs/ca/ /etc/filebeat/certs/
cp /etc/elasticsearch/certs/elasticsearch.crt /etc/filebeat/certs/filebeat.crt
cp /etc/elasticsearch/certs/elasticsearch.key /etc/filebeat/certs/filebeat.key
ā§ŽāĨ¤ āĻ āϤāĻāĻĒāϰ Filebeat āϏāĻžāϰā§āĻāĻŋāϏ āϏā§āĻāĻžāϰā§āĻ āĻāϰāĻžāϰ āĻāύā§āϝ āĻāĻŽāĻžāύā§āĻĄ
systemctl daemon-reloadsystemctl enable filebeatsystemctl start filebeat
⧝āĨ¤ Filebeat āĻ āĻŋāĻ āĻŽāϤ āĻāύā§āϏāĻāϞ āĻšāϝāĻŧā§āĻā§ āĻāĻŋ āύāĻž, āϤāĻž āĻĻā§āĻāĻžāϰ āĻāύā§āϝ
filebeat test output
āĻāϰ āĻĒāϰā§āϰ āϧāĻžāĻĒā§ Kibana āĻāύā§āϏāĻāϞ āĻāϰāĻŦ
Kibana āĻāύā§āϏāĻāϞ āĻĒāϰā§āĻŦ
ā§§āĨ¤ Kibana āĻĒā§āϝāĻžāĻā§āĻ āĻāύā§āϏāĻāϞ
apt-get install kibana=7.17.9
⧍āĨ¤ Kibana āĻāύāĻĢāĻŋāĻāĻžāϰā§āĻļāύ āĻĢā§āϞā§āĻĄāĻžāϰ⧠āĻāϞāĻžāϏā§āĻāĻŋāĻāϏāĻžāϰā§āĻ āϏāĻžāϰā§āĻāĻŋāĻĢāĻŋāĻā§āĻ āĻāĻĒāĻŋ āĻāϰāĻŋ
mkdir /etc/kibana/certs/ca -pcp -R /etc/elasticsearch/certs/ca/ /etc/kibana/certs/cp /etc/elasticsearch/certs/elasticsearch.key /etc/kibana/certs/kibana.keycp /etc/elasticsearch/certs/elasticsearch.crt /etc/kibana/certs/kibana.crtchown -R kibana:kibana /etc/kibana/chmod -R 500 /etc/kibana/certschmod 440 /etc/kibana/certs/ca/ca.* /etc/kibana/certs/kibana.*
ā§ŠāĨ¤ Kibana āĻāύāĻĢāĻŋāĻāĻžāϰā§āĻļāύ āĻĢāĻžāĻāϞ āĻĄāĻžāĻāύāϞā§āĻĄ
curl -so /etc/kibana/kibana.yml https://packages.wazuh.com/4.4/tpl/elastic-basic/kibana_all_in_one.yml
ā§ĒāĨ¤ kibana.yml āĻĢāĻžāĻāϞāĻāĻŋ āĻāĻĄāĻŋāĻ āĻāϰāϤ⧠āĻšāĻŦā§
nano /etc/kibana/kibana.yml
elasticsearch.password:
āϏā§āĻ āĻāϰāĻžāϰ āĻāύā§āϝ
[ctrl + o] + enter >> to save
[ctrl + x] >> to exit
ā§ĢāĨ¤ āĻĄā§āĻāĻž āĻĢā§āϞā§āĻĄāĻžāϰ āϤā§āϰ⧠āĻāϰāĻž āĻāĻŦāĻ āĻĒāĻžāϰāĻŽāĻŋāĻļāύ āĻĻā§āĻāϝāĻŧāĻž
mkdir /usr/share/kibana/data
chown -R kibana:kibana /usr/share/kibana
ā§ŦāĨ¤ Kibana Plug-in āĻāύā§āϏāĻāϞ
cd /usr/share/kibana
sudo -u kibana /usr/share/kibana/bin/kibana-plugin install https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana-4.4.1_7.17.9-1.zip
ā§āĨ¤ Port 443 āĻāϰ āϏāĻžāĻĨā§ Link āĻāϰāĻž
setcap âcap_net_bind_service=+epâ /usr/share/kibana/node/bin/node
ā§ŽāĨ¤ āĻāĻŦāĻžāϰ⧠Kibana āϏāĻžāϰā§āĻāĻŋāϏ Enable & Start āĻāϰāϤ⧠āĻšāĻŦā§
systemctl daemon-reloadsystemctl enable kibanasystemctl start kibana
āĻāĻŦāĻžāϰ⧠Wazuh-manager āĻāϰ IP (āϝ⧠āĻŽā§āĻļāĻŋāύ⧠āĻāϤāĻā§āώāĻŖ āĻāĻŽāϰāĻž āϏāĻŦ āĻāύā§āϏāĻāϞ āĻāϰāϞāĻžāĻŽ) āĻĻāĻŋāϝāĻŧā§ āĻŦā§āϰāĻžāĻāϏ āĻāϰāϤ⧠āĻšāĻŦā§āĨ¤
IP āĻĻā§āĻāϤ⧠ifconfig command āĻāĻŋ āĻĻāĻŋāϤ⧠āĻšāĻŦā§āĨ¤
URL: https:// <IP>
āϏāĻŦ āĻāĻŋāĻā§ āĻ āĻŋāĻ āĻĨāĻžāĻāϞā§, Username āĻāĻŦāĻ Password āĻāĻžāĻāĻŦā§

āϏā§āĻāĻžāύ⧠Username: elastic āĻāĻŦāĻ Password āĻĻāĻŋāϤ⧠āĻšāĻŦā§ Elastic āĻāϰ Password (āϝ⧠Password āĻĒā§āϰā§āĻŦā§ āϤā§āϰ⧠āĻāϰāĻž āĻšāϝāĻŧā§āĻā§) āĨ¤
āϏāĻŦ āĻāĻŋāĻā§ āĻ āĻŋāĻ āĻĨāĻžāĻāϞā§, āĻāĻĒāύāĻŋ Successfully Log-in āĻāϰāϤ⧠āĻĒāĻžāϰāĻŦā§āύāĨ¤


āĻāĻŦāĻžāϰ⧠āĻā§āĻā§āĻ āĻāĻāĻāĻŋ āĻāĻžāĻ āĻāϰāĻŋ, āϝā§āύ āĻ āĻĒā§āϰāϝāĻŧā§āĻāύā§āϝāĻŧ āĻāĻĒāĻĄā§āĻ āĻšāϝāĻŧā§ āĻā§āĻā§āĻ āύāĻž āĻšāϝāĻŧā§ āϝāĻžāϝāĻŧāĨ¤
sed -i âs/^deb/#deb/â /etc/apt/sources.list.d/wazuh.list
sed -i âs/^deb/#deb/â /etc/apt/sources.list.d/elastic-7.x.list
apt-get update
Wazuh-manager āĻāĻŦāĻ āĻĒā§āϰāϝāĻŧā§āĻāύā§āϝāĻŧ āĻāύā§āώāĻžāĻā§āĻāĻŋāĻ Element Install āĻāϰāĻž āĻšāϝāĻŧā§ āĻāĻŋāϝāĻŧā§āĻā§āĨ¤Â āĻāĻāĻžāĻŽā§ āĻĒāϰā§āĻŦā§Â āĻāĻŽāϰāĻž āĻāϰ āϏāĻžāĻĨā§Â Agent add āĻāϰāĻŦ, āĻāĻŦāĻ Agent āĻĨā§āĻā§ āϞāĻ āĻāĻžāϞā§āĻā§āĻ āĻāϰāĻŦāĨ¤
