Wazuh Installation

āĻĒā§āϰāϤāĻŋāύāĻŋāϝāĻŧāϤ āϏāĻžāχāĻŦāĻžāϰ āĻ…ā§āϝāϟāĻžāϕ⧇āϰ āϏāĻ‚āĻ–ā§āϝāĻž āĻŦ⧃āĻĻā§āϧāĻŋāϰ āĻĢāϞ⧇ āφāĻŽāĻžāĻĻ⧇āϰ āύāĻŋāϰāĻžāĻĒāĻ¤ā§āϤāĻž āĻŦā§āϝāĻŦāĻ¸ā§āĻĨāĻžāϰ āωāĻ¨ā§āύāϤāĻŋāϰ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧāϤāĻž āωāĻĒāϞāĻŦā§āϧāĻŋ āĻ•āϰāϤ⧇ āĻĒāĻžāϰāĻŋāĨ¤ āĻŦāĻ°ā§āϤāĻŽāĻžāύ āϏāĻžāχāĻŦāĻžāϰ āĻ“āϝāĻŧāĻžāĻ°ā§āĻ˛ā§āĻĄā§‡ āύāĻŋāϰāĻžāĻĒāĻĻ āĻĨāĻžāĻ•āϤ⧇ āĻĒā§āϰāϝāĻŧā§‹āϜāύ ‍āϏāĻ āĻŋāĻ• āύāĻŋāϰāĻžāĻĒāĻ¤ā§āϤāĻž āĻŦā§āϝāĻŦāĻ¸ā§āĻĨāĻž āĻāĻŦāĻ‚ āĻŽāύāĻŋāϟāϰāĻŋāĻ‚ āϏāĻŋāϏāĻŸā§‡āĻŽāĨ¤ āĻāĻ•āϟāĻŋ āχāύāĻĢā§āϰāĻžāĻ¸ā§āĻŸā§āϰāĻžāĻ•āϚāĻžāϰ āĻāϰ āϏāĻŋāĻ•āĻŋāωāϰāĻŋāϟāĻŋ āĻŽāύāĻŋāϟāϰāĻŋāĻ‚ āϗ⧁āϰ⧁āĻ¤ā§āϤāĻĒā§‚āĻ°ā§āĻŖ āĻāĻ•āϟāĻŋ āĻ•āĻžāϜāĨ¤ āφāĻŽāϰāĻž āĻāĻ•āϟāĻŋ Open-Source SIEM Solution āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰ⧇ Log Analysis āĻ•āϰāĻŦ āĻāĻŦāĻ‚ āĻāϰ Installation Process āĻĻ⧇āĻ–āĻŦāĨ¤

āĻ āĻĒāĻ°ā§āĻŦ⧇ āφāĻŽāϰāĻž āĻļ⧁āϧ⧁ Wazuh āχāύāĻ¸ā§āϟāϞ⧇āĻļāύ āĻ¸ā§āĻŸā§āϰāĻžāĻ•āϚāĻžāϰ āϏāĻŽā§āĻĒāĻ°ā§āϕ⧇ āϜāĻžāύāĻŦ, āĻ•āĻŋāĻ­āĻžāĻŦ⧇ āĻ•āĻžāϜ āĻ•āϰ⧇, āĻ•āĻŋāĻ­āĻžāĻŦ⧇ āχāĻ¨ā§āϏāϟāϞ āĻ•āϰāϤ⧇ āĻšāϝāĻŧ āχāĻ¤ā§āϝāĻžāĻĻāĻŋ āĻŦāĻŋāώāϝāĻŧ⧇ āϧāĻžāϰāĻŖāĻž āύāĻŋāĻŦā§‹āĨ¤

Wazuh āĻšāϞ⧋ OSSEC āĻāϰ SIEM Solution based āĻāĻ•āϟāĻŋ Opensource SIEM Solution. āĻĒ⧁āϰ⧋ SIEM Solution āĻ Wazuh-manager, Wazuh-agent, Filebeat, Kibana, Elasticsearch āĻāϰ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻž āĻšāϝāĻŧāĨ¤ āĻ āϏāĻžāĻ°ā§āĻ­āĻŋāϏāϗ⧁āϞ⧋ āĻĒā§āϰāϤāĻŋāϟāĻŋ āφāϞāĻžāĻĻāĻž āφāϞāĻžāĻĻāĻžāĻ­āĻžāĻŦ⧇ āχāύāĻ¸ā§āϟāϞ āĻ•āϰ⧇ āĻāĻ•āϟāĻŋāϰ āϏāĻžāĻĨ⧇ āφāϰ⧇āĻ•āϟāĻŋāϰ āϏāĻŽāĻ¨ā§āĻŦāϝāĻŧ āĻ•āϰāϤ⧇ āĻšāϝāĻŧāĨ¤

āφāĻŽāϰāĻž āϏāĻ•āϞ āϏāĻžāĻ°ā§āĻ­āĻŋāϏ āĻāĻ•āϟāĻŋ āĻŽā§‡āĻļāĻŋāύ⧇ āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻŦā§‹ āĻāĻŦāĻ‚ āĻāĻ•āϟāĻŋ āĻāĻœā§‡āĻ¨ā§āϟ āĻ…āĻ¨ā§āϝ āĻāĻ•āϟāĻŋ āĻŽā§‡āĻļāĻŋāύ⧇ āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻŦā§‹āĨ¤

āĻāχ āĻĒā§āϰāϏ⧇āϏāϟāĻŋāϰ āύāĻžāĻŽ āĻ…āϞ āχāύ āĻ“āϝāĻŧāĻžāύ āĻĄāĻŋāĻĒā§āϞāϝāĻŧāĻŽā§‡āĻ¨ā§āϟāĨ¤ āφāĻŽāϰāĻž āχāύāĻ¸ā§āϟāϞ⧇āĻļāύ āĻāϰ āϜāĻ¨ā§āϝ  Wazuh āĻāϰ āĻ…āĻĢāĻŋāϏāĻŋāϝāĻŧāĻžāϞ āĻĄāϕ⧁āĻŽā§‡āĻ¨ā§āϟ āĻ…āύ⧁āϏāϰāĻŖ āĻ•āϰāĻŦā§‹āĨ¤ āϏāĻŽā§āĻĒ⧁āĻ°ā§āĻŖ āχāĻ¨ā§āϏāϟāϞ⧇āĻļāύ⧇āϰ āϜāĻ¨ā§āϝ āĻ­āĻžāĻ°ā§āϚ⧁āϝāĻŧāĻžāϞāĻŦāĻ•ā§āϏ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻŦāĨ¤ āωāĻĒāϰ⧇ āĻĄāĻŋāϜāĻžāχāύ āφāĻ°ā§āĻ•āĻŋāĻŸā§‡āĻ•āϚāĻžāϰ āĻĻ⧇āϖ⧇ āĻŦā§‹āĻāĻž āϝāĻžāĻšā§āϛ⧇, āϏāĻ•āϞ āϏāĻžāĻ°ā§āĻ­āĻŋāϏ āχāĻ¨ā§āϏāϟāϞ⧇āĻļāύ⧇āϰ āϜāĻ¨ā§āϝ āĻāĻ•āϟāĻŋ āĻŽāĻžāĻ¤ā§āϰ āĻ…āĻĒāĻžāϰ⧇āϟāĻŋāĻ‚ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻž āĻšāĻŦ⧇āĨ¤ āϏāĻŽā§āĻĒā§‚āĻ°ā§āĻŖ āĻĒā§āϰāϏ⧇āϏāϟāĻŋ āφāĻŽāϰāĻž āĻ­āĻžāĻ°ā§āϚ⧁āϝāĻŧāĻžāϞāĻŦāĻ•ā§āϏ⧇ āϏāĻŋāĻŽā§āϞ⧇āϟ āĻ•āϰāĻŦāĨ¤ āϝāĻĻāĻŋāĻ“ āĻšā§‹āĻ¸ā§āϟ āĻŽā§‡āĻļāĻŋāύ⧇ āĻāĻ• āϏāĻžāĻĨ⧇ āϏāĻ•āϞ āϏāĻžāĻ°ā§āĻ­āĻŋāϏ āχāĻ¨ā§āϏāϟāϞ āĻ•āϰāĻŦ, āϤāĻĻ⧁āĻĒāϰāĻŋ āĻāϰ āĻŽāĻžāĻā§‡ āĻ•āĻŋāϛ⧁ āĻĒā§āϰāϏ⧇āϏ āϧāĻžāĻĒ⧇ āϧāĻžāĻĒ⧇ āϏāĻŽā§āĻĒāĻ¨ā§āύ āĻšāϝāĻŧ⧇ āĻĨāĻžāϕ⧇āĨ¤ āĻ…āĻ°ā§āĻĨāĻžā§Ž, āĻāĻœā§‡āĻ¨ā§āϟ āĻĨ⧇āϕ⧇ āϞāĻ— āĻ•āĻžāϞ⧇āĻ•āĻļāύ āĻ•āϰ⧇ Wazuh-Manager āĻāϰ āĻ•āĻžāϛ⧇ āϞāĻ— āĻĒāĻžāĻ āĻžāύ⧋ āĻāĻŦāĻ‚ āϞāĻ— Visualization āĻāϰ āĻŽāĻžāĻā§‡ āϝ⧇ āĻĒā§āϰāϏ⧇āϏāϗ⧁āϞ⧋ āĻšāϝāĻŧ āϤāĻžāϰ āĻāĻ•āϟāĻŋ āϏāĻžāĻŽāĻžāϰāĻŋ āϤ⧁āϞ⧇ āϧāϰāĻ›āĻŋāĨ¤

Wazuh-Agent āĻĨ⧇āϕ⧇ āϞāĻ— āύāĻŋāϝāĻŧ⧇ Wazuh-manager āĻ āĻĒāĻžāĻ āĻžāύ⧋ āĻšāϝāĻŧ, Wazuh-manager āĻ āϏ⧇āϟ āĻ•āϰāĻž āϰ⧁āϞāϏ āĻ…āύ⧁āϝāĻžāϝāĻŧā§€ āϞāĻ— āϗ⧁āϞ⧋ āĻĒā§āϰāϏ⧇āϏ āĻ•āϰ⧇ Filebeat āĻāϰ āϏāĻžāĻšāĻžāĻ¯ā§āϝ⧇ Elasticsearch āĻāϰ āĻ•āĻžāϛ⧇ āĻĒāĻžāĻ āĻžāύ⧋ āĻšāϝāĻŧāĨ¤ Elasticsearch āĻāĻ–āĻžāύ⧇ Database āĻāϰ āĻŽāϤ āĻ•āĻžāϜ āĻ•āϰ⧇āĨ¤ Elasticsearch āϞāĻ— āϗ⧁āϞ⧋ Kibana āϤ⧇ āĻĒāĻžāĻ āĻžāϝāĻŧ, āĻāϰ āĻĒāϰ Kibana āĻāϰ āĻŽāĻžāĻ§ā§āϝāĻŽā§‡ āϞāĻ— āϗ⧁āϞ⧋ āĻĄā§āϝāĻžāĻļāĻŦā§‹āĻ°ā§āĻĄ āĻ āĻŦā§‹āϧāĻ—āĻŽā§āϝāĻ­āĻžāĻŦ⧇ āωāĻĒāĻ¸ā§āĻĨāĻžāĻĒāύ āĻ•āϰāĻž āĻšāϝāĻŧāĨ¤

āϏāĻŽā§āĻĒā§‚āĻ°ā§āĻŖ āĻĒā§āϰ⧋āϏ⧇āϏāϟāĻŋ āϏāĻŋāĻŽā§āϞ⧇āϟ āĻ•āϰāϤ⧇ Operating System āĻšāĻŋāϏ⧇āĻŦ⧇ Ubuntu āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻŦāĨ¤

Ubuntu āφāĻŽāϰāĻž āĻšā§‹āĻ¸ā§āϟ āĻŽā§‡āĻļāĻŋāύ āĻšāĻŋāϏ⧇āĻŦ⧇ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻŦāĨ¤ āĻ­āĻžāĻ°ā§āϚ⧁āϝāĻŧāĻžāϞ āĻŦāĻ•ā§āϏ⧇ OS āϟāĻŋāϤ⧇ Minimum 2 GB RAM, 1 āϟāĻŋ CPU āĻĻāĻŋāϤ⧇ āĻšāĻŦ⧇, āϝ⧇āĻšā§‡āϤ⧁ āϏ⧇āĻ–āĻžāύ⧇ āϏāĻ•āϞ Service Install āĻšāĻŦ⧇āĨ¤ Network Adapter āĻ Bridge Adapter (Host/main OS āĻāϰ āϏāĻžāĻĨ⧇ Communicate āĻ•āϰāϤ⧇ āϚāĻžāχāϞ⧇) āĻ…āĻĨāĻŦāĻž Nat-Network āϰ⧇āϖ⧇, Allow VMs āĻ…āĻĨāĻŦāĻž Allow All āĻ•āϰāϤ⧇ āĻšāĻŦ⧇āĨ¤

āĻāχ āϧāĻžāĻĒ⧇ āφāĻŽāϰāĻž āĻļ⧁āϧ⧁ āĻšā§‹āĻ¸ā§āϟ āĻŽā§‡āĻļāĻŋāύ āϰ⧇āĻĄāĻŋ āĻ•āϰāĻŦāĨ¤ āĻ…āĻ°ā§āĻĨāĻžā§Ž Wazuh-Manager, Filebeat, Elasticsearch, Kibana āĻāϗ⧁āϞ⧋ install āĻ•āϰ⧇ āĻšā§‹āĻ¸ā§āϟ āĻŽā§‡āĻļāĻŋāύ āϰ⧇āĻĄāĻŋ āĻ•āϰāĻŦāĨ¤

āχāĻ¨ā§āϏāϟāϞ⧇āĻļāύ⧇āϰ āĻĒā§āϰāĻĨāĻŽ āϧāĻžāĻĒ⧇, Ubuntu āĻŽā§‡āĻļāĻŋāύ āφāĻĒāĻĄā§‡āϟ āĻ•āϰ⧇ āύāĻŋāϤ⧇ āĻšāĻŦ⧇, āĻāϰ āĻĒāϰ āϏāĻŋāϰāĻŋāϝāĻŧāĻžāϞ āĻ…āύ⧁āϝāĻžāϝāĻŧā§€ āĻāĻ•āϟāĻžāϰ āĻĒāϰ āĻāĻ•āϟāĻž Command āĻĻāĻŋāϝāĻŧ⧇ āϝ⧇āϤ⧇ āĻšāĻŦ⧇āĨ¤

Command āϗ⧁āϞ⧋ Run āĻ•āϰāĻžāϰ āϏāĻŽāϝāĻŧ Administrative privilege āĻĒā§āϰāϝāĻŧā§‹āϜāύ āĻšāĻŦ⧇āĨ¤

Installation āĻāϰ āĻļ⧁āϰ⧁āϤ⧇ āĻĒā§āϝāĻžāϕ⧇āϜāϗ⧁āϞ⧋ Install āĻ•āϰ⧇ āύāĻŋāϤ⧇ āĻšāĻŦ⧇

apt-get install apt-transport-https zip unzip lsb-release curl gnupg

ā§§āĨ¤ Install GPG Key

curl -s https://artifacts.elastic.co/GPG-KEY-elasticsearch | gpg –no-default-keyring –keyring gnupg-ring:/usr/share/keyrings/elasticsearch.gpg –import && chmod 644 /usr/share/keyrings/elasticsearch.gpg

2. Repo Add āĻ•āϰāĻŦāĨ¤

echo “deb [signed-by=/usr/share/keyrings/elasticsearch.gpg] https://artifacts.elastic.co/packages/7.x/apt stable main” | tee /etc/apt/sources.list.d/elastic-7.x.list

ā§ŠāĨ¤ āφāĻĒāĻĄā§‡āϟ āĻ•āϰ⧇ āύāĻŋāĻŦāĨ¤

apt-get update

āφāĻŽāĻžāĻĻ⧇āϰ āĻŽā§‡āĻļāĻŋāύ āĻāĻ–āύ Elasticsearch Install āĻāϰ āϜāĻ¨ā§āϝ āĻĒā§āϰāĻ¸ā§āϤ⧁āϤāĨ¤

āĻāĻ–āύ Elasticsearch Install āĻāĻŦāĻ‚ Configure āĻ•āϰāĻŦāĨ¤

ā§§āĨ¤ Elasticsearch āĻĒāĻžāϕ⧇āϜāϗ⧁āϞ⧋ āχāĻ¨ā§āϏāϟāϞ āĻ•āϰ⧇ āύāĻŋāχāĨ¤

apt-get install elasticsearch=7.17.9

⧍āĨ¤ Configuration file download āĻ•āϰāĻŋāĨ¤

curl -so /etc/elasticsearch/elasticsearch.yml https://packages.wazuh.com/4.4/tpl/elastic-basic/elasticsearch_all_in_one.yml

āĻāχ āĻ…āĻ‚āĻļ⧇ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āϟ Create āĻ•āϰāĻž āĻāĻŦāĻ‚ Deploy āĻ•āϰāĻž āĻĻ⧇āĻ–āĻŦ

ā§§āĨ¤ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āϟ āϤ⧈āϰ⧀āϰ āϜāĻ¨ā§āϝ Configuration āĻĢāĻžāχāϞ Download āĻ•āϰāĻŋāĨ¤

curl -so /usr/share/elasticsearch/instances.yml https://packages.wazuh.com/4.4/tpl/elastic-basic/instances_aio.yml

⧍āĨ¤ āύāĻŋāĻšā§‡āϰ āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āϰāĻžāύ āĻ•āϰāϞ⧇ elasticsearch-certutil tool āĻāϰ āĻŽāĻžāĻ§ā§āϝāĻŽā§‡ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āϟ āϤ⧈āϰ⧀ āĻšāĻŦ⧇āĨ¤

/usr/share/elasticsearch/bin/elasticsearch-certutil cert ca –pem –in instances.yml –keep-ca-key –out ~/certs.zip

ā§ŠāĨ¤ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āϟ āϰ⧇āĻĄāĻŋ! āĻāĻ–āύ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āϟ āĻāϰ zip āĻĢāĻžāχāϞ unzip āĻ•āϰāϤ⧇ āĻšāĻŦ⧇āĨ¤

unzip ~/certs.zip -d ~/certs

ā§ĒāĨ¤ āĻāχ āϧāĻžāĻĒ⧇ Elasticsearch āĻāϰ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āĻŸā§‡āϰ āϜāĻ¨ā§āϝ āĻāĻ•āϟāĻŋ directory āϤ⧈āϰ⧀ āĻ•āϰāĻŦ āĻāĻŦāĻ‚ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āϟāϗ⧁āϞ⧋ Directory āϤ⧇ āϰāĻžāĻ–āĻŦāĨ¤

mkdir /etc/elasticsearch/certs/ca -p

cp -R ~/certs/ca/ ~/certs/elasticsearch/* /etc/elasticsearch/certs/

chown -R elasticsearch: /etc/elasticsearch/certs

chmod -R 500 /etc/elasticsearch/certs

chmod 400 /etc/elasticsearch/certs/ca/ca.* /etc/elasticsearch/certs/elasticsearch.*

rm -rf ~/certs/ ~/certs.zip

ā§ĢāĨ¤ āĻāĻ–āύ Elasticsearch service enable āĻ•āϰāĻŦ āĻāĻŦāĻ‚ service start āĻ•āϰāĻŦāĨ¤

systemctl daemon-reload

systemctl enable elasticsearch

systemctl start elasticsearch

ā§ŦāĨ¤ Elasticsearch āĻāϰ āϏāĻ•āϞ User āĻāĻŦāĻ‚ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āϰ⧁āϞāϏ⧇āϰ āϜāĻ¨ā§āϝ credential āϤ⧈āϰ⧀ āĻ•āϰāĻŦāĨ¤

/usr/share/elasticsearch/bin/elasticsearch-setup-passwords auto

āĻāχ āĻ•āĻŽāĻžāĻ¨ā§āĻĄāϟāĻŋ āύāĻŋāĻšā§‡āϰ āĻŽāϤ āφāωāϟāĻĒ⧁āϟ āĻĻāĻŋāĻŦ⧇, āĻāϗ⧁āϞ⧋ āϏ⧇āĻ­ āĻ•āϰ⧇ āϰāĻžāĻ–āϤ⧇ āĻšāĻŦ⧇, āĻĒāϰāĻŦāĻ°ā§āϤ⧀āϤ⧇ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝāĨ¤

Changed password for user apm_system

PASSWORD apm_system = 4w3qt8Q7fC4bs956W84r

Changed password for user kibana_system

PASSWORD kibana_system = CUANVQIaChV6P6U86Ups

Changed password for user kibana

PASSWORD kibana = CUANVQIaChV6P6U86Ups

Changed password for user logstash_system

PASSWORD logstash_system = gz3lCnmLZWsZUQ6uw0F3

Changed password for user beats_system

PASSWORD beats_system = H2Qfc1UUqCvxYSfJcoR2

Changed password for user remote_monitoring_user

PASSWORD remote_monitoring_user = AwbIMfrafL1aM1GKrMQc

Changed password for user elastic

PASSWORD elastic = dQYzrlwVZPhdKANPlHOB

āĻāĻ–āύ āĻšā§‡āĻ• āĻ•āϰāĻž āϝ⧇āϤ⧇ āĻĒāĻžāϰ⧇, āϏāĻžāĻ°ā§āĻ­āĻŋāϏāϗ⧁āϞ⧋ āĻ āĻŋāĻ•āĻ­āĻžāĻŦ⧇ āχāĻ¨ā§āϏāϟāϞ āĻšāϞ⧋ āĻ•āĻŋ āύāĻžāĨ¤

[<passāĻāϰ āĻ¸ā§āĻĨāĻžāύ⧇ āϏāĻžāĻ°ā§āĻ­āĻŋāϏ āϗ⧁āϞ⧋āϰ Password āĻĻāĻŋāϤ⧇ āĻšāĻŦ⧇, āϝ⧇āϗ⧁āϞ⧋ āĻāĻ•āϟ⧁ āφāϗ⧇ āφāĻŽāϰāĻž āĻ•āĻĒāĻŋ āĻ•āϰ⧇ āϰāĻžāĻ–āϞāĻžāĻŽ (āφāĻĒāύāĻžāϰ password āφāĻĒāύāĻŋ āϏ⧇āĻ­ āĻ•āϰ⧇ āϰ⧇āϖ⧇āϛ⧇āύ)]

elastic
curl -XGET -u -k

remote monitoring user

curl -XGET -u -k

beast system

curl -XGET -u -k

logsthash system

curl -XGET -u  -k

kibana

curl -XGET -u -k

kibana system

curl -XGET -u -k

apm system

curl -XGET -u -k

āωāĻĒāϰāĻ•ā§āϤ āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻĻāĻŋāϞ⧇ āϏāĻžāĻ°ā§āĻ­āĻŋāϏāϗ⧁āϞ⧋ āϚāĻžāϞ⧁ āĻĨāĻžāĻ•āϞ⧇ āĻāĻŽāύ āφāωāϟāĻĒ⧁āϟ āφāϏāĻŦ⧇āĨ¤

root@nayem-VirtualBox:/home/nayem# curl -XGET https://localhost:9200 -u elastic:dQYzrlwVZPhdKANPlHOB -k
{

  “name” : “elasticsearch”,

  “cluster_name” : “elasticsearch”,

  “cluster_uuid” : “QoGKtHL0QoyPP_IYkw0s-Q”,

  “version” : {

    “number” : “7.17.9”,

    “build_flavor” : “default”,

    “build_type” : “deb”,

    “build_hash” : “ef48222227ee6b9e70e502f0f0daa52435ee634d”,

    “build_date” : “2023-01-31T05:34:43.305517834Z”,

    “build_snapshot” : false,

    “lucene_version” : “8.11.1”,

    “minimum_wire_compatibility_version” : “6.8.0”,

    “minimum_index_compatibility_version” : “6.0.0-beta1”

  },

  “tagline” : “You Know, for Search”

}

Wazuh repository āĻ…ā§āϝāĻžāĻĄ āĻ•āϰāĻžāϰ āĻ…āĻ‚āĻļ

ā§§āĨ¤ GPG Key Install āĻ•āϰāĻŋāĨ¤

curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg –no-default-keyring –keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg –import && chmod 644 /usr/share/keyrings/wazuh.gpg

⧍āĨ¤ Add Repo.

echo “deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main” | tee -a /etc/apt/sources.list.d/wazuh.list

ā§ŠāĨ¤ Update āĻ•āϰ⧇ āύāĻŋāχ

apt-get updat

ā§§āĨ¤ Wazuh-manager āĻĒā§āϝāĻžāϕ⧇āϜ āχāĻ¨ā§āϏāϟāϞ āĻ•āϰāĻŋ

apt-get install wazuh-manager

⧍āĨ¤ Wazuh-manager āϏāĻžāĻ°ā§āĻ­āĻŋāϏ Enable & Start

systemctl daemon-reload
systemctl enable wazuh-manager
systemctl start wazuh-manager

ā§ŠāĨ¤ Wazuh-manager āϏāĻžāĻ°ā§āĻ­āĻŋāϏ āϚāĻžāϞ⧁ āφāϛ⧇ āĻ•āĻŋ āύāĻž āĻšā§‡āĻ• āĻ•āϰāĻŋ

systemctl status wazuh-manager

āφāĻļāĻž āĻ•āϰāĻ›āĻŋ Wazuh-manager running āφāϛ⧇ āĻāĻŦāĻ‚ āϏāĻŦ āĻ•āĻŋāϛ⧁ āĻ āĻŋāĻ• āĻ āĻžāĻ• Install āĻ•āϰāϤ⧇ āĻĒ⧇āϰ⧇āϛ⧇āύāĨ¤ āĻāĻŦāĻžāϰ āĻĒāϰ⧇āϰ āϧāĻžāĻĒ⧇ āφāĻŽāϰāĻž Fileeat āχāĻ¨ā§āϏāϟāϞ āĻ•āϰāĻŦāĨ¤

ā§§āĨ¤ āύāĻŋāĻšā§‡āϰ āĻ•āĻŽāĻžāĻ¨ā§āĻĄā§‡āϰ āĻŽāĻžāĻ§ā§āϝāĻŽā§‡ Filebeat āĻĒāĻžāϕ⧇āϜ āχāĻ¨ā§āϏāϟāϞ āĻ•āϰāĻŋāĨ¤

apt-get install filebeat=7.17.9

⧍āĨ¤ āĻĒā§‚āĻ°ā§āĻŦ⧇ āĻĨ⧇āϕ⧇ āĻ•āύāĻĢāĻŋāĻ—āĻžāϰ āĻ•āϰāĻž Filebeat āĻāϰ config āĻĢāĻžāχāϞ āχāĻ¨ā§āϏāϟāϞ āĻ•āϰāĻŦāĨ¤ āĻāϰ āĻŽāĻžāĻ§ā§āϝāĻŽā§‡ āĻĢāĻžāχāϞāĻŦāĻŋāϟ Wazuh alert Elasticsearch āĻāϰ āĻ•āĻžāϛ⧇ āĻĒāĻžāĻ āĻžāϝāĻŧāĨ¤

curl -so /etc/filebeat/filebeat.yml https://packages.wazuh.com/4.4/tpl/elastic-basic/filebeat_all_in_one.yml

ā§ŠāĨ¤ Elasticsearch āĻāϰ āϜāĻ¨ā§āϝ Alert Sample āĻĄāĻžāωāύāϞ⧋āĻĄ āĻāĻŦāĻ‚ Permission āĻĻ⧇āĻ“āϝāĻŧāĻž

curl -so /etc/filebeat/wazuh-template.json https://raw.githubusercontent.com/wazuh/wazuh/4.4/extensions/elasticsearch/7.x/wazuh-template.json

chmod go+r /etc/filebeat/wazuh-template.json

ā§ĒāĨ¤ Filebeat āĻāϰ āϜāĻ¨ā§āϝ Wazuh Module āĻĄāĻžāωāύāϞ⧋āĻĄ

curl -s https://packages.wazuh.com/4.x/filebeat/wazuh-filebeat-0.2.tar.gz | tar -xvz -C /usr/share/filebeat/module

ā§ĢāĨ¤ filebeat.yml āĻĢāĻžāχāϞāϟāĻŋ āĻāĻĄāĻŋāϟ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ āύāĻŋāĻ°ā§āĻĻāĻŋāĻˇā§āϟ āϞ⧋āϕ⧇āĻļāĻžāύ⧇ āϝ⧇āϤ⧇ āĻšāĻŦ⧇ āĻāĻŦāĻ‚ āĻĢāĻžāχāϞāϟāĻŋ āĻāĻĄāĻŋāϟ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇

nano /etc/filebeat/filebeat.yml

ā§ŦāĨ¤ āĻāχ āϞāĻžāχāύāϟāĻŋ āĻāĻĄāĻŋāϟ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇ <pass> āĻāϰ ‍āĻ¸ā§āĻĨāĻžāύ⧇ āφāĻĒāύāĻžāϰ Elastic password āĻĻāĻŋāϤ⧇ āĻšāĻŦ⧇

output.elasticsearch.password:

āĻāϰ āĻĒāϰ āϏ⧇āĻ­ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ

[ctrl + o] + enter >> to save

[ctrl + x] >> to exit

ā§­āĨ¤ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āϟāϗ⧁āϞ⧋ āĻ•āĻĒāĻŋ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ

cp -r /etc/elasticsearch/certs/ca/ /etc/filebeat/certs/
cp /etc/elasticsearch/certs/elasticsearch.crt /etc/filebeat/certs/filebeat.crt
cp /etc/elasticsearch/certs/elasticsearch.key /etc/filebeat/certs/filebeat.key

ā§ŽāĨ¤ āĻ…āϤāσāĻĒāϰ Filebeat āϏāĻžāĻ°ā§āĻ­āĻŋāϏ āĻ¸ā§āϟāĻžāĻ°ā§āϟ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ āĻ•āĻŽāĻžāĻ¨ā§āĻĄ

systemctl daemon-reloadsystemctl enable filebeatsystemctl start filebeat

⧝āĨ¤ Filebeat āĻ āĻŋāĻ• āĻŽāϤ āχāĻ¨ā§āϏāϟāϞ āĻšāϝāĻŧ⧇āϛ⧇ āĻ•āĻŋ āύāĻž, āϤāĻž āĻĻ⧇āĻ–āĻžāϰ āϜāĻ¨ā§āϝ

filebeat test output

āĻāϰ āĻĒāϰ⧇āϰ āϧāĻžāĻĒ⧇ Kibana āχāĻ¨ā§āϏāϟāϞ āĻ•āϰāĻŦ

ā§§āĨ¤ Kibana āĻĒā§āϝāĻžāϕ⧇āϜ āχāĻ¨ā§āϏāϟāϞ

apt-get install kibana=7.17.9

⧍āĨ¤ Kibana āĻ•āύāĻĢāĻŋāĻ—āĻžāϰ⧇āĻļāύ āĻĢā§‹āĻ˛ā§āĻĄāĻžāϰ⧇ āχāϞāĻžāĻ¸ā§āϟāĻŋāĻ•āϏāĻžāĻ°ā§āϚ āϏāĻžāĻ°ā§āϟāĻŋāĻĢāĻŋāϕ⧇āϟ āĻ•āĻĒāĻŋ āĻ•āϰāĻŋ

mkdir /etc/kibana/certs/ca -pcp -R /etc/elasticsearch/certs/ca/ /etc/kibana/certs/cp /etc/elasticsearch/certs/elasticsearch.key /etc/kibana/certs/kibana.keycp /etc/elasticsearch/certs/elasticsearch.crt /etc/kibana/certs/kibana.crtchown -R kibana:kibana /etc/kibana/chmod -R 500 /etc/kibana/certschmod 440 /etc/kibana/certs/ca/ca.* /etc/kibana/certs/kibana.*

ā§ŠāĨ¤ Kibana āĻ•āύāĻĢāĻŋāĻ—āĻžāϰ⧇āĻļāύ āĻĢāĻžāχāϞ āĻĄāĻžāωāύāϞ⧋āĻĄ

curl -so /etc/kibana/kibana.yml https://packages.wazuh.com/4.4/tpl/elastic-basic/kibana_all_in_one.yml

ā§ĒāĨ¤ kibana.yml āĻĢāĻžāχāϞāϟāĻŋ āĻāĻĄāĻŋāϟ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇

nano /etc/kibana/kibana.yml
elasticsearch.password:

āϏ⧇āĻ­ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ

[ctrl + o] + enter >> to save

[ctrl + x] >> to exit

ā§ĢāĨ¤ āĻĄā§‡āϟāĻž āĻĢā§‹āĻ˛ā§āĻĄāĻžāϰ āϤ⧈āϰ⧀ āĻ•āϰāĻž āĻāĻŦāĻ‚ āĻĒāĻžāϰāĻŽāĻŋāĻļāύ āĻĻ⧇āĻ“āϝāĻŧāĻž

mkdir /usr/share/kibana/data
chown -R kibana:kibana /usr/share/kibana

ā§ŦāĨ¤ Kibana Plug-in āχāĻ¨ā§āϏāϟāϞ

cd /usr/share/kibana
sudo -u kibana /usr/share/kibana/bin/kibana-plugin install https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana-4.4.1_7.17.9-1.zip

ā§­āĨ¤ Port 443 āĻāϰ āϏāĻžāĻĨ⧇ Link āĻ•āϰāĻž

setcap ‘cap_net_bind_service=+ep’ /usr/share/kibana/node/bin/node

ā§ŽāĨ¤ āĻāĻŦāĻžāϰ⧇ Kibana āϏāĻžāĻ°ā§āĻ­āĻŋāϏ Enable & Start āĻ•āϰāϤ⧇ āĻšāĻŦ⧇

systemctl daemon-reloadsystemctl enable kibanasystemctl start kibana

āĻāĻŦāĻžāϰ⧇ Wazuh-manager āĻāϰ IP (āϝ⧇ āĻŽā§‡āĻļāĻŋāύ⧇ āĻāϤāĻ•ā§āώāĻŖ āφāĻŽāϰāĻž āϏāĻŦ āχāĻ¨ā§āϏāϟāϞ āĻ•āϰāϞāĻžāĻŽ) āĻĻāĻŋāϝāĻŧ⧇ āĻŦā§āϰāĻžāωāϏ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇āĨ¤

IP āĻĻ⧇āĻ–āϤ⧇ ifconfig command āϟāĻŋ āĻĻāĻŋāϤ⧇ āĻšāĻŦ⧇āĨ¤

URL: https:// <IP>

āϏāĻŦ āĻ•āĻŋāϛ⧁ āĻ āĻŋāĻ• āĻĨāĻžāĻ•āϞ⧇, Username āĻāĻŦāĻ‚ Password āϚāĻžāχāĻŦ⧇

āϏ⧇āĻ–āĻžāύ⧇ Username: elastic āĻāĻŦāĻ‚ Password āĻĻāĻŋāϤ⧇ āĻšāĻŦ⧇ Elastic āĻāϰ Password (āϝ⧇ Password āĻĒā§‚āĻ°ā§āĻŦ⧇ āϤ⧈āϰ⧀ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇) āĨ¤

āϏāĻŦ āĻ•āĻŋāϛ⧁ āĻ āĻŋāĻ• āĻĨāĻžāĻ•āϞ⧇, āφāĻĒāύāĻŋ Successfully Log-in āĻ•āϰāϤ⧇ āĻĒāĻžāϰāĻŦ⧇āύāĨ¤

āĻāĻŦāĻžāϰ⧇ āϛ⧋āĻŸā§āϟ āĻāĻ•āϟāĻŋ āĻ•āĻžāϜ āĻ•āϰāĻŋ, āϝ⧇āύ āĻ…āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āφāĻĒāĻĄā§‡āϟ āĻšāϝāĻŧ⧇ āĻšā§‡āĻžā§āϜ āύāĻž āĻšāϝāĻŧ⧇ āϝāĻžāϝāĻŧāĨ¤

sed -i “s/^deb/#deb/” /etc/apt/sources.list.d/wazuh.list
sed -i “s/^deb/#deb/” /etc/apt/sources.list.d/elastic-7.x.list
apt-get update

Wazuh-manager āĻāĻŦāĻ‚ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āφāύ⧁āώāĻžāĻ™ā§āĻ—āĻŋāĻ• Element Install āĻ•āϰāĻž āĻšāϝāĻŧ⧇ āĻ—āĻŋāϝāĻŧ⧇āϛ⧇āĨ¤Â āφāĻ—āĻžāĻŽā§€ āĻĒāĻ°ā§āĻŦā§‡Â āφāĻŽāϰāĻž āĻāϰ āϏāĻžāĻĨā§‡Â Agent add āĻ•āϰāĻŦ, āĻāĻŦāĻ‚ Agent āĻĨ⧇āϕ⧇ āϞāĻ— āĻ•āĻžāϞ⧇āĻ•ā§āϟ āĻ•āϰāĻŦāĨ¤

Leave a Comment

Your email address will not be published. Required fields are marked *

What is Lorem Ipsum?

Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry’s standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.