Remove cdb related tasks and config
This commit is contained in:
parent
285cbc26fc
commit
144067763b
@ -1,7 +1,4 @@
|
|||||||
---
|
---
|
||||||
- name: rebuild cdb_lists
|
|
||||||
command: /var/ossec/bin/ossec-makelists
|
|
||||||
|
|
||||||
- name: restart wazuh-manager
|
- name: restart wazuh-manager
|
||||||
service:
|
service:
|
||||||
name: wazuh-manager
|
name: wazuh-manager
|
||||||
|
|||||||
@ -198,11 +198,6 @@
|
|||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
- name: Retrieving CDB lists
|
|
||||||
include_vars: cdb_lists.yml
|
|
||||||
tags:
|
|
||||||
- config
|
|
||||||
|
|
||||||
- name: Check if syslog output is enabled
|
- name: Check if syslog output is enabled
|
||||||
set_fact: syslog_output=true
|
set_fact: syslog_output=true
|
||||||
when: item.server is not none
|
when: item.server is not none
|
||||||
@ -334,27 +329,6 @@
|
|||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
- name: CDB Lists
|
|
||||||
template:
|
|
||||||
src: cdb_lists.j2
|
|
||||||
dest: "/var/ossec/etc/lists/{{ item.name }}"
|
|
||||||
owner: root
|
|
||||||
group: ossec
|
|
||||||
mode: 0640
|
|
||||||
no_log: true
|
|
||||||
register: wazuh_manager_cdb_lists
|
|
||||||
until: wazuh_manager_cdb_lists is succeeded
|
|
||||||
notify:
|
|
||||||
- rebuild cdb_lists
|
|
||||||
- restart wazuh-manager
|
|
||||||
with_items:
|
|
||||||
- "{{ cdb_lists }}"
|
|
||||||
when:
|
|
||||||
- cdb_lists is defined
|
|
||||||
- cdb_lists is iterable
|
|
||||||
tags:
|
|
||||||
- config
|
|
||||||
|
|
||||||
- name: Ensure Wazuh Manager, wazuh API service is started and enabled
|
- name: Ensure Wazuh Manager, wazuh API service is started and enabled
|
||||||
service:
|
service:
|
||||||
name: "{{ item }}"
|
name: "{{ item }}"
|
||||||
|
|||||||
@ -360,8 +360,9 @@
|
|||||||
<rule_exclude>{{ rule }}</rule_exclude>
|
<rule_exclude>{{ rule }}</rule_exclude>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
{% if cdb_lists is defined %}
|
||||||
{% for list in cdb_lists %}
|
{% for list in cdb_lists %}
|
||||||
<list>etc/lists/{{ list.name }}</list>
|
<list>etc/lists/{{ list }}</list>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
|
|||||||
@ -1,87 +1,5 @@
|
|||||||
---
|
---
|
||||||
cdb_lists:
|
cdb_lists:
|
||||||
- name: 'audit-keys'
|
- 'audit-keys'
|
||||||
content: |
|
- 'security-eventchannel'
|
||||||
audit-wazuh-w:write
|
- 'amazon/aws-eventnames'
|
||||||
audit-wazuh-r:read
|
|
||||||
audit-wazuh-a:attribute
|
|
||||||
audit-wazuh-x:execute
|
|
||||||
audit-wazuh-c:command
|
|
||||||
- name: 'aws-source'
|
|
||||||
content: |
|
|
||||||
ec2.amazonaws.com:
|
|
||||||
elasticloadbalancing.amazonaws.com:
|
|
||||||
iam.amazonaws.com:
|
|
||||||
signin.amazonaws.com:
|
|
||||||
kms.amazonaws.com:
|
|
||||||
s3.amazonaws.com:
|
|
||||||
- name: 'aws-eventnames'
|
|
||||||
content: |
|
|
||||||
AddUserToGroup:
|
|
||||||
AllocateAddress:
|
|
||||||
AssociateAddress:
|
|
||||||
AssociateDhcpOptions:
|
|
||||||
AssociateRouteTable:
|
|
||||||
AttachGroupPolicy:
|
|
||||||
AttachNetworkInterface:
|
|
||||||
AttachRolePolicy:
|
|
||||||
AttachUserPolicy:
|
|
||||||
AttachVolume:
|
|
||||||
AuthorizeSecurityGroupIngress:
|
|
||||||
ConsoleLogin:
|
|
||||||
CopySnapshot:
|
|
||||||
CreateAccountAlias:
|
|
||||||
CreateGroup:
|
|
||||||
CreateImage:
|
|
||||||
CreateLoadBalancer:
|
|
||||||
CreatePlacementGroup:
|
|
||||||
CreatePolicy:
|
|
||||||
CreateRole:
|
|
||||||
CreateRouteTable:
|
|
||||||
CreateSecurityGroup:
|
|
||||||
CreateSnapshot:
|
|
||||||
CreateSubnet:
|
|
||||||
CreateTags:
|
|
||||||
CreateUser:
|
|
||||||
CreateVolume:
|
|
||||||
CreateVpc:
|
|
||||||
DeleteAccountAlias:
|
|
||||||
DeleteLoadBalancer:
|
|
||||||
DeletePlacementGroup:
|
|
||||||
DeleteSecurityGroup:
|
|
||||||
DeleteSnapshot:
|
|
||||||
DeleteTags:
|
|
||||||
DeleteUser:
|
|
||||||
DeleteVolume:
|
|
||||||
DeregisterImage:
|
|
||||||
DetachGroupPolicy:
|
|
||||||
DetachNetworkInterface:
|
|
||||||
DetachRolePolicy:
|
|
||||||
DetachVolume:
|
|
||||||
DisableKey:
|
|
||||||
DisassociateAddress:
|
|
||||||
DisassociateAddress:
|
|
||||||
DisassociateRouteTable:
|
|
||||||
GetGroup:
|
|
||||||
ListAliases:
|
|
||||||
ListGroups:
|
|
||||||
ListUsers:
|
|
||||||
ModifyImageAttribute:
|
|
||||||
ModifyInstanceAttribute:
|
|
||||||
ModifyNetworkInterfaceAttribute:
|
|
||||||
ModifySnapshotAttribute:
|
|
||||||
ModifySubnetAttribute:
|
|
||||||
ModifyVolumeAttribute:
|
|
||||||
MonitorInstances:
|
|
||||||
RebootInstances:
|
|
||||||
RegisterImage:
|
|
||||||
RemoveUserFromGroup:
|
|
||||||
RevokeSecurityGroupIngress:
|
|
||||||
RunInstances:
|
|
||||||
StartInstances:
|
|
||||||
StopInstances:
|
|
||||||
TerminateInstances:
|
|
||||||
UnmonitorInstances:
|
|
||||||
UpdateAccessKey:
|
|
||||||
UpdateAccountPasswordPolicy:
|
|
||||||
UpdateInstanceAlias:
|
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user