From 3299a18757846693eaafb74a0bdf578c9f94c405 Mon Sep 17 00:00:00 2001 From: Miguelangel Freitas Date: Tue, 20 Feb 2018 19:02:40 +0000 Subject: [PATCH] Updating Wazuh Agent role playbook and Readme --- ansible-wazuh-agent/README.md | 19 +++++++++++++------ wazuh-agent.yml | 13 +++++++++++-- 2 files changed, 24 insertions(+), 8 deletions(-) diff --git a/ansible-wazuh-agent/README.md b/ansible-wazuh-agent/README.md index 305685cb..31538ff5 100644 --- a/ansible-wazuh-agent/README.md +++ b/ansible-wazuh-agent/README.md @@ -17,11 +17,8 @@ This role is compatible with: Role Variables -------------- -* `wazuh_manager_ip`: Wazuh Manager IP Address. -* `wazuh_authd_port`: Registration service port (Default: 1515). -* `wazuh_register_client`: If true, agent will request a new key from registration service (Default: True). -* `wazuh_agent_config`: Includes several parameters for configuring agent components as syscheck, rootcheck, open-scap and localfiles. - +* `wazuh_managers`: Collection of Wazuh Managers' IP address, port, and protocol used by the agent +* `wazuh_agent_authd`: Collection with the settings to register an agent using authd. Playbook example ---------------- @@ -30,7 +27,17 @@ The following is an example how this role can be used: - hosts: all:!wazuh-manager roles: - - { role: ansible-wazuh-agent, wazuh_manager_ip: 192.168.1.1, wazuh_register_client: true, wazuh_authd_port: 1515 } + - ansible-wazuh-agent + vars: + wazuh_managers: + - address: 127.0.0.1 + port: 1514 + protocol: udp + wazuh_agent_authd: + enable: true + port: 1515 + ssl_agent_ca: null + ssl_auto_negotiate: 'no' License and copyright --------------------- diff --git a/wazuh-agent.yml b/wazuh-agent.yml index 61590f47..25a09d54 100644 --- a/wazuh-agent.yml +++ b/wazuh-agent.yml @@ -1,4 +1,13 @@ - hosts: all:!wazuh-manager roles: - - { role: ansible-wazuh-agent, wazuh_manager_ip: 127.0.0.1 } - + - ansible-wazuh-agent + vars: + wazuh_managers: + - address: 127.0.0.1 + port: 1514 + protocol: udp + wazuh_agent_authd: + enable: true + port: 1515 + ssl_agent_ca: null + ssl_auto_negotiate: 'no'