diff --git a/roles/wazuh/ansible-wazuh-manager/defaults/main.yml b/roles/wazuh/ansible-wazuh-manager/defaults/main.yml index 88a9fb20..3251a6ce 100644 --- a/roles/wazuh/ansible-wazuh-manager/defaults/main.yml +++ b/roles/wazuh/ansible-wazuh-manager/defaults/main.yml @@ -174,6 +174,7 @@ wazuh_manager_sca: wazuh_manager_vulnerability_detector: enabled: 'no' interval: '5m' + min_full_scan_interval: '6h' run_on_start: 'yes' providers: - enabled: 'no' @@ -181,20 +182,47 @@ wazuh_manager_vulnerability_detector: - 'trusty' - 'xenial' - 'bionic' + - 'focal' + - 'jammy' update_interval: '1h' name: '"canonical"' - enabled: 'no' os: - - 'wheezy' - - 'stretch' - - 'jessie' - 'buster' + - 'bullseye' update_interval: '1h' name: '"debian"' - enabled: 'no' - update_from_year: '2010' + os: + - '5' + - '6' + - '7' + - '8' + - '9' update_interval: '1h' name: '"redhat"' + - enabled: 'no' + os: + - 'amazon-linux' + - 'amazon-linux-2' + update_interval: '1h' + name: '"alas"' + - enabled: 'no' + os: + - '11-server' + - '11-desktop' + - '12-server' + - '12-desktop' + - '15-server' + - '15-desktop' + update_interval: '1h' + name: '"suse"' + - enabled: 'no' + update_interval: '1h' + name: '"arch"' + - enabled: 'no' + update_interval: '1h' + name: '"msu"' - enabled: 'no' update_from_year: '2010' update_interval: '1h' diff --git a/roles/wazuh/ansible-wazuh-manager/templates/var-ossec-etc-ossec-server.conf.j2 b/roles/wazuh/ansible-wazuh-manager/templates/var-ossec-etc-ossec-server.conf.j2 index cf87a44c..658fcf43 100644 --- a/roles/wazuh/ansible-wazuh-manager/templates/var-ossec-etc-ossec-server.conf.j2 +++ b/roles/wazuh/ansible-wazuh-manager/templates/var-ossec-etc-ossec-server.conf.j2 @@ -265,6 +265,9 @@ {% if wazuh_manager_config.vulnerability_detector.interval is defined %} {{ wazuh_manager_config.vulnerability_detector.interval }} {% endif %} + {% if wazuh_manager_config.vulnerability_detector.min_full_scan_interval is defined %} + {{ wazuh_manager_config.vulnerability_detector.min_full_scan_interval }} + {% endif %} {% if wazuh_manager_config.vulnerability_detector.run_on_start is defined %} {{ wazuh_manager_config.vulnerability_detector.run_on_start }} {% endif %}