diff --git a/roles/wazuh/ansible-wazuh-manager/defaults/main.yml b/roles/wazuh/ansible-wazuh-manager/defaults/main.yml index c7e319d1..63acaebc 100644 --- a/roles/wazuh/ansible-wazuh-manager/defaults/main.yml +++ b/roles/wazuh/ansible-wazuh-manager/defaults/main.yml @@ -185,8 +185,8 @@ wazuh_manager_config: expect: 'srcip' timeout_allowed: 'yes' ruleset: - rules_path: 'custom_ruleset/rules/' - decoders_path: 'custom_ruleset/decoders/' + rules_path: '/custom_ruleset/rules/' + decoders_path: '/custom_ruleset/decoders/' rule_exclude: - '0215-policy_rules.xml' active_responses: @@ -221,11 +221,10 @@ wazuh_agent_configs: - /etc/svc/volatile no_diff: - /etc/ssl/private.key - directories: - - dirs: /etc,/usr/bin,/usr/sbin - checks: 'check_all="yes"' - - dirs: /bin,/sbin - checks: 'check_all="yes"' + # Example + #directories: + #- dirs: /etc,/usr/bin,/usr/sbin + # checks: 'check_all="yes"' rootcheck: frequency: 43200 cis_distribution_filename: null