Merge branch 'devel' into async_ignore_check_mode
This commit is contained in:
commit
67305df536
4
.gitignore
vendored
4
.gitignore
vendored
@ -5,4 +5,6 @@ wazuh-elastic_stack-single.yml
|
|||||||
wazuh-elastic.yml
|
wazuh-elastic.yml
|
||||||
wazuh-kibana.yml
|
wazuh-kibana.yml
|
||||||
wazuh-manager.yml
|
wazuh-manager.yml
|
||||||
*.pyc
|
*.pyc
|
||||||
|
Pipfile.lock
|
||||||
|
*.swp
|
||||||
|
|||||||
201
CHANGELOG.md
Normal file → Executable file
201
CHANGELOG.md
Normal file → Executable file
@ -1,9 +1,201 @@
|
|||||||
# Change Log
|
# Change Log
|
||||||
All notable changes to this project will be documented in this file.
|
All notable changes to this project will be documented in this file.
|
||||||
|
|
||||||
|
## [v3.12.0_7.6.1]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.12.0
|
||||||
|
- Added registration address variable to wazuh-agent playbook ([@Zenidd](https://github.com/Zenidd)) [PR#392](https://github.com/wazuh/wazuh-ansible/pull/392)
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Bump NodeJS version to 10.x ([@manuasir](https://github.com/manuasir)) [PR#386](https://github.com/wazuh/wazuh-ansible/pull/386)
|
||||||
|
- Add flag to enable/disable Windows MD5 check ([@jm404](https://github.com/jm404)) [PR#383](https://github.com/wazuh/wazuh-ansible/pull/383)
|
||||||
|
- Rule paths are now relative to playbooks. ([@Zenidd ](https://github.com/Zenidd)) [PR#393](https://github.com/wazuh/wazuh-ansible/pull/393)
|
||||||
|
- Add the option to create agent groups and add an agent to 1 or more group. ([@rshad](https://github.com/rshad)) [PR#361](https://github.com/wazuh/wazuh-ansible/pull/361)
|
||||||
|
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Removed bad formed XML comments. ([@manuasir](https://github.com/manuasir)) [PR#391](https://github.com/wazuh/wazuh-ansible/pull/391)
|
||||||
|
- NodeJS node_options variable and Kibana plugin optimization fix. ([@Zenidd](https://github.com/Zenidd)) [PR#385](https://github.com/wazuh/wazuh-ansible/pull/385)
|
||||||
|
- Restrictive permissions for certificate files. ([@Zenidd](https://github.com/Zenidd)) [PR#382](https://github.com/wazuh/wazuh-ansible/pull/382)
|
||||||
|
|
||||||
|
## [v3.11.4_7.6.1]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.11.4
|
||||||
|
- Support for RHEL/CentOS 8 ([@jm404](https://github.com/jm404)) [PR#377](https://github.com/wazuh/wazuh-ansible/pull/377)
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Disabled shared configuration by default ([@jm404](https://github.com/jm404)) [PR#369](https://github.com/wazuh/wazuh-ansible/pull/369)
|
||||||
|
- Add chdir argument to Wazuh Kibana Plugin installation tasks ([@jm404](https://github.com/jm404)) [PR#375](https://github.com/wazuh/wazuh-ansible/pull/375)
|
||||||
|
- Adjustments for systems without (direct) internet connection ([@joschneid](https://github.com/joschneid)) [PR#348](https://github.com/wazuh/wazuh-ansible/pull/348)
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Avoid to install Wazuh API in worker nodes ([@manuasir](https://github.com/manuasir)) [PR#371](https://github.com/wazuh/wazuh-ansible/pull/371)
|
||||||
|
- Conditionals of custom Wazuh packages installation tasks ([@rshad](https://github.com/rshad)) [PR#372](https://github.com/wazuh/wazuh-ansible/pull/372)
|
||||||
|
- Fix Ansible elastic_stack-distributed template ([@francobep](https://github.com/francobep)) [PR#352](https://github.com/wazuh/wazuh-ansible/pull/352)
|
||||||
|
- Fix manager API verification ([@Zenidd](https://github.com/Zenidd)) [PR#360](https://github.com/wazuh/wazuh-ansible/pull/360)
|
||||||
|
|
||||||
|
## [v3.11.3_7.5.2]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.11.3
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Fix Wazuh Agent configuration file for RHEL 8 ([@xr09](https://github.com/xr09)) [PR#354](https://github.com/wazuh/wazuh-ansible/pull/354)
|
||||||
|
- Fix default port used in Wazuh Agent playbook ([@jm404](https://github.com/jm404)) [PR#347](https://github.com/wazuh/wazuh-ansible/pull/347)
|
||||||
|
|
||||||
|
## [v3.11.2_7.5.1]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.11.2
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Update templates for Python 3 compatibility ([@xr09](https://github.com/xr09)) [PR#344](https://github.com/wazuh/wazuh-ansible/pull/344)
|
||||||
|
|
||||||
|
## [v3.11.1_7.5.1]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.11.1
|
||||||
|
|
||||||
|
|
||||||
|
## [v3.11.0_7.5.1]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.11.0
|
||||||
|
|
||||||
|
- Implemented changes to configure Wazuh API using the `wazuh.yml` file ([@xr09](https://github.com/xr09)) [PR#342](https://github.com/wazuh/wazuh-ansible/pull/342)
|
||||||
|
|
||||||
|
- Wazuh Agent registration task now explicitly notify restart ([@jm404](https://github.com/jm404)) [PR#302](https://github.com/wazuh/wazuh-ansible/pull/302)
|
||||||
|
|
||||||
|
- Support both IP and DNS when creating elastic cluster ([@xr09](https://github.com/xr09)) [PR#252](https://github.com/wazuh/wazuh-ansible/pull/252)
|
||||||
|
|
||||||
|
- Added config tag to the Wazuh Agent's enable task ([@xr09](https://github.com/xr09)) [PR#261](https://github.com/wazuh/wazuh-ansible/pull/261)
|
||||||
|
|
||||||
|
- Implement task to configure Elasticsearch user on every cluster node ([@xr09](https://github.com/xr09)) [PR#270](https://github.com/wazuh/wazuh-ansible/pull/270)
|
||||||
|
|
||||||
|
- Added SCA to Wazuh Agent and Manager installation ([@jm404](https://github.com/jm404)) [PR#260](https://github.com/wazuh/wazuh-ansible/pull/260)
|
||||||
|
|
||||||
|
- Added support for environments with low disk space ([@xr09](https://github.com/xr09)) [PR#281](https://github.com/wazuh/wazuh-ansible/pull/281)
|
||||||
|
|
||||||
|
- Add parameters to configure an Elasticsearch coordinating node ([@jm404](https://github.com/jm404)) [PR#292](https://github.com/wazuh/wazuh-ansible/pull/292)
|
||||||
|
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Updated Filebeat and Elasticsearch templates ([@manuasir](https://github.com/manuasir)) [PR#285](https://github.com/wazuh/wazuh-ansible/pull/285)
|
||||||
|
|
||||||
|
- Make ossec.conf file more readable by removing trailing whitespaces ([@jm404](https://github.com/jm404)) [PR#286](https://github.com/wazuh/wazuh-ansible/pull/286)
|
||||||
|
|
||||||
|
- Wazuh repositories can now be configured to different sources URLs ([@jm404](https://github.com/jm404)) [PR#288](https://github.com/wazuh/wazuh-ansible/pull/288)
|
||||||
|
|
||||||
|
- Wazuh App URL is now flexible ([@jm404](https://github.com/jm404)) [PR#304](https://github.com/wazuh/wazuh-ansible/pull/304)
|
||||||
|
|
||||||
|
- Agent installation task now does not hardcodes the "-1" sufix ([@jm404](https://github.com/jm404)) [PR#310](https://github.com/wazuh/wazuh-ansible/pull/310)
|
||||||
|
|
||||||
|
- Enhanced task importation in Wazuh Manager role and removed deprecated warnings ([@xr09](https://github.com/xr09)) [PR#320](https://github.com/wazuh/wazuh-ansible/pull/320)
|
||||||
|
|
||||||
|
- Wazuh API installation task have been upgraded ([@rshad](https://github.com/rshad)) [PR#330](https://github.com/wazuh/wazuh-ansible/pull/330)
|
||||||
|
|
||||||
|
- It's now possible to install Wazuh Manager and Agent from sources ([@jm404](https://github.com/jm404)) [PR#329](https://github.com/wazuh/wazuh-ansible/pull/329)
|
||||||
|
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Ansible upgrade from 6.x to 7.x ([@jm404](https://github.com/jm404)) [PR#252](https://github.com/wazuh/wazuh-ansible/pull/251)
|
||||||
|
|
||||||
|
- Wazuh Agent registration using agent name has been fixed ([@jm404](https://github.com/jm404)) [PR#298](https://github.com/wazuh/wazuh-ansible/pull/298)
|
||||||
|
- Fix Wazuh repository and installation conditionals ([@jm404](https://github.com/jm404)) [PR#299](https://github.com/wazuh/wazuh-ansible/pull/299)
|
||||||
|
|
||||||
|
- Fixed Wazuh Agent registration using an Agent's name ([@jm404](https://github.com/jm404)) [PR#334](https://github.com/wazuh/wazuh-ansible/pull/334)
|
||||||
|
|
||||||
|
|
||||||
|
## [v3.11.0_7.3.2]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.11.0
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Moved molecule folder to Wazuh QA Repository [manuasir](https://github.com/manuasir) [#120ed16](https://github.com/wazuh/wazuh-ansible/commit/120ed163b6f131315848938beca65c1f1cad7f1b)
|
||||||
|
|
||||||
|
- Refactored XPack Security configuration tasks [@jm404](https://github.com/jm404) [#246](https://github.com/wazuh/wazuh-ansible/pull/246)
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Fixed ES bootstrap password configuration [@jm404](https://github.com/jm404) [#b8803de](https://github.com/wazuh/wazuh-ansible/commit/b8803de85fb71edf090b0c076d4fe3684cd7cb36)
|
||||||
|
|
||||||
|
## [v3.10.0_7.3.2]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.10.0
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Updated Kibana [@jm404](https://github.com/jm404) [#237](https://github.com/wazuh/wazuh-ansible/pull/237)
|
||||||
|
- Updated agent.conf template [@moodymob](https://github.com/moodymob) [#222](https://github.com/wazuh/wazuh-ansible/pull/222)
|
||||||
|
- Improved molecule tests [@rshad](https://github.com/rshad) [#223](https://github.com/wazuh/wazuh-ansible/pull/223/files)
|
||||||
|
- Moved "run_cluster_mode.sh" script to molecule folder [@jm404](https://github.com/jm404) [#a9d2c52](https://github.com/wazuh/wazuh-ansible/commit/a9d2c5201047c273c2c4fead5a54e576111da455)
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Fixed typo in the `agent.conf` template [@joey1a2b3c](https://github.com/joey1a2b3c) [#227](https://github.com/wazuh/wazuh-ansible/pull/227)
|
||||||
|
- Updated conditionals in tasks to fix Amazon Linux installation [@jm404](https://github.com/jm404) [#229](https://github.com/wazuh/wazuh-ansible/pull/229)
|
||||||
|
- Fixed Kibana installation in Amazon Linux [@jm404](https://github.com/jm404) [#232](https://github.com/wazuh/wazuh-ansible/pull/232)
|
||||||
|
- Fixed Windows Agent installation and configuration [@jm404](https://github.com/jm404) [#234](https://github.com/wazuh/wazuh-ansible/pull/234)
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Removed registry key check on Wazuh Agent installation in windows [@jm404](https://github.com/jm404) [#265](https://github.com/wazuh/wazuh-ansible/pull/265)
|
||||||
|
|
||||||
|
## [v3.9.5_7.2.1]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Update to Wazuh v3.9.5
|
||||||
|
- Update to Elastic Stack to v7.2.1
|
||||||
|
|
||||||
|
## [v3.9.4_7.2.0]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Support for registring agents behind NAT [@jheikki100](https://github.com/jheikki100) [#208](https://github.com/wazuh/wazuh-ansible/pull/208)
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Default protocol to TCP [@ionphractal](https://github.com/ionphractal) [#204](https://github.com/wazuh/wazuh-ansible/pull/204).
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Fixed network.host is not localhost [@rshad](https://github.com/rshad) [#204](https://github.com/wazuh/wazuh-ansible/pull/212).
|
||||||
|
|
||||||
|
## [v3.9.3_7.2.0]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- Update to Wazuh v3.9.3 ([rshad](https://github.com/rshad) [PR#206](https://github.com/wazuh/wazuh-ansible/pull/206#))
|
||||||
|
- Added Versioning Control for Wazuh stack's components installation, so now it's possible to specify which package to install for wazuh-manager, wazuh-agent, Filebeat, Elasticsearch and Kibana. ([rshad](https://github.com/rshad) [PR#206](https://github.com/wazuh/wazuh-ansible/pull/206#))
|
||||||
|
- Fixes for Molecule testing issues. Issues such as Ansible-Lint and None-Idempotent tasks. ([rshad](https://github.com/rshad) [PR#206](https://github.com/wazuh/wazuh-ansible/pull/206#))
|
||||||
|
- Fixes for Wazuh components installations' related issues. Such issues were related to determined OS distributions such as `Ubuntu Trusty` and `CetOS 6`. ([rshad](https://github.com/rshad) [PR#206](https://github.com/wazuh/wazuh-ansible/pull/206#))
|
||||||
|
- Created Ansible playbook and role in order to automate the uninstallation of already installed Wazuh components. ([rshad](https://github.com/rshad) [PR#206](https://github.com/wazuh/wazuh-ansible/pull/206#))
|
||||||
|
|
||||||
|
|
||||||
## [v3.9.2_7.1.1]
|
## [v3.9.2_7.1.1]
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- Update to Wazuh v3.9.2
|
- Update to Wazuh v3.9.2
|
||||||
- Support for Elastic 7
|
- Support for Elastic 7
|
||||||
@ -11,13 +203,13 @@ All notable changes to this project will be documented in this file.
|
|||||||
|
|
||||||
## [v3.9.2_6.8.0]
|
## [v3.9.2_6.8.0]
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- Update to Wazuh v3.9.2
|
- Update to Wazuh v3.9.2
|
||||||
|
|
||||||
## [v3.9.1]
|
## [v3.9.1]
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- Update to Wazuh v3.9.1
|
- Update to Wazuh v3.9.1
|
||||||
- Support for ELK v6.8.0
|
- Support for ELK v6.8.0
|
||||||
@ -45,7 +237,7 @@ All notable changes to this project will be documented in this file.
|
|||||||
|
|
||||||
## [v3.8.2]
|
## [v3.8.2]
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- Update to Wazuh version v3.8.2. ([#150](https://github.com/wazuh/wazuh-ansible/pull/150))
|
- Update to Wazuh version v3.8.2. ([#150](https://github.com/wazuh/wazuh-ansible/pull/150))
|
||||||
|
|
||||||
@ -145,4 +337,3 @@ Roles:
|
|||||||
- ansible-filebeat: This role is prepared to install filebeat on the host that runs it.
|
- ansible-filebeat: This role is prepared to install filebeat on the host that runs it.
|
||||||
- ansible-wazuh-manager: With this role we will install Wazuh manager and Wazuh API on the host that runs it.
|
- ansible-wazuh-manager: With this role we will install Wazuh manager and Wazuh API on the host that runs it.
|
||||||
- ansible-wazuh-agent: Using this role we will install Wazuh agent on the host that runs it and is able to register it.
|
- ansible-wazuh-agent: Using this role we will install Wazuh agent on the host that runs it and is able to register it.
|
||||||
|
|
||||||
|
|||||||
18
Pipfile
18
Pipfile
@ -1,18 +0,0 @@
|
|||||||
[[source]]
|
|
||||||
url = "https://pypi.org/simple"
|
|
||||||
verify_ssl = true
|
|
||||||
name = "pypi"
|
|
||||||
|
|
||||||
[packages]
|
|
||||||
molecule = "*"
|
|
||||||
docker-py = "*"
|
|
||||||
ansible = "*"
|
|
||||||
|
|
||||||
[dev-packages]
|
|
||||||
|
|
||||||
[requires]
|
|
||||||
python_version = "2.7"
|
|
||||||
|
|
||||||
[scripts]
|
|
||||||
test ="molecule test"
|
|
||||||
agent ="molecule test -s wazuh-agent"
|
|
||||||
15
README.md
15
README.md
@ -47,6 +47,21 @@ These playbooks install and configure Wazuh agent, manager and Elastic Stack.
|
|||||||
* `master` branch contains the latest code, be aware of possible bugs on this branch.
|
* `master` branch contains the latest code, be aware of possible bugs on this branch.
|
||||||
|
|
||||||
## Testing
|
## Testing
|
||||||
|
|
||||||
|
1. Get the `wazuh-ansible` folder from the `wazuh-qa` [repository](https://github.com/wazuh/wazuh-qa/tree/master/ansible/wazuh-ansible).
|
||||||
|
|
||||||
|
```
|
||||||
|
git clone https://github.com/wazuh/wazuh-qa
|
||||||
|
```
|
||||||
|
|
||||||
|
2. Copy the `Pipfile` and the `molecule` folder into the root wazuh-ansible directory:
|
||||||
|
|
||||||
|
```
|
||||||
|
cp wazuh-qa/ansible/wazuh-ansible/* . -R
|
||||||
|
```
|
||||||
|
|
||||||
|
3. Follow these steps for launching the tests. Check the Pipfile for running different scenarios:
|
||||||
|
|
||||||
```
|
```
|
||||||
pip install pipenv
|
pip install pipenv
|
||||||
sudo pipenv install
|
sudo pipenv install
|
||||||
|
|||||||
4
VERSION
4
VERSION
@ -1,2 +1,2 @@
|
|||||||
WAZUH-ANSIBLE_VERSION="v3.9.1"
|
WAZUH-ANSIBLE_VERSION="v4"
|
||||||
REVISION="3901"
|
REVISION="31140"
|
||||||
|
|||||||
@ -1,14 +0,0 @@
|
|||||||
# Molecule managed
|
|
||||||
|
|
||||||
{% if item.registry is defined %}
|
|
||||||
FROM {{ item.registry.url }}/{{ item.image }}
|
|
||||||
{% else %}
|
|
||||||
FROM {{ item.image }}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
RUN if [ $(command -v apt-get) ]; then apt-get update && apt-get upgrade -y && apt-get install -y python sudo bash ca-certificates && apt-get clean; \
|
|
||||||
elif [ $(command -v dnf) ]; then dnf makecache && dnf --assumeyes install python sudo python-devel python2-dnf bash && dnf clean all; \
|
|
||||||
elif [ $(command -v yum) ]; then yum makecache fast && yum update -y && yum install -y python sudo yum-plugin-ovl bash && sed -i 's/plugins=0/plugins=1/g' /etc/yum.conf && yum clean all; \
|
|
||||||
elif [ $(command -v zypper) ]; then zypper refresh && zypper update -y && zypper install -y python sudo bash python-xml && zypper clean -a; \
|
|
||||||
elif [ $(command -v apk) ]; then apk update && apk add --no-cache python sudo bash ca-certificates; \
|
|
||||||
elif [ $(command -v xbps-install) ]; then xbps-install -Syu && xbps-install -y python sudo bash ca-certificates && xbps-remove -O; fi
|
|
||||||
@ -1,16 +0,0 @@
|
|||||||
*******
|
|
||||||
Install
|
|
||||||
*******
|
|
||||||
|
|
||||||
Requirements
|
|
||||||
============
|
|
||||||
|
|
||||||
* Docker Engine
|
|
||||||
* docker-py
|
|
||||||
|
|
||||||
Install
|
|
||||||
=======
|
|
||||||
|
|
||||||
.. code-block:: bash
|
|
||||||
|
|
||||||
$ sudo pip install docker-py
|
|
||||||
@ -1,81 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Create
|
|
||||||
hosts: localhost
|
|
||||||
connection: local
|
|
||||||
gather_facts: false
|
|
||||||
no_log: false
|
|
||||||
tasks:
|
|
||||||
- name: Log into a Docker registry
|
|
||||||
docker_login:
|
|
||||||
username: "{{ item.registry.credentials.username }}"
|
|
||||||
password: "{{ item.registry.credentials.password }}"
|
|
||||||
email: "{{ item.registry.credentials.email | default(omit) }}"
|
|
||||||
registry: "{{ item.registry.url }}"
|
|
||||||
docker_host: "{{ item.docker_host | default('unix://var/run/docker.sock') }}"
|
|
||||||
with_items: "{{ molecule_yml.platforms }}"
|
|
||||||
when:
|
|
||||||
- item.registry is defined
|
|
||||||
- item.registry.credentials is defined
|
|
||||||
- item.registry.credentials.username is defined
|
|
||||||
|
|
||||||
- name: Create Dockerfiles from image names
|
|
||||||
template:
|
|
||||||
src: "{{ molecule_scenario_directory }}/Dockerfile.j2"
|
|
||||||
dest: "{{ molecule_ephemeral_directory }}/Dockerfile_{{ item.image | regex_replace('[^a-zA-Z0-9_]', '_') }}"
|
|
||||||
with_items: "{{ molecule_yml.platforms }}"
|
|
||||||
register: platforms
|
|
||||||
|
|
||||||
- name: Discover local Docker images
|
|
||||||
docker_image_facts:
|
|
||||||
name: "molecule_local/{{ item.item.name }}"
|
|
||||||
docker_host: "{{ item.item.docker_host | default('unix://var/run/docker.sock') }}"
|
|
||||||
with_items: "{{ platforms.results }}"
|
|
||||||
register: docker_images
|
|
||||||
|
|
||||||
- name: Build an Ansible compatible image
|
|
||||||
docker_image:
|
|
||||||
path: "{{ molecule_ephemeral_directory }}"
|
|
||||||
name: "molecule_local/{{ item.item.image }}"
|
|
||||||
docker_host: "{{ item.item.docker_host | default('unix://var/run/docker.sock') }}"
|
|
||||||
dockerfile: "{{ item.item.dockerfile | default(item.invocation.module_args.dest) }}"
|
|
||||||
force: "{{ item.item.force | default(true) }}"
|
|
||||||
with_items: "{{ platforms.results }}"
|
|
||||||
when: platforms.changed or docker_images.results | map(attribute='images') | select('equalto', []) | list | count >= 0
|
|
||||||
|
|
||||||
- name: Create docker network(s)
|
|
||||||
docker_network:
|
|
||||||
name: "{{ item }}"
|
|
||||||
docker_host: "{{ item.docker_host | default('unix://var/run/docker.sock') }}"
|
|
||||||
state: present
|
|
||||||
with_items: "{{ molecule_yml.platforms | molecule_get_docker_networks }}"
|
|
||||||
|
|
||||||
- name: Create molecule instance(s)
|
|
||||||
docker_container:
|
|
||||||
name: "{{ item.name }}"
|
|
||||||
docker_host: "{{ item.docker_host | default('unix://var/run/docker.sock') }}"
|
|
||||||
hostname: "{{ item.name }}"
|
|
||||||
image: "molecule_local/{{ item.image }}"
|
|
||||||
state: started
|
|
||||||
recreate: false
|
|
||||||
log_driver: json-file
|
|
||||||
command: "{{ item.command | default('bash -c \"while true; do sleep 10000; done\"') }}"
|
|
||||||
privileged: "{{ item.privileged | default(omit) }}"
|
|
||||||
volumes: "{{ item.volumes | default(omit) }}"
|
|
||||||
capabilities: "{{ item.capabilities | default(omit) }}"
|
|
||||||
exposed_ports: "{{ item.exposed_ports | default(omit) }}"
|
|
||||||
published_ports: "{{ item.published_ports | default(omit) }}"
|
|
||||||
ulimits: "{{ item.ulimits | default(omit) }}"
|
|
||||||
networks: "{{ item.networks | default(omit) }}"
|
|
||||||
dns_servers: "{{ item.dns_servers | default(omit) }}"
|
|
||||||
register: server
|
|
||||||
with_items: "{{ molecule_yml.platforms }}"
|
|
||||||
async: 7200
|
|
||||||
poll: 0
|
|
||||||
|
|
||||||
- name: Wait for instance(s) creation to complete
|
|
||||||
async_status:
|
|
||||||
jid: "{{ item.ansible_job_id }}"
|
|
||||||
register: docker_jobs
|
|
||||||
until: docker_jobs.finished
|
|
||||||
retries: 300
|
|
||||||
with_items: "{{ server.results }}"
|
|
||||||
@ -1,32 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Destroy
|
|
||||||
hosts: localhost
|
|
||||||
connection: local
|
|
||||||
gather_facts: false
|
|
||||||
no_log: false
|
|
||||||
tasks:
|
|
||||||
- name: Destroy molecule instance(s)
|
|
||||||
docker_container:
|
|
||||||
name: "{{ item.name }}"
|
|
||||||
docker_host: "{{ item.docker_host | default('unix://var/run/docker.sock') }}"
|
|
||||||
state: absent
|
|
||||||
force_kill: "{{ item.force_kill | default(true) }}"
|
|
||||||
register: server
|
|
||||||
with_items: "{{ molecule_yml.platforms }}"
|
|
||||||
async: 7200
|
|
||||||
poll: 0
|
|
||||||
|
|
||||||
- name: Wait for instance(s) deletion to complete
|
|
||||||
async_status:
|
|
||||||
jid: "{{ item.ansible_job_id }}"
|
|
||||||
register: docker_jobs
|
|
||||||
until: docker_jobs.finished
|
|
||||||
retries: 300
|
|
||||||
with_items: "{{ server.results }}"
|
|
||||||
|
|
||||||
- name: Delete docker network(s)
|
|
||||||
docker_network:
|
|
||||||
name: "{{ item }}"
|
|
||||||
docker_host: "{{ item.docker_host | default('unix://var/run/docker.sock') }}"
|
|
||||||
state: absent
|
|
||||||
with_items: "{{ molecule_yml.platforms | molecule_get_docker_networks }}"
|
|
||||||
@ -1,50 +0,0 @@
|
|||||||
---
|
|
||||||
dependency:
|
|
||||||
name: galaxy
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
lint:
|
|
||||||
name: yamllint
|
|
||||||
enabled: false
|
|
||||||
platforms:
|
|
||||||
- name: bionic
|
|
||||||
image: ubuntu:bionic
|
|
||||||
- name: xenial
|
|
||||||
image: solita/ubuntu-systemd:xenial
|
|
||||||
privileged: true
|
|
||||||
command: /sbin/init
|
|
||||||
- name: trusty
|
|
||||||
image: ubuntu:trusty
|
|
||||||
- name: centos6
|
|
||||||
image: centos:6
|
|
||||||
- name: centos7
|
|
||||||
image: milcom/centos7-systemd
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
env:
|
|
||||||
ANSIBLE_ROLES_PATH: ../../roles
|
|
||||||
lint:
|
|
||||||
name: ansible-lint
|
|
||||||
enabled: true
|
|
||||||
scenario:
|
|
||||||
name: default
|
|
||||||
test_sequence:
|
|
||||||
- lint
|
|
||||||
- dependency
|
|
||||||
- cleanup
|
|
||||||
- destroy
|
|
||||||
- syntax
|
|
||||||
- create
|
|
||||||
- prepare
|
|
||||||
- converge
|
|
||||||
# - idempotence
|
|
||||||
- side_effect
|
|
||||||
- verify
|
|
||||||
- cleanup
|
|
||||||
- destroy
|
|
||||||
verifier:
|
|
||||||
name: testinfra
|
|
||||||
lint:
|
|
||||||
name: flake8
|
|
||||||
enabled: true
|
|
||||||
@ -1,10 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Converge
|
|
||||||
hosts: all
|
|
||||||
roles:
|
|
||||||
- role: wazuh/ansible-wazuh-manager
|
|
||||||
|
|
||||||
# - {role: wazuh/ansible-filebeat} #, filebeat_output_elasticsearch_hosts: 'your elastic stack server IP'
|
|
||||||
# Elasticsearch requires too much memory to test multiple containers concurrently - To Fix
|
|
||||||
# - {role: elastic-stack/ansible-elasticsearch, elasticsearch_network_host: 'localhost'}
|
|
||||||
# - {role: elastic-stack/ansible-kibana, elasticsearch_network_host: 'localhost'}
|
|
||||||
@ -1,26 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Prepare
|
|
||||||
hosts: all
|
|
||||||
gather_facts: true
|
|
||||||
tasks:
|
|
||||||
|
|
||||||
- name: "Install Python packages for Trusty to solve trust issues"
|
|
||||||
package:
|
|
||||||
name:
|
|
||||||
- python-setuptools
|
|
||||||
- python-pip
|
|
||||||
state: latest
|
|
||||||
register: wazuh_manager_trusty_packages_installed
|
|
||||||
until: wazuh_manager_trusty_packages_installed is succeeded
|
|
||||||
when:
|
|
||||||
- ansible_distribution == "Ubuntu"
|
|
||||||
- ansible_distribution_major_version | int == 14
|
|
||||||
|
|
||||||
- name: "Install dependencies"
|
|
||||||
package:
|
|
||||||
name:
|
|
||||||
- curl
|
|
||||||
- net-tools
|
|
||||||
state: latest
|
|
||||||
register: wazuh_manager_dependencies_packages_installed
|
|
||||||
until: wazuh_manager_dependencies_packages_installed is succeeded
|
|
||||||
@ -1,80 +0,0 @@
|
|||||||
import os
|
|
||||||
import pytest
|
|
||||||
|
|
||||||
import testinfra.utils.ansible_runner
|
|
||||||
|
|
||||||
testinfra_hosts = testinfra.utils.ansible_runner.AnsibleRunner(
|
|
||||||
os.environ['MOLECULE_INVENTORY_FILE']).get_hosts('all')
|
|
||||||
|
|
||||||
|
|
||||||
def get_wazuh_version():
|
|
||||||
"""This return the version of Wazuh."""
|
|
||||||
return "3.9.2"
|
|
||||||
|
|
||||||
|
|
||||||
def test_wazuh_packages_are_installed(host):
|
|
||||||
"""Test if the main packages are installed."""
|
|
||||||
manager = host.package("wazuh-manager")
|
|
||||||
api = host.package("wazuh-api")
|
|
||||||
|
|
||||||
distribution = host.system_info.distribution.lower()
|
|
||||||
if distribution == 'centos':
|
|
||||||
if host.system_info.release == "7":
|
|
||||||
assert manager.is_installed
|
|
||||||
assert manager.version.startswith(get_wazuh_version())
|
|
||||||
assert api.is_installed
|
|
||||||
assert api.version.startswith(get_wazuh_version())
|
|
||||||
elif host.system_info.release.startswith("6"):
|
|
||||||
assert manager.is_installed
|
|
||||||
assert manager.version.startswith(get_wazuh_version())
|
|
||||||
elif distribution == 'ubuntu':
|
|
||||||
assert manager.is_installed
|
|
||||||
assert manager.version.startswith(get_wazuh_version())
|
|
||||||
|
|
||||||
|
|
||||||
def test_wazuh_services_are_running(host):
|
|
||||||
"""Test if the services are enabled and running.
|
|
||||||
|
|
||||||
When assert commands are commented, this means that the service command has
|
|
||||||
a wrong exit code: https://github.com/wazuh/wazuh-ansible/issues/107
|
|
||||||
"""
|
|
||||||
manager = host.service("wazuh-manager")
|
|
||||||
api = host.service("wazuh-api")
|
|
||||||
|
|
||||||
distribution = host.system_info.distribution.lower()
|
|
||||||
if distribution == 'centos':
|
|
||||||
# assert manager.is_running
|
|
||||||
assert manager.is_enabled
|
|
||||||
# assert not api.is_running
|
|
||||||
assert not api.is_enabled
|
|
||||||
elif distribution == 'ubuntu':
|
|
||||||
# assert manager.is_running
|
|
||||||
assert manager.is_enabled
|
|
||||||
# assert api.is_running
|
|
||||||
assert api.is_enabled
|
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.parametrize("wazuh_file, wazuh_owner, wazuh_group, wazuh_mode", [
|
|
||||||
("/var/ossec/etc/sslmanager.cert", "root", "root", 0o640),
|
|
||||||
("/var/ossec/etc/sslmanager.key", "root", "root", 0o640),
|
|
||||||
("/var/ossec/etc/rules/local_rules.xml", "root", "ossec", 0o640),
|
|
||||||
("/var/ossec/etc/lists/audit-keys", "root", "ossec", 0o640),
|
|
||||||
])
|
|
||||||
def test_wazuh_files(host, wazuh_file, wazuh_owner, wazuh_group, wazuh_mode):
|
|
||||||
"""Test if Wazuh related files exist and have proper owners and mode."""
|
|
||||||
wazuh_file_host = host.file(wazuh_file)
|
|
||||||
|
|
||||||
assert wazuh_file_host.user == wazuh_owner
|
|
||||||
assert wazuh_file_host.group == wazuh_group
|
|
||||||
assert wazuh_file_host.mode == wazuh_mode
|
|
||||||
|
|
||||||
|
|
||||||
def test_open_ports(host):
|
|
||||||
"""Test if the main port is open and the agent-auth is not open."""
|
|
||||||
distribution = host.system_info.distribution.lower()
|
|
||||||
if distribution == 'ubuntu':
|
|
||||||
assert host.socket("tcp://0.0.0.0:1515").is_listening
|
|
||||||
assert not host.socket("tcp://0.0.0.0:1514").is_listening
|
|
||||||
elif distribution == 'centos':
|
|
||||||
assert host.socket("tcp://:::1515").is_listening
|
|
||||||
assert not host.socket("tcp://:::1514").is_listening
|
|
||||||
@ -1,14 +0,0 @@
|
|||||||
# Molecule managed
|
|
||||||
|
|
||||||
{% if item.registry is defined %}
|
|
||||||
FROM {{ item.registry.url }}/{{ item.image }}
|
|
||||||
{% else %}
|
|
||||||
FROM {{ item.image }}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
RUN if [ $(command -v apt-get) ]; then apt-get update && apt-get install -y python sudo bash ca-certificates && apt-get clean; \
|
|
||||||
elif [ $(command -v dnf) ]; then dnf makecache && dnf --assumeyes install python sudo python-devel python*-dnf bash && dnf clean all; \
|
|
||||||
elif [ $(command -v yum) ]; then yum makecache fast && yum install -y python sudo yum-plugin-ovl bash && sed -i 's/plugins=0/plugins=1/g' /etc/yum.conf && yum clean all; \
|
|
||||||
elif [ $(command -v zypper) ]; then zypper refresh && zypper install -y python sudo bash python-xml && zypper clean -a; \
|
|
||||||
elif [ $(command -v apk) ]; then apk update && apk add --no-cache python sudo bash ca-certificates; \
|
|
||||||
elif [ $(command -v xbps-install) ]; then xbps-install -Syu && xbps-install -y python sudo bash ca-certificates && xbps-remove -O; fi
|
|
||||||
@ -1,22 +0,0 @@
|
|||||||
*******
|
|
||||||
Docker driver installation guide
|
|
||||||
*******
|
|
||||||
|
|
||||||
Requirements
|
|
||||||
============
|
|
||||||
|
|
||||||
* Docker Engine
|
|
||||||
|
|
||||||
Install
|
|
||||||
=======
|
|
||||||
|
|
||||||
Please refer to the `Virtual environment`_ documentation for installation best
|
|
||||||
practices. If not using a virtual environment, please consider passing the
|
|
||||||
widely recommended `'--user' flag`_ when invoking ``pip``.
|
|
||||||
|
|
||||||
.. _Virtual environment: https://virtualenv.pypa.io/en/latest/
|
|
||||||
.. _'--user' flag: https://packaging.python.org/tutorials/installing-packages/#installing-to-the-user-site
|
|
||||||
|
|
||||||
.. code-block:: bash
|
|
||||||
|
|
||||||
$ pip install 'molecule[docker]'
|
|
||||||
@ -1,82 +0,0 @@
|
|||||||
---
|
|
||||||
dependency:
|
|
||||||
name: galaxy
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
lint:
|
|
||||||
name: yamllint
|
|
||||||
platforms:
|
|
||||||
- name: wazuh_server_centos7
|
|
||||||
image: milcom/centos7-systemd
|
|
||||||
networks:
|
|
||||||
- name: wazuh
|
|
||||||
privileged: true
|
|
||||||
groups:
|
|
||||||
- manager
|
|
||||||
- name: wazuh_agent_bionic
|
|
||||||
image: ubuntu:bionic
|
|
||||||
networks:
|
|
||||||
- name: wazuh
|
|
||||||
groups:
|
|
||||||
- agent
|
|
||||||
- name: wazuh_agent_xenial
|
|
||||||
image: solita/ubuntu-systemd:xenial
|
|
||||||
privileged: true
|
|
||||||
command: /sbin/init
|
|
||||||
networks:
|
|
||||||
- name: wazuh
|
|
||||||
groups:
|
|
||||||
- agent
|
|
||||||
- name: wazuh_agent_trusty
|
|
||||||
image: ubuntu:trusty
|
|
||||||
networks:
|
|
||||||
- name: wazuh
|
|
||||||
groups:
|
|
||||||
- agent
|
|
||||||
- name: wazuh_agent_centos6
|
|
||||||
image: centos:6
|
|
||||||
networks:
|
|
||||||
- name: wazuh
|
|
||||||
groups:
|
|
||||||
- agent
|
|
||||||
- name: wazuh_agent_centos7
|
|
||||||
image: milcom/centos7-systemd
|
|
||||||
privileged: true
|
|
||||||
networks:
|
|
||||||
- name: wazuh
|
|
||||||
groups:
|
|
||||||
- agent
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
docker:
|
|
||||||
create: ../default/create.yml
|
|
||||||
destroy: ../default/destroy.yml
|
|
||||||
env:
|
|
||||||
ANSIBLE_ROLES_PATH: ../../roles
|
|
||||||
inventory:
|
|
||||||
group_vars:
|
|
||||||
agent:
|
|
||||||
api_pass: password
|
|
||||||
wazuh_managers:
|
|
||||||
- address: "{{ wazuh_manager_ip }}"
|
|
||||||
port: 1514
|
|
||||||
protocol: tcp
|
|
||||||
api_port: 55000
|
|
||||||
api_proto: 'http'
|
|
||||||
api_user: null
|
|
||||||
wazuh_agent_authd:
|
|
||||||
enable: true
|
|
||||||
port: 1515
|
|
||||||
ssl_agent_ca: null
|
|
||||||
ssl_agent_cert: null
|
|
||||||
ssl_agent_key: null
|
|
||||||
ssl_auto_negotiate: 'no'
|
|
||||||
|
|
||||||
lint:
|
|
||||||
name: ansible-lint
|
|
||||||
enabled: true
|
|
||||||
verifier:
|
|
||||||
name: testinfra
|
|
||||||
lint:
|
|
||||||
name: flake8
|
|
||||||
@ -1,20 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Converge
|
|
||||||
hosts: agent
|
|
||||||
pre_tasks:
|
|
||||||
- name: "Get ip Wazuh Manager"
|
|
||||||
shell: |
|
|
||||||
set -o pipefail
|
|
||||||
grep $(hostname) /etc/hosts | awk '{print $1}' | sort | head -n 2 | tail -n 1
|
|
||||||
register: wazuh_manager_ip_stdout
|
|
||||||
changed_when: false
|
|
||||||
delegate_to: wazuh_server_centos7
|
|
||||||
args:
|
|
||||||
executable: /bin/bash
|
|
||||||
|
|
||||||
- name: "Set fact for ip address"
|
|
||||||
set_fact:
|
|
||||||
wazuh_manager_ip: "{{ wazuh_manager_ip_stdout.stdout }}"
|
|
||||||
|
|
||||||
roles:
|
|
||||||
- role: wazuh/ansible-wazuh-agent
|
|
||||||
@ -1,43 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Prepare
|
|
||||||
hosts: manager
|
|
||||||
gather_facts: true
|
|
||||||
tasks:
|
|
||||||
|
|
||||||
- name: "Install dependencies"
|
|
||||||
package:
|
|
||||||
name:
|
|
||||||
- curl
|
|
||||||
- net-tools
|
|
||||||
state: latest
|
|
||||||
register: wazuh_manager_dependencies_packages_installed
|
|
||||||
until: wazuh_manager_dependencies_packages_installed is succeeded
|
|
||||||
|
|
||||||
roles:
|
|
||||||
- role: wazuh/ansible-wazuh-manager
|
|
||||||
|
|
||||||
- name: Prepare
|
|
||||||
hosts: agent
|
|
||||||
gather_facts: true
|
|
||||||
tasks:
|
|
||||||
|
|
||||||
- name: "Install Python packages for Trusty to solve trust issues"
|
|
||||||
package:
|
|
||||||
name:
|
|
||||||
- python-setuptools
|
|
||||||
- python-pip
|
|
||||||
state: latest
|
|
||||||
register: wazuh_manager_trusty_packages_installed
|
|
||||||
until: wazuh_manager_trusty_packages_installed is succeeded
|
|
||||||
when:
|
|
||||||
- ansible_distribution == "Ubuntu"
|
|
||||||
- ansible_distribution_major_version | int == 14
|
|
||||||
|
|
||||||
- name: "Install dependencies"
|
|
||||||
package:
|
|
||||||
name:
|
|
||||||
- curl
|
|
||||||
- net-tools
|
|
||||||
state: latest
|
|
||||||
register: wazuh_agent_dependencies_packages_installed
|
|
||||||
until: wazuh_agent_dependencies_packages_installed is succeeded
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
import os
|
|
||||||
import pytest
|
|
||||||
|
|
||||||
import testinfra.utils.ansible_runner
|
|
||||||
|
|
||||||
testinfra_hosts = testinfra.utils.ansible_runner.AnsibleRunner(
|
|
||||||
os.environ['MOLECULE_INVENTORY_FILE']).get_hosts('agent')
|
|
||||||
|
|
||||||
|
|
||||||
def test_ossec_package_installed(Package):
|
|
||||||
ossec = Package('wazuh-agent')
|
|
||||||
assert ossec.is_installed
|
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.parametrize("wazuh_service, wazuh_owner", (
|
|
||||||
("ossec-agentd", "ossec"),
|
|
||||||
("ossec-execd", "root"),
|
|
||||||
("ossec-syscheckd", "root"),
|
|
||||||
("wazuh-modulesd", "root"),
|
|
||||||
))
|
|
||||||
def test_wazuh_processes_running(host, wazuh_service, wazuh_owner):
|
|
||||||
master = host.process.get(user=wazuh_owner, comm=wazuh_service)
|
|
||||||
assert master.args == "/var/ossec/bin/" + wazuh_service
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
import os
|
|
||||||
|
|
||||||
import testinfra.utils.ansible_runner
|
|
||||||
|
|
||||||
testinfra_hosts = testinfra.utils.ansible_runner.AnsibleRunner(
|
|
||||||
os.environ['MOLECULE_INVENTORY_FILE']).get_hosts('manager')
|
|
||||||
|
|
||||||
|
|
||||||
def test_agents_registered_on_manager(host):
|
|
||||||
cmd = host.run("/var/ossec/bin/manage_agents -l")
|
|
||||||
assert 'wazuh_agent_bionic' in cmd.stdout
|
|
||||||
assert 'wazuh_agent_xenial' in cmd.stdout
|
|
||||||
assert 'wazuh_agent_trusty' in cmd.stdout
|
|
||||||
assert 'wazuh_agent_centos6' in cmd.stdout
|
|
||||||
assert 'wazuh_agent_centos7' in cmd.stdout
|
|
||||||
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
- hosts: <your wazuh agents hosts>
|
- hosts: <your wazuh agents hosts>
|
||||||
roles:
|
roles:
|
||||||
- /etc/ansible/roles/wazuh-ansible/roles/wazuh/ansible-wazuh-agent
|
- ../roles/wazuh/ansible-wazuh-agent
|
||||||
vars:
|
vars:
|
||||||
wazuh_managers:
|
wazuh_managers:
|
||||||
- address: <your manager IP>
|
- address: <your manager IP>
|
||||||
@ -11,6 +11,7 @@
|
|||||||
api_proto: 'http'
|
api_proto: 'http'
|
||||||
api_user: ansible
|
api_user: ansible
|
||||||
wazuh_agent_authd:
|
wazuh_agent_authd:
|
||||||
|
registration_address: <registration IP>
|
||||||
enable: true
|
enable: true
|
||||||
port: 1515
|
port: 1515
|
||||||
ssl_agent_ca: null
|
ssl_agent_ca: null
|
||||||
|
|||||||
@ -1,4 +1,5 @@
|
|||||||
---
|
---
|
||||||
- hosts: <your elasticsearch host>
|
- hosts: <YOUR_ELASTICSEARCH_IP>
|
||||||
roles:
|
roles:
|
||||||
- {role: /etc/ansible/roles/wazuh-ansible/roles/elastic-stack/ansible-elasticsearch, elasticsearch_network_host: 'your elasticsearch IP'}
|
- role: ../roles/elastic-stack/ansible-elasticsearch
|
||||||
|
elasticsearch_network_host: '<YOUR_ELASTICSEARCH_IP>'
|
||||||
|
|||||||
@ -1,9 +1,91 @@
|
|||||||
---
|
---
|
||||||
- hosts: <your wazuh server host>
|
|
||||||
|
- hosts: <node-1 IP>
|
||||||
roles:
|
roles:
|
||||||
- role: /etc/ansible/roles/wazuh-ansible/roles/wazuh/ansible-wazuh-manager
|
- role: ../roles/elastic-stack/ansible-elasticsearch
|
||||||
- {role: /etc/ansible/roles/wazuh-ansible/roles/wazuh/ansible-filebeat, filebeat_output_logstash_hosts: 'your elastic stack server IP'}
|
elasticsearch_network_host: <node-1 IP>
|
||||||
- hosts: <your elastic stack server host>
|
elasticsearch_node_name: node-1
|
||||||
|
elasticsearch_bootstrap_node: true
|
||||||
|
elasticsearch_cluster_nodes:
|
||||||
|
- <node-1 IP>
|
||||||
|
- <node-2 IP>
|
||||||
|
- <node-3 IP>
|
||||||
|
elasticsearch_discovery_nodes:
|
||||||
|
- <node-1 IP>
|
||||||
|
- <node-2 IP>
|
||||||
|
- <node-3 IP>
|
||||||
|
elasticsearch_xpack_security: true
|
||||||
|
node_certs_generator: true
|
||||||
|
elasticsearch_xpack_security_password: elastic_pass
|
||||||
|
single_node: false
|
||||||
|
|
||||||
|
vars:
|
||||||
|
instances:
|
||||||
|
node1:
|
||||||
|
name: node-1 # Important: must be equal to elasticsearch_node_name.
|
||||||
|
ip: <node-1 IP> # When unzipping, the node will search for its node name folder to get the cert.
|
||||||
|
node2:
|
||||||
|
name: node-2
|
||||||
|
ip: <node-2 IP>
|
||||||
|
node3:
|
||||||
|
name: node-3
|
||||||
|
ip: <node-3 IP>
|
||||||
|
|
||||||
|
- hosts: <node-2 IP>
|
||||||
roles:
|
roles:
|
||||||
- {role: /etc/ansible/roles/wazuh-ansible/roles/elastic-stack/ansible-elasticsearch, elasticsearch_network_host: 'localhost'}
|
- role: ../roles/elastic-stack/ansible-elasticsearch
|
||||||
- {role: /etc/ansible/roles/wazuh-ansible/roles/elastic-stack/ansible-kibana, elasticsearch_network_host: 'localhost'}
|
elasticsearch_network_host: <node-2 IP>
|
||||||
|
elasticsearch_node_name: node-2
|
||||||
|
single_node: false
|
||||||
|
elasticsearch_xpack_security: true
|
||||||
|
elasticsearch_master_candidate: true
|
||||||
|
elasticsearch_discovery_nodes:
|
||||||
|
- <node-1 IP>
|
||||||
|
- <node-2 IP>
|
||||||
|
- <node-3 IP>
|
||||||
|
|
||||||
|
- hosts: <node-3 IP>
|
||||||
|
roles:
|
||||||
|
- role: ../roles/elastic-stack/ansible-elasticsearch
|
||||||
|
elasticsearch_network_host: <node-3 IP>
|
||||||
|
elasticsearch_node_name: node-3
|
||||||
|
single_node: false
|
||||||
|
elasticsearch_xpack_security: true
|
||||||
|
elasticsearch_master_candidate: true
|
||||||
|
elasticsearch_discovery_nodes:
|
||||||
|
- <node-1 IP>
|
||||||
|
- <node-2 IP>
|
||||||
|
- <node-3 IP>
|
||||||
|
|
||||||
|
|
||||||
|
# - hosts: 172.16.0.162
|
||||||
|
# roles:
|
||||||
|
# - role: ../roles/wazuh/ansible-wazuh-manager
|
||||||
|
|
||||||
|
# - role: ../roles/wazuh/ansible-filebeat
|
||||||
|
# filebeat_output_elasticsearch_hosts: 172.16.0.161:9200
|
||||||
|
# filebeat_xpack_security: true
|
||||||
|
# filebeat_node_name: node-2
|
||||||
|
# node_certs_generator: false
|
||||||
|
# elasticsearch_xpack_security_password: elastic_pass
|
||||||
|
|
||||||
|
# - role: ../roles/elastic-stack/ansible-elasticsearch
|
||||||
|
# elasticsearch_network_host: 172.16.0.162
|
||||||
|
# node_name: node-2
|
||||||
|
# elasticsearch_bootstrap_node: false
|
||||||
|
# elasticsearch_master_candidate: true
|
||||||
|
# elasticsearch_discovery_nodes:
|
||||||
|
# - 172.16.0.161
|
||||||
|
# - 172.16.0.162
|
||||||
|
# elasticsearch_xpack_security: true
|
||||||
|
# node_certs_generator: false
|
||||||
|
|
||||||
|
|
||||||
|
# - hosts: 172.16.0.163
|
||||||
|
# roles:
|
||||||
|
# - role: ../roles/elastic-stack/ansible-kibana
|
||||||
|
# kibana_xpack_security: true
|
||||||
|
# kibana_node_name: node-3
|
||||||
|
# elasticsearch_network_host: 172.16.0.161
|
||||||
|
# node_certs_generator: false
|
||||||
|
# elasticsearch_xpack_security_password: elastic_pass
|
||||||
|
|||||||
@ -1,6 +1,8 @@
|
|||||||
---
|
---
|
||||||
- hosts: <your server host>
|
- hosts: <your server host>
|
||||||
roles:
|
roles:
|
||||||
- {role: ../roles/wazuh/ansible-wazuh-manager}
|
- {role: ../roles/wazuh/ansible-wazuh-manager}
|
||||||
- {role: ../roles/elastic-stack/ansible-elasticsearch, elasticsearch_network_host: '0.0.0.0', single_node: true}
|
- role: ../roles/wazuh/ansible-filebeat
|
||||||
- { role: ../roles/elastic-stack/ansible-kibana, elasticsearch_network_host: 'localhost' }
|
filebeat_output_elasticsearch_hosts: localhost:9200
|
||||||
|
- {role: ../roles/elastic-stack/ansible-elasticsearch, elasticsearch_network_host: '0.0.0.0', single_node: true}
|
||||||
|
- { role: ../roles/elastic-stack/ansible-kibana, elasticsearch_network_host: '0.0.0.0', elasticsearch_reachable_host: 'localhost' }
|
||||||
@ -1,4 +1,6 @@
|
|||||||
---
|
---
|
||||||
- hosts: <your kibana host>
|
- hosts: <KIBANA_HOST>
|
||||||
roles:
|
roles:
|
||||||
- {role: /etc/ansible/roles/wazuh-ansible/roles/elastic-stack/ansible-kibana, elasticsearch_network_host: 'your elasticsearch IP'}
|
- role: ../roles/elastic-stack/ansible-kibana
|
||||||
|
elasticsearch_network_host: <YOUR_ELASTICSEARCH_IP>
|
||||||
|
|
||||||
|
|||||||
@ -1,5 +1,8 @@
|
|||||||
---
|
---
|
||||||
- hosts: <your wazuh server host>
|
- hosts: <WAZUH_MANAGER_HOST>
|
||||||
roles:
|
roles:
|
||||||
- role: /etc/ansible/roles/wazuh-ansible/roles/wazuh/ansible-wazuh-manager
|
- role: ../roles/wazuh/ansible-wazuh-manager
|
||||||
- {role: /etc/ansible/roles/wazuh-ansible/roles/wazuh/ansible-filebeat, filebeat_output_elasticsearch_hosts: 'your elasticsearch IP'}
|
- role: ../roles/wazuh/ansible-filebeat
|
||||||
|
filebeat_output_elasticsearch_hosts: <YOUR_ELASTICSEARCH_IP>:9200
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@ -12,6 +12,8 @@ This role will work on:
|
|||||||
* Fedora
|
* Fedora
|
||||||
* Debian
|
* Debian
|
||||||
* Ubuntu
|
* Ubuntu
|
||||||
|
|
||||||
|
For the elasticsearch role with XPack security the `unzip` command must be available on the Ansible master.
|
||||||
|
|
||||||
Role Variables
|
Role Variables
|
||||||
--------------
|
--------------
|
||||||
@ -46,13 +48,89 @@ Example Playbook
|
|||||||
|
|
||||||
- hosts: 172.16.0.162
|
- hosts: 172.16.0.162
|
||||||
roles:
|
roles:
|
||||||
- {role: ../roles/elastic-stack/ansible-elasticsearch, elasticsearch_network_host: '172.16.0.162', elasticsearch_master_candidate: true, elasticsearch_cluster_nodes: ['172.16.0.162','172.16.0.163','172.16.0.161']}
|
- {role: ../roles/elastic-stack/ansible-elasticsearch, elasticsearch_network_host: '172.16.0.162', elasticsearch_node_master: true, elasticsearch_cluster_nodes: ['172.16.0.162','172.16.0.163','172.16.0.161']}
|
||||||
|
|
||||||
- hosts: 172.16.0.163
|
- hosts: 172.16.0.163
|
||||||
roles:
|
roles:
|
||||||
- {role: ../roles/elastic-stack/ansible-elasticsearch, elasticsearch_network_host: '172.16.0.163', elasticsearch_master_candidate: true, elasticsearch_cluster_nodes: ['172.16.0.162','172.16.0.163','172.16.0.161']}
|
- {role: ../roles/elastic-stack/ansible-elasticsearch, elasticsearch_network_host: '172.16.0.163', elasticsearch_node_master: true, elasticsearch_cluster_nodes: ['172.16.0.162','172.16.0.163','172.16.0.161']}
|
||||||
```
|
```
|
||||||
|
|
||||||
|
- Three nodes Elasticsearch cluster with XPack security
|
||||||
|
```
|
||||||
|
---
|
||||||
|
- hosts: elastic-1
|
||||||
|
roles:
|
||||||
|
- role: ../roles/elastic-stack/ansible-elasticsearch
|
||||||
|
elasticsearch_network_host: 172.16.0.111
|
||||||
|
elasticsearch_node_name: node-1
|
||||||
|
single_node: false
|
||||||
|
elasticsearch_node_master: true
|
||||||
|
elasticsearch_bootstrap_node: true
|
||||||
|
elasticsearch_cluster_nodes:
|
||||||
|
- 172.16.0.111
|
||||||
|
- 172.16.0.112
|
||||||
|
- 172.16.0.113
|
||||||
|
elasticsearch_discovery_nodes:
|
||||||
|
- 172.16.0.111
|
||||||
|
- 172.16.0.112
|
||||||
|
- 172.16.0.113
|
||||||
|
elasticsearch_xpack_security: true
|
||||||
|
node_certs_generator: true
|
||||||
|
node_certs_generator_ip: 172.16.0.111
|
||||||
|
|
||||||
|
vars:
|
||||||
|
instances:
|
||||||
|
node-1:
|
||||||
|
name: node-1
|
||||||
|
ip: 172.16.0.111
|
||||||
|
node-2:
|
||||||
|
name: node-2
|
||||||
|
ip: 172.16.0.112
|
||||||
|
node-3:
|
||||||
|
name: node-3
|
||||||
|
ip: 172.16.0.113
|
||||||
|
|
||||||
|
- hosts: elastic-2
|
||||||
|
roles:
|
||||||
|
- role: ../roles/elastic-stack/ansible-elasticsearch
|
||||||
|
elasticsearch_network_host: 172.16.0.112
|
||||||
|
elasticsearch_node_name: node-2
|
||||||
|
single_node: false
|
||||||
|
elasticsearch_xpack_security: true
|
||||||
|
elasticsearch_node_master: true
|
||||||
|
node_certs_generator_ip: 172.16.0.111
|
||||||
|
elasticsearch_discovery_nodes:
|
||||||
|
- 172.16.0.111
|
||||||
|
- 172.16.0.112
|
||||||
|
- 172.16.0.113
|
||||||
|
|
||||||
|
- hosts: elastic-3
|
||||||
|
roles:
|
||||||
|
- role: ../roles/elastic-stack/ansible-elasticsearch
|
||||||
|
elasticsearch_network_host: 172.16.0.113
|
||||||
|
elasticsearch_node_name: node-3
|
||||||
|
single_node: false
|
||||||
|
elasticsearch_xpack_security: true
|
||||||
|
elasticsearch_node_master: true
|
||||||
|
node_certs_generator_ip: 172.16.0.111
|
||||||
|
elasticsearch_discovery_nodes:
|
||||||
|
- 172.16.0.111
|
||||||
|
- 172.16.0.112
|
||||||
|
- 172.16.0.113
|
||||||
|
vars:
|
||||||
|
elasticsearch_xpack_users:
|
||||||
|
anne:
|
||||||
|
password: 'PasswordHere'
|
||||||
|
roles: '["kibana_user", "monitoring_user"]'
|
||||||
|
jack:
|
||||||
|
password: 'PasswordHere'
|
||||||
|
roles: '["superuser"]'
|
||||||
|
|
||||||
|
```
|
||||||
|
|
||||||
|
It is possible to define users directly on the playbook, these must be defined on a variable `elasticsearch_xpack_users` on the last node of the cluster as in the example.
|
||||||
|
|
||||||
|
|
||||||
License and copyright
|
License and copyright
|
||||||
---------------------
|
---------------------
|
||||||
|
|
||||||
|
|||||||
@ -1,12 +1,43 @@
|
|||||||
---
|
---
|
||||||
elasticsearch_cluster_name: wazuh
|
|
||||||
elasticsearch_node_name: node-1
|
|
||||||
elasticsearch_http_port: 9200
|
elasticsearch_http_port: 9200
|
||||||
elasticsearch_network_host: 127.0.0.1
|
elasticsearch_network_host: 127.0.0.1
|
||||||
|
elasticsearch_reachable_host: 127.0.0.1
|
||||||
elasticsearch_jvm_xms: null
|
elasticsearch_jvm_xms: null
|
||||||
elastic_stack_version: 7.1.1
|
elastic_stack_version: 7.6.1
|
||||||
single_node: false
|
elasticsearch_lower_disk_requirements: false
|
||||||
|
|
||||||
|
elasticrepo:
|
||||||
|
apt: 'https://artifacts.elastic.co/packages/7.x/apt'
|
||||||
|
yum: 'https://artifacts.elastic.co/packages/7.x/yum'
|
||||||
|
gpg: 'https://artifacts.elastic.co/GPG-KEY-elasticsearch'
|
||||||
|
key_id: '46095ACC8548582C1A2699A9D27D666CD88E42B4'
|
||||||
|
|
||||||
|
# Cluster Settings
|
||||||
|
single_node: true
|
||||||
|
elasticsearch_cluster_name: wazuh
|
||||||
|
elasticsearch_node_name: node-1
|
||||||
elasticsearch_bootstrap_node: false
|
elasticsearch_bootstrap_node: false
|
||||||
elasticsearch_master_candidate: false
|
elasticsearch_node_master: false
|
||||||
elasticsearch_cluster_nodes:
|
elasticsearch_cluster_nodes:
|
||||||
- 127.0.0.1
|
- 127.0.0.1
|
||||||
|
elasticsearch_discovery_nodes:
|
||||||
|
- 127.0.0.1
|
||||||
|
elasticsearch_node_data: true
|
||||||
|
elasticsearch_node_ingest: true
|
||||||
|
|
||||||
|
# X-Pack Security
|
||||||
|
elasticsearch_xpack_security: false
|
||||||
|
elasticsearch_xpack_security_user: elastic
|
||||||
|
elasticsearch_xpack_security_password: elastic_pass
|
||||||
|
|
||||||
|
node_certs_generator: false
|
||||||
|
node_certs_source: /usr/share/elasticsearch
|
||||||
|
node_certs_destination: /etc/elasticsearch/certs
|
||||||
|
|
||||||
|
# CA generation
|
||||||
|
master_certs_path: /es_certs
|
||||||
|
generate_CA: true
|
||||||
|
ca_key_name: ""
|
||||||
|
ca_cert_name: ""
|
||||||
|
ca_password: ""
|
||||||
|
|||||||
@ -1,24 +1,52 @@
|
|||||||
---
|
---
|
||||||
- name: Debian/Ubuntu | Install apt-transport-https and ca-certificates
|
- name: Debian/Ubuntu | Install apt-transport-https and ca-certificates
|
||||||
apt:
|
apt:
|
||||||
name: ['apt-transport-https', 'ca-certificates']
|
name:
|
||||||
|
- apt-transport-https
|
||||||
|
- ca-certificates
|
||||||
state: present
|
state: present
|
||||||
|
register: elasticsearch_ca_packages_installed
|
||||||
|
until: elasticsearch_ca_packages_installed is succeeded
|
||||||
|
|
||||||
|
- name: Update and upgrade apt packages
|
||||||
|
become: true
|
||||||
|
apt:
|
||||||
|
upgrade: yes
|
||||||
|
update_cache: yes
|
||||||
|
cache_valid_time: 86400 #One day
|
||||||
|
when:
|
||||||
|
- ansible_distribution == "Ubuntu"
|
||||||
|
- ansible_distribution_major_version | int == 14
|
||||||
|
|
||||||
|
- name: Update and upgrade apt packages
|
||||||
|
become: true
|
||||||
|
apt:
|
||||||
|
upgrade: yes
|
||||||
|
update_cache: yes
|
||||||
|
cache_valid_time: 86400 #One day
|
||||||
|
when:
|
||||||
|
- ansible_distribution == "Ubuntu"
|
||||||
|
- ansible_distribution_major_version | int == 14
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Add Elasticsearch GPG key.
|
- name: Debian/Ubuntu | Add Elasticsearch GPG key.
|
||||||
apt_key:
|
apt_key:
|
||||||
url: "https://artifacts.elastic.co/GPG-KEY-elasticsearch"
|
url: "{{ elasticrepo.gpg }}"
|
||||||
|
id: "{{ elasticrepo.key_id }}"
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Install Elastic repo
|
- name: Debian/Ubuntu | Install Elastic repo
|
||||||
apt_repository:
|
apt_repository:
|
||||||
repo: 'deb https://artifacts.elastic.co/packages/7.x/apt stable main'
|
repo: "deb {{ elasticrepo.apt }} stable main"
|
||||||
state: present
|
state: present
|
||||||
filename: 'elastic_repo'
|
filename: 'elastic_repo_7'
|
||||||
update_cache: true
|
update_cache: true
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Install Elasticsarch
|
- name: Debian/Ubuntu | Install Elasticsarch
|
||||||
apt:
|
apt:
|
||||||
name: "elasticsearch={{ elastic_stack_version }}"
|
name: "elasticsearch={{ elastic_stack_version }}"
|
||||||
state: present
|
state: present
|
||||||
cache_valid_time: 3600
|
cache_valid_time: 3600
|
||||||
|
register: elasticsearch_main_packages_installed
|
||||||
|
until: elasticsearch_main_packages_installed is succeeded
|
||||||
tags: install
|
tags: install
|
||||||
|
|||||||
@ -1,5 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: Debian/Ubuntu | Removing Elasticsearch repository
|
- name: Debian/Ubuntu | Removing Elasticsearch repository
|
||||||
apt_repository:
|
apt_repository:
|
||||||
repo: deb https://artifacts.elastic.co/packages/7.x/apt stable main
|
repo: "deb {{ elasticrepo.apt }} stable main"
|
||||||
state: absent
|
state: absent
|
||||||
|
changed_when: false
|
||||||
|
|||||||
@ -1,5 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: RedHat/CentOS/Fedora | Remove Elasticsearch repository (and clean up left-over metadata)
|
- name: RedHat/CentOS/Fedora | Remove Elasticsearch repository (and clean up left-over metadata)
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: elastic_repo
|
name: elastic_repo_7
|
||||||
state: absent
|
state: absent
|
||||||
|
changed_when: false
|
||||||
|
|||||||
@ -2,11 +2,12 @@
|
|||||||
|
|
||||||
- name: RedHat/CentOS/Fedora | Install Elastic repo
|
- name: RedHat/CentOS/Fedora | Install Elastic repo
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: elastic_repo
|
name: elastic_repo_7
|
||||||
description: Elastic repository for 7.x packages
|
description: Elastic repository for 7.x packages
|
||||||
baseurl: https://artifacts.elastic.co/packages/7.x/yum
|
baseurl: "{{ elasticrepo.yum }}"
|
||||||
gpgkey: https://artifacts.elastic.co/GPG-KEY-elasticsearch
|
gpgkey: "{{ elasticrepo.gpg }}"
|
||||||
gpgcheck: true
|
gpgcheck: true
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
- name: RedHat/CentOS/Fedora | Install Elasticsarch
|
- name: RedHat/CentOS/Fedora | Install Elasticsarch
|
||||||
package: name=elasticsearch-{{ elastic_stack_version }} state=present
|
package: name=elasticsearch-{{ elastic_stack_version }} state=present
|
||||||
|
|||||||
@ -48,16 +48,6 @@
|
|||||||
- ansible_service_mgr != "systemd"
|
- ansible_service_mgr != "systemd"
|
||||||
- ansible_os_family == "RedHat"
|
- ansible_os_family == "RedHat"
|
||||||
|
|
||||||
- name: Configure Elasticsearch.
|
|
||||||
template:
|
|
||||||
src: elasticsearch.yml.j2
|
|
||||||
dest: /etc/elasticsearch/elasticsearch.yml
|
|
||||||
owner: root
|
|
||||||
group: elasticsearch
|
|
||||||
mode: 0660
|
|
||||||
notify: restart elasticsearch
|
|
||||||
tags: configure
|
|
||||||
|
|
||||||
- name: Configure Elasticsearch JVM memmory.
|
- name: Configure Elasticsearch JVM memmory.
|
||||||
template:
|
template:
|
||||||
src: jvm.options.j2
|
src: jvm.options.j2
|
||||||
@ -69,51 +59,94 @@
|
|||||||
tags: configure
|
tags: configure
|
||||||
|
|
||||||
# fix in new PR (ignore_errors)
|
# fix in new PR (ignore_errors)
|
||||||
- name: Reload systemd
|
|
||||||
systemd: daemon_reload=true
|
- import_tasks: "RMRedHat.yml"
|
||||||
ignore_errors: true
|
when: ansible_os_family == "RedHat"
|
||||||
|
|
||||||
|
- import_tasks: "xpack_security.yml"
|
||||||
when:
|
when:
|
||||||
- not (ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA")
|
- elasticsearch_xpack_security
|
||||||
- not (ansible_distribution == "Ubuntu" and ansible_distribution_version is version('15.04', '<'))
|
|
||||||
- not (ansible_distribution == "Debian" and ansible_distribution_version is version('8', '<'))
|
- name: Configure Elasticsearch.
|
||||||
|
template:
|
||||||
|
src: elasticsearch.yml.j2
|
||||||
|
dest: /etc/elasticsearch/elasticsearch.yml
|
||||||
|
owner: root
|
||||||
|
group: elasticsearch
|
||||||
|
mode: 0660
|
||||||
|
notify: restart elasticsearch
|
||||||
|
tags: configure
|
||||||
|
|
||||||
|
- name: Trusty | set MAX_LOCKED_MEMORY=unlimited in Elasticsearch in /etc/security/limits.conf
|
||||||
|
lineinfile:
|
||||||
|
path: /etc/security/limits.conf
|
||||||
|
line: elasticsearch - memlock unlimited
|
||||||
|
create: yes
|
||||||
|
become: true
|
||||||
|
when:
|
||||||
|
- ansible_distribution == "Ubuntu"
|
||||||
|
- ansible_distribution_major_version | int == 14
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Trusty | set MAX_LOCKED_MEMORY=unlimited in Elasticsearch in /etc/security/limits.d/elasticsearch.conf
|
||||||
|
lineinfile:
|
||||||
|
path: /etc/security/limits.d/elasticsearch.conf
|
||||||
|
line: elasticsearch - memlock unlimited
|
||||||
|
create: yes
|
||||||
|
become: true
|
||||||
|
changed_when: false
|
||||||
|
when:
|
||||||
|
- ansible_distribution == "Ubuntu"
|
||||||
|
- ansible_distribution_major_version | int == 14
|
||||||
|
|
||||||
- name: Ensure Elasticsearch started and enabled
|
- name: Ensure Elasticsearch started and enabled
|
||||||
ignore_errors: true
|
|
||||||
service:
|
service:
|
||||||
name: elasticsearch
|
name: elasticsearch
|
||||||
enabled: true
|
enabled: true
|
||||||
state: started
|
state: started
|
||||||
|
|
||||||
- name: Make sure Elasticsearch is running before proceeding
|
|
||||||
wait_for: host={{ elasticsearch_network_host }} port={{ elasticsearch_http_port }} delay=3 timeout=300
|
|
||||||
tags:
|
tags:
|
||||||
- configure
|
- configure
|
||||||
- init
|
- init
|
||||||
|
|
||||||
- name: Check for Wazuh Alerts template
|
- name: Make sure Elasticsearch is running before proceeding
|
||||||
uri:
|
wait_for: host={{ elasticsearch_reachable_host }} port={{ elasticsearch_http_port }} delay=3 timeout=400
|
||||||
url: "http://{{elasticsearch_network_host}}:{{elasticsearch_http_port}}/_template/wazuh"
|
tags:
|
||||||
method: GET
|
- configure
|
||||||
status_code: 200, 404
|
- init
|
||||||
when: not elasticsearch_bootstrap_node or single_node
|
|
||||||
poll: 30
|
|
||||||
register: wazuh_alerts_template_exits
|
|
||||||
tags: init
|
|
||||||
|
|
||||||
- name: Installing Wazuh Alerts template
|
|
||||||
uri:
|
|
||||||
url: "http://{{elasticsearch_network_host}}:{{elasticsearch_http_port}}/_template/wazuh"
|
|
||||||
method: PUT
|
|
||||||
status_code: 200
|
|
||||||
body_format: json
|
|
||||||
body: "{{ lookup('template','wazuh-elastic7-template-alerts.json.j2') }}"
|
|
||||||
when:
|
|
||||||
- wazuh_alerts_template_exits.status is defined
|
|
||||||
- wazuh_alerts_template_exits.status != 200
|
|
||||||
tags: init
|
|
||||||
|
|
||||||
- import_tasks: "RMRedHat.yml"
|
- import_tasks: "RMRedHat.yml"
|
||||||
when: ansible_os_family == "RedHat"
|
when: ansible_os_family == "RedHat"
|
||||||
|
|
||||||
- import_tasks: "RMDebian.yml"
|
- import_tasks: "RMDebian.yml"
|
||||||
when: ansible_os_family == "Debian"
|
when: ansible_os_family == "Debian"
|
||||||
|
|
||||||
|
- name: Wait for Elasticsearch API
|
||||||
|
uri:
|
||||||
|
url: "https://{{ node_certs_generator_ip }}:{{ elasticsearch_http_port }}/_cluster/health/"
|
||||||
|
user: "elastic" # Default Elasticsearch user is always "elastic"
|
||||||
|
password: "{{ elasticsearch_xpack_security_password }}"
|
||||||
|
validate_certs: no
|
||||||
|
status_code: 200,401
|
||||||
|
return_content: yes
|
||||||
|
timeout: 4
|
||||||
|
register: _result
|
||||||
|
until: ( _result.json is defined) and (_result.json.status == "green")
|
||||||
|
retries: 24
|
||||||
|
delay: 5
|
||||||
|
when:
|
||||||
|
- elasticsearch_xpack_users is defined
|
||||||
|
|
||||||
|
- name: Create elasticsearch users
|
||||||
|
uri:
|
||||||
|
url: "https://{{ node_certs_generator_ip }}:{{ elasticsearch_http_port }}/_security/user/{{ item.key }}"
|
||||||
|
method: POST
|
||||||
|
body_format: json
|
||||||
|
user: "elastic"
|
||||||
|
password: "{{ elasticsearch_xpack_security_password }}"
|
||||||
|
body: '{ "password" : "{{ item.value["password"] }}", "roles" : {{ item.value["roles"] }} }'
|
||||||
|
validate_certs: no
|
||||||
|
loop: "{{ elasticsearch_xpack_users|default({})|dict2items }}"
|
||||||
|
register: http_response
|
||||||
|
failed_when: http_response.status != 200
|
||||||
|
when:
|
||||||
|
- elasticsearch_xpack_users is defined
|
||||||
|
|||||||
@ -0,0 +1,197 @@
|
|||||||
|
|
||||||
|
- name: Check if certificate exists locally
|
||||||
|
stat:
|
||||||
|
path: "{{ node_certs_destination }}/{{ elasticsearch_node_name }}.crt"
|
||||||
|
register: certificate_file_exists
|
||||||
|
|
||||||
|
- name: Write the instances.yml file in the selected node (force = no)
|
||||||
|
template:
|
||||||
|
src: instances.yml.j2
|
||||||
|
dest: "{{ node_certs_source }}/instances.yml"
|
||||||
|
force: no
|
||||||
|
register: instances_file_exists
|
||||||
|
tags:
|
||||||
|
- config
|
||||||
|
- xpack-security
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
- not certificate_file_exists.stat.exists
|
||||||
|
|
||||||
|
- name: Update instances.yml status after generation
|
||||||
|
stat:
|
||||||
|
path: "{{ node_certs_source }}/instances.yml"
|
||||||
|
register: instances_file_exists
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
|
||||||
|
- name: Check if the certificates ZIP file exists
|
||||||
|
stat:
|
||||||
|
path: "{{ node_certs_source }}/certs.zip"
|
||||||
|
register: xpack_certs_zip
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
|
||||||
|
- name: Importing custom CA key
|
||||||
|
copy:
|
||||||
|
src: "{{ master_certs_path }}/ca/{{ ca_key_name }}"
|
||||||
|
dest: "{{ node_certs_source }}/{{ ca_key_name }}"
|
||||||
|
mode: 0440
|
||||||
|
when:
|
||||||
|
- not generate_CA
|
||||||
|
- node_certs_generator
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
|
- name: Importing custom CA cert
|
||||||
|
copy:
|
||||||
|
src: "{{ master_certs_path }}/ca/{{ ca_cert_name }}"
|
||||||
|
dest: "{{ node_certs_source }}/{{ ca_cert_name }}"
|
||||||
|
mode: 0440
|
||||||
|
when:
|
||||||
|
- not generate_CA
|
||||||
|
- node_certs_generator
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
|
- name: Generating certificates for Elasticsearch security (generating CA)
|
||||||
|
command: >-
|
||||||
|
/usr/share/elasticsearch/bin/elasticsearch-certutil cert ca --pem
|
||||||
|
--in {{ node_certs_source }}/instances.yml
|
||||||
|
--out {{ node_certs_source }}/certs.zip
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
- not xpack_certs_zip.stat.exists
|
||||||
|
- generate_CA
|
||||||
|
tags:
|
||||||
|
- xpack-security
|
||||||
|
- molecule-idempotence-notest
|
||||||
|
|
||||||
|
- name: Generating certificates for Elasticsearch security (using provided CA | Without CA Password)
|
||||||
|
command: >-
|
||||||
|
/usr/share/elasticsearch/bin/elasticsearch-certutil cert
|
||||||
|
--ca-key {{ node_certs_source }}/{{ ca_key_name }}
|
||||||
|
--ca-cert {{ node_certs_source }}/{{ ca_cert_name }}
|
||||||
|
--pem --in {{ node_certs_source }}/instances.yml
|
||||||
|
--out {{ node_certs_source }}/certs.zip
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
- not xpack_certs_zip.stat.exists
|
||||||
|
- not generate_CA
|
||||||
|
- ca_password | length == 0
|
||||||
|
tags:
|
||||||
|
- xpack-security
|
||||||
|
- molecule-idempotence-notest
|
||||||
|
|
||||||
|
- name: Generating certificates for Elasticsearch security (using provided CA | Using CA Password)
|
||||||
|
command: >-
|
||||||
|
/usr/share/elasticsearch/bin/elasticsearch-certutil cert
|
||||||
|
--ca-key {{ node_certs_source }}/{{ ca_key_name }}
|
||||||
|
--ca-cert {{ node_certs_source }}/{{ ca_cert_name }}
|
||||||
|
--pem --in {{ node_certs_source }}/instances.yml --out {{ node_certs_source }}/certs.zip
|
||||||
|
--ca-pass {{ ca_password }}
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
- not xpack_certs_zip.stat.exists
|
||||||
|
- not generate_CA
|
||||||
|
- ca_password | length > 0
|
||||||
|
tags:
|
||||||
|
- xpack-security
|
||||||
|
- molecule-idempotence-notest
|
||||||
|
|
||||||
|
- name: Verify the Elastic certificates directory
|
||||||
|
file:
|
||||||
|
path: "{{ master_certs_path }}"
|
||||||
|
state: directory
|
||||||
|
mode: 0700
|
||||||
|
delegate_to: "127.0.0.1"
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
|
||||||
|
- name: Verify the Certificates Authority directory
|
||||||
|
file:
|
||||||
|
path: "{{ master_certs_path }}/ca/"
|
||||||
|
state: directory
|
||||||
|
mode: 0700
|
||||||
|
delegate_to: "127.0.0.1"
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
|
||||||
|
- name: Copying certificates to Ansible master
|
||||||
|
fetch:
|
||||||
|
src: "{{ node_certs_source }}/certs.zip"
|
||||||
|
dest: "{{ master_certs_path }}/"
|
||||||
|
flat: yes
|
||||||
|
mode: 0700
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
tags:
|
||||||
|
- xpack-security
|
||||||
|
- molecule-idempotence-notest
|
||||||
|
|
||||||
|
- name: Delete certs.zip in Generator node
|
||||||
|
file:
|
||||||
|
state: absent
|
||||||
|
path: "{{ node_certs_source }}/certs.zip"
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
tags: molecule-idempotence-notest
|
||||||
|
|
||||||
|
- name: Unzip generated certs.zip
|
||||||
|
unarchive:
|
||||||
|
src: "{{ master_certs_path }}/certs.zip"
|
||||||
|
dest: "{{ master_certs_path }}/"
|
||||||
|
delegate_to: "127.0.0.1"
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
tags:
|
||||||
|
- xpack-security
|
||||||
|
- molecule-idempotence-notest
|
||||||
|
|
||||||
|
- name: Copying node's certificate from master
|
||||||
|
copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0440
|
||||||
|
with_items:
|
||||||
|
- "{{ master_certs_path }}/{{ elasticsearch_node_name }}/{{ elasticsearch_node_name }}.key"
|
||||||
|
- "{{ master_certs_path }}/{{ elasticsearch_node_name }}/{{ elasticsearch_node_name }}.crt"
|
||||||
|
- "{{ master_certs_path }}/ca/ca.crt"
|
||||||
|
when:
|
||||||
|
- generate_CA
|
||||||
|
tags:
|
||||||
|
- xpack-security
|
||||||
|
- molecule-idempotence-notest
|
||||||
|
|
||||||
|
- name: Copying node's certificate from master (Custom CA)
|
||||||
|
copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0440
|
||||||
|
with_items:
|
||||||
|
- "{{ master_certs_path }}/{{ elasticsearch_node_name }}/{{ elasticsearch_node_name }}.key"
|
||||||
|
- "{{ master_certs_path }}/{{ elasticsearch_node_name }}/{{ elasticsearch_node_name }}.crt"
|
||||||
|
- "{{ master_certs_path }}/ca/{{ ca_cert_name }}"
|
||||||
|
when:
|
||||||
|
- not generate_CA
|
||||||
|
tags:
|
||||||
|
- xpack-security
|
||||||
|
- molecule-idempotence-notest
|
||||||
|
|
||||||
|
- name: Ensuring folder permissions
|
||||||
|
file:
|
||||||
|
path: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0774
|
||||||
|
state: directory
|
||||||
|
recurse: yes
|
||||||
|
when:
|
||||||
|
- elasticsearch_xpack_security
|
||||||
|
- generate_CA
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
|
- name: Set elasticsearch bootstrap password
|
||||||
|
shell: |
|
||||||
|
set -o pipefail
|
||||||
|
echo {{ elasticsearch_xpack_security_password }} | {{ node_certs_source }}/bin/elasticsearch-keystore add -xf bootstrap.password
|
||||||
|
args:
|
||||||
|
executable: /bin/bash
|
||||||
|
when:
|
||||||
|
- node_certs_generator
|
||||||
|
tags: molecule-idempotence-notest
|
||||||
@ -15,10 +15,50 @@ cluster.initial_master_nodes:
|
|||||||
{% for item in elasticsearch_cluster_nodes %}
|
{% for item in elasticsearch_cluster_nodes %}
|
||||||
- {{ item }}
|
- {{ item }}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% elif elasticsearch_master_candidate %}
|
|
||||||
node.master: true
|
|
||||||
discovery.seed_hosts:
|
discovery.seed_hosts:
|
||||||
{% for item in elasticsearch_cluster_nodes %}
|
{% for item in elasticsearch_discovery_nodes %}
|
||||||
|
- {{ item }}
|
||||||
|
{% endfor %}
|
||||||
|
{% else %}
|
||||||
|
node.master: {{ elasticsearch_node_master|lower }}
|
||||||
|
{% if elasticsearch_node_data|lower == 'false' %}
|
||||||
|
node.data: false
|
||||||
|
{% endif %}
|
||||||
|
{% if elasticsearch_node_ingest|lower == 'false' %}
|
||||||
|
node.ingest: false
|
||||||
|
{% endif %}
|
||||||
|
discovery.seed_hosts:
|
||||||
|
{% for item in elasticsearch_discovery_nodes %}
|
||||||
- {{ item }}
|
- {{ item }}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
|
{% if elasticsearch_lower_disk_requirements %}
|
||||||
|
cluster.routing.allocation.disk.threshold_enabled: true
|
||||||
|
cluster.routing.allocation.disk.watermark.flood_stage: 200mb
|
||||||
|
cluster.routing.allocation.disk.watermark.low: 500mb
|
||||||
|
cluster.routing.allocation.disk.watermark.high: 300mb
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
{% if elasticsearch_xpack_security %}
|
||||||
|
# XPACK Security
|
||||||
|
xpack.security.enabled: true
|
||||||
|
xpack.security.transport.ssl.enabled: true
|
||||||
|
xpack.security.transport.ssl.verification_mode: certificate
|
||||||
|
xpack.security.transport.ssl.key: {{node_certs_destination}}/{{ elasticsearch_node_name }}.key
|
||||||
|
xpack.security.transport.ssl.certificate: {{node_certs_destination}}/{{ elasticsearch_node_name }}.crt
|
||||||
|
{% if generate_CA == true %}
|
||||||
|
xpack.security.transport.ssl.certificate_authorities: [ "{{ node_certs_destination }}/ca.crt" ]
|
||||||
|
{% elif generate_CA == false %}
|
||||||
|
xpack.security.transport.ssl.certificate_authorities: [ "{{ node_certs_destination }}/{{ca_cert_name}}" ]
|
||||||
|
{% endif %}
|
||||||
|
xpack.security.http.ssl.enabled: true
|
||||||
|
xpack.security.http.ssl.verification_mode: certificate
|
||||||
|
xpack.security.http.ssl.key: {{node_certs_destination}}/{{ elasticsearch_node_name }}.key
|
||||||
|
xpack.security.http.ssl.certificate: {{node_certs_destination}}/{{ elasticsearch_node_name }}.crt
|
||||||
|
{% if generate_CA == true %}
|
||||||
|
xpack.security.http.ssl.certificate_authorities: [ "{{ node_certs_destination }}/ca.crt" ]
|
||||||
|
{% elif generate_CA == false %}
|
||||||
|
xpack.security.http.ssl.certificate_authorities: [ "{{ node_certs_destination }}/{{ca_cert_name}}" ]
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
|
|||||||
@ -0,0 +1,17 @@
|
|||||||
|
|
||||||
|
# {{ ansible_managed }}
|
||||||
|
# TO-DO
|
||||||
|
|
||||||
|
{% if node_certs_generator %}
|
||||||
|
instances:
|
||||||
|
{% for (key,value) in instances.items() %}
|
||||||
|
- name: "{{ value.name }}"
|
||||||
|
{% if value.ip is defined and value.ip | length > 0 %}
|
||||||
|
ip:
|
||||||
|
- "{{ value.ip }}"
|
||||||
|
{% elif value.dns is defined and value.dns | length > 0 %}
|
||||||
|
dns:
|
||||||
|
- "{{ value.dns }}"
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
@ -1,621 +0,0 @@
|
|||||||
{
|
|
||||||
"order": 0,
|
|
||||||
"template": "wazuh-alerts-3.x-*",
|
|
||||||
"settings": {
|
|
||||||
"index.refresh_interval": "5s"
|
|
||||||
},
|
|
||||||
"mappings": {
|
|
||||||
"wazuh": {
|
|
||||||
"dynamic_templates": [
|
|
||||||
{
|
|
||||||
"string_as_keyword": {
|
|
||||||
"match_mapping_type": "string",
|
|
||||||
"mapping": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"properties": {
|
|
||||||
"@timestamp": {
|
|
||||||
"type": "date",
|
|
||||||
"format": "dateOptionalTime"
|
|
||||||
},
|
|
||||||
"@version": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"agent": {
|
|
||||||
"properties": {
|
|
||||||
"ip": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"manager": {
|
|
||||||
"properties": {
|
|
||||||
"name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"cluster": {
|
|
||||||
"properties": {
|
|
||||||
"name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"AlertsFile": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"full_log": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"previous_log": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"GeoLocation": {
|
|
||||||
"properties": {
|
|
||||||
"area_code": {
|
|
||||||
"type": "long"
|
|
||||||
},
|
|
||||||
"city_name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"continent_code": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"coordinates": {
|
|
||||||
"type": "double"
|
|
||||||
},
|
|
||||||
"country_code2": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"country_code3": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"country_name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"dma_code": {
|
|
||||||
"type": "long"
|
|
||||||
},
|
|
||||||
"ip": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"latitude": {
|
|
||||||
"type": "double"
|
|
||||||
},
|
|
||||||
"location": {
|
|
||||||
"type": "geo_point"
|
|
||||||
},
|
|
||||||
"longitude": {
|
|
||||||
"type": "double"
|
|
||||||
},
|
|
||||||
"postal_code": {
|
|
||||||
"type": "keyword"
|
|
||||||
},
|
|
||||||
"real_region_name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"region_name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"timezone": {
|
|
||||||
"type": "text"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"host": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"syscheck": {
|
|
||||||
"properties": {
|
|
||||||
"path": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"sha1_before": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"sha1_after": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"uid_before": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"uid_after": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"gid_before": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"gid_after": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"perm_before": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"perm_after": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"md5_after": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"md5_before": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"gname_after": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"gname_before": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"inode_after": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"inode_before": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"mtime_after": {
|
|
||||||
"type": "date",
|
|
||||||
"format": "dateOptionalTime",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"mtime_before": {
|
|
||||||
"type": "date",
|
|
||||||
"format": "dateOptionalTime",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"uname_after": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"uname_before": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"size_before": {
|
|
||||||
"type": "long",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"size_after": {
|
|
||||||
"type": "long",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"diff": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"event": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"location": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"message": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"offset": {
|
|
||||||
"type": "keyword"
|
|
||||||
},
|
|
||||||
"rule": {
|
|
||||||
"properties": {
|
|
||||||
"description": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"groups": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"level": {
|
|
||||||
"type": "long",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"cve": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"info": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"frequency": {
|
|
||||||
"type": "long",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"firedtimes": {
|
|
||||||
"type": "long",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"cis": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"pci_dss": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"gdpr": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"gpg13": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"decoder": {
|
|
||||||
"properties": {
|
|
||||||
"parent": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"ftscomment": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"fts": {
|
|
||||||
"type": "long",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"accumulate": {
|
|
||||||
"type": "long",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"data": {
|
|
||||||
"properties": {
|
|
||||||
"protocol": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"action": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"srcip": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"dstip": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"srcport": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"dstport": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"srcuser": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"dstuser": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"status": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"data": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"system_name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"url": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"oscap": {
|
|
||||||
"properties": {
|
|
||||||
"check.title": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"check.id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"check.result": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"check.severity": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"check.description": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"check.rationale": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"check.references": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"check.identifiers": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"check.oval.id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"scan.id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"scan.content": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"scan.benchmark.id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"scan.profile.title": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"scan.profile.id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"scan.score": {
|
|
||||||
"type": "double",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"scan.return_code": {
|
|
||||||
"type": "long",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"audit": {
|
|
||||||
"properties": {
|
|
||||||
"type": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"id": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"syscall": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"exit": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"ppid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"pid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"auid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"uid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"gid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"euid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"suid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"fsuid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"egid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"sgid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"fsgid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"tty": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"session": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"command": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"exe": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"key": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"cwd": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"directory.name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"directory.inode": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"directory.mode": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"file.name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"file.inode": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"file.mode": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"acct": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"dev": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"enforcing": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"list": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"old-auid": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"old-ses": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"old_enforcing": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"old_prom": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"op": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"prom": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"res": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"srcip": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"subj": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"success": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"program_name": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"command": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
},
|
|
||||||
"type": {
|
|
||||||
"type": "text"
|
|
||||||
},
|
|
||||||
"title": {
|
|
||||||
"type": "keyword",
|
|
||||||
"doc_values": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@ -1,7 +1,53 @@
|
|||||||
---
|
---
|
||||||
|
kibana_node_name: node-1
|
||||||
|
|
||||||
elasticsearch_http_port: "9200"
|
elasticsearch_http_port: "9200"
|
||||||
elasticsearch_network_host: "127.0.0.1"
|
elasticsearch_network_host: "127.0.0.1"
|
||||||
kibana_server_host: "0.0.0.0"
|
kibana_server_host: "0.0.0.0"
|
||||||
kibana_server_port: "5601"
|
kibana_server_port: "5601"
|
||||||
elastic_stack_version: 7.1.1
|
elastic_stack_version: 7.6.1
|
||||||
wazuh_version: 3.9.2
|
wazuh_version: 3.12.0
|
||||||
|
wazuh_app_url: https://packages.wazuh.com/wazuhapp/wazuhapp
|
||||||
|
|
||||||
|
elasticrepo:
|
||||||
|
apt: 'https://artifacts.elastic.co/packages/7.x/apt'
|
||||||
|
yum: 'https://artifacts.elastic.co/packages/7.x/yum'
|
||||||
|
gpg: 'https://artifacts.elastic.co/GPG-KEY-elasticsearch'
|
||||||
|
key_id: '46095ACC8548582C1A2699A9D27D666CD88E42B4'
|
||||||
|
|
||||||
|
# API credentials
|
||||||
|
wazuh_api_credentials:
|
||||||
|
- id: "default"
|
||||||
|
url: "http://localhost"
|
||||||
|
port: 55000
|
||||||
|
user: "foo"
|
||||||
|
password: "bar"
|
||||||
|
|
||||||
|
# Xpack Security
|
||||||
|
kibana_xpack_security: false
|
||||||
|
|
||||||
|
elasticsearch_xpack_security_user: elastic
|
||||||
|
elasticsearch_xpack_security_password: elastic_pass
|
||||||
|
|
||||||
|
node_certs_generator: false
|
||||||
|
node_certs_source: /usr/share/elasticsearch
|
||||||
|
node_certs_destination: /etc/kibana/certs
|
||||||
|
|
||||||
|
# CA Generation
|
||||||
|
master_certs_path: /es_certs
|
||||||
|
generate_CA: true
|
||||||
|
ca_cert_name: ""
|
||||||
|
|
||||||
|
# Nodejs
|
||||||
|
nodejs:
|
||||||
|
repo_dict:
|
||||||
|
debian: "deb"
|
||||||
|
redhat: "rpm"
|
||||||
|
repo_url_ext: "nodesource.com/setup_10.x"
|
||||||
|
|
||||||
|
# Build from sources
|
||||||
|
build_from_sources: false
|
||||||
|
wazuh_plugin_branch: 3.12-7.6
|
||||||
|
|
||||||
|
#Nodejs NODE_OPTIONS
|
||||||
|
node_options: --max-old-space-size=4096
|
||||||
|
|||||||
@ -1,24 +1,32 @@
|
|||||||
---
|
---
|
||||||
- name: Debian/Ubuntu | Install apt-transport-https and ca-certificates
|
- name: Debian/Ubuntu | Install apt-transport-https and ca-certificates
|
||||||
apt:
|
apt:
|
||||||
name: ['apt-transport-https', 'ca-certificates']
|
name:
|
||||||
|
- apt-transport-https
|
||||||
|
- ca-certificates
|
||||||
state: present
|
state: present
|
||||||
|
register: kibana_installing_ca_package
|
||||||
|
until: kibana_installing_ca_package is succeeded
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Add Elasticsearch GPG key
|
- name: Debian/Ubuntu | Add Elasticsearch GPG key
|
||||||
apt_key:
|
apt_key:
|
||||||
url: "https://artifacts.elastic.co/GPG-KEY-elasticsearch"
|
url: "{{ elasticrepo.gpg }}"
|
||||||
|
id: "{{ elasticrepo.key_id }}"
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Install Elastic repo
|
- name: Debian/Ubuntu | Install Elastic repo
|
||||||
apt_repository:
|
apt_repository:
|
||||||
repo: 'deb https://artifacts.elastic.co/packages/7.x/apt stable main'
|
repo: "deb {{ elasticrepo.apt }} stable main"
|
||||||
state: present
|
state: present
|
||||||
filename: 'elastic_repo'
|
filename: 'elastic_repo_7'
|
||||||
update_cache: true
|
update_cache: true
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Install Kibana
|
- name: Debian/Ubuntu | Install Kibana
|
||||||
apt:
|
apt:
|
||||||
name: "kibana={{ elastic_stack_version }}"
|
name: "kibana={{ elastic_stack_version }}"
|
||||||
state: present
|
state: present
|
||||||
cache_valid_time: 3600
|
cache_valid_time: 3600
|
||||||
|
register: installing_kibana_package
|
||||||
|
until: installing_kibana_package is succeeded
|
||||||
tags: install
|
tags: install
|
||||||
|
|||||||
@ -1,5 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: Debian/Ubuntu | Removing Elasticsearch repository
|
- name: Debian/Ubuntu | Removing Elasticsearch repository
|
||||||
apt_repository:
|
apt_repository:
|
||||||
repo: deb https://artifacts.elastic.co/packages/7.x/apt stable main
|
repo: "deb {{ elasticrepo.apt }} stable main"
|
||||||
state: absent
|
state: absent
|
||||||
|
changed_when: false
|
||||||
|
|||||||
@ -1,5 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: Remove Elasticsearch repository (and clean up left-over metadata)
|
- name: Remove Elasticsearch repository (and clean up left-over metadata)
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: elastic_repo
|
name: elastic_repo_7
|
||||||
state: absent
|
state: absent
|
||||||
|
changed_when: false
|
||||||
|
|||||||
@ -1,12 +1,15 @@
|
|||||||
---
|
---
|
||||||
- name: RedHat/CentOS/Fedora | Install Elastic repo
|
- name: RedHat/CentOS/Fedora | Install Elastic repo
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: elastic_repo
|
name: elastic_repo_7
|
||||||
description: Elastic repository for 7.x packages
|
description: Elastic repository for 7.x packages
|
||||||
baseurl: https://artifacts.elastic.co/packages/7.x/yum
|
baseurl: "{{ elasticrepo.yum }}"
|
||||||
gpgkey: https://artifacts.elastic.co/GPG-KEY-elasticsearch
|
gpgkey: "{{ elasticrepo.gpg }}"
|
||||||
gpgcheck: true
|
gpgcheck: true
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
- name: RedHat/CentOS/Fedora | Install Kibana
|
- name: RedHat/CentOS/Fedora | Install Kibana
|
||||||
package: name=kibana-{{ elastic_stack_version }} state=present
|
package: name=kibana-{{ elastic_stack_version }} state=present
|
||||||
|
register: installing_kibana_package
|
||||||
|
until: installing_kibana_package is succeeded
|
||||||
tags: install
|
tags: install
|
||||||
|
|||||||
@ -0,0 +1,76 @@
|
|||||||
|
---
|
||||||
|
- name: Ensure the Git package is present
|
||||||
|
package:
|
||||||
|
name: git
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Modify repo url if host is in Debian family
|
||||||
|
set_fact:
|
||||||
|
node_js_repo_type: deb
|
||||||
|
when:
|
||||||
|
- ansible_os_family | lower == "debian"
|
||||||
|
|
||||||
|
- name: Download script to install Nodejs repository
|
||||||
|
get_url:
|
||||||
|
url: "https://{{ nodejs['repo_dict'][ansible_os_family|lower] }}.{{ nodejs['repo_url_ext'] }}"
|
||||||
|
dest: "/tmp/setup_nodejs_repo.sh"
|
||||||
|
mode: 0700
|
||||||
|
|
||||||
|
- name: Execute downloaded script to install Nodejs repo
|
||||||
|
command: /tmp/setup_nodejs_repo.sh
|
||||||
|
register: node_repo_installation_result
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Install Nodejs
|
||||||
|
package:
|
||||||
|
name: nodejs
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Install yarn dependency to build the Wazuh Kibana Plugin
|
||||||
|
# Using shell due to errors when evaluating text between @ with command
|
||||||
|
shell: "npm install -g {{ 'yarn' }}{{ '@' }}{{ '1.10.1'}}" # noqa 305
|
||||||
|
register: install_yarn_result
|
||||||
|
changed_when: install_yarn_result == 0
|
||||||
|
|
||||||
|
- name: Remove old wazuh-kibana-app git directory
|
||||||
|
file:
|
||||||
|
path: /tmp/app
|
||||||
|
state: absent
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Clone wazuh-kibana-app repository # Using command as git module doesn't cover single-branch nor depth
|
||||||
|
command: git clone https://github.com/wazuh/wazuh-kibana-app -b {{ wazuh_plugin_branch }} --single-branch --depth=1 app # noqa 303
|
||||||
|
register: clone_app_repo_result
|
||||||
|
changed_when: false
|
||||||
|
args:
|
||||||
|
chdir: "/tmp"
|
||||||
|
|
||||||
|
- name: Executing yarn to build the package
|
||||||
|
command: "{{ item }}"
|
||||||
|
with_items:
|
||||||
|
- "yarn"
|
||||||
|
- "yarn build"
|
||||||
|
register: yarn_execution_result
|
||||||
|
changed_when: false
|
||||||
|
args:
|
||||||
|
chdir: "/tmp/app/"
|
||||||
|
|
||||||
|
- name: Obtain name of generated package
|
||||||
|
shell: "find ./ -name 'wazuh-*.zip' -printf '%f\\n'"
|
||||||
|
register: wazuhapp_package_name
|
||||||
|
changed_when: false
|
||||||
|
args:
|
||||||
|
chdir: "/tmp/app/build"
|
||||||
|
|
||||||
|
- name: Install Wazuh Plugin (can take a while)
|
||||||
|
shell: NODE_OPTIONS="{{ node_options }}" /usr/share/kibana/bin/kibana-plugin install file:///tmp/app/build/{{ wazuhapp_package_name.stdout }}
|
||||||
|
args:
|
||||||
|
executable: /bin/bash
|
||||||
|
creates: /usr/share/kibana/plugins/wazuh/package.json
|
||||||
|
chdir: /usr/share/kibana
|
||||||
|
become: yes
|
||||||
|
become_user: kibana
|
||||||
|
notify: restart kibana
|
||||||
|
tags:
|
||||||
|
- install
|
||||||
|
- skip_ansible_lint
|
||||||
@ -1,22 +1,77 @@
|
|||||||
---
|
---
|
||||||
|
|
||||||
|
- name: Stopping early, trying to compile Wazuh Kibana Plugin on Debian 10 is not possible
|
||||||
|
fail:
|
||||||
|
msg: "It's not possible to compile the Wazuh Kibana plugin on Debian 10 due to: https://github.com/wazuh/wazuh-kibana-app/issues/1924"
|
||||||
|
when:
|
||||||
|
- build_from_sources
|
||||||
|
- ansible_distribution == "Debian"
|
||||||
|
- ansible_distribution_major_version == "10"
|
||||||
|
|
||||||
- import_tasks: RedHat.yml
|
- import_tasks: RedHat.yml
|
||||||
when: ansible_os_family == 'RedHat'
|
when: ansible_os_family == 'RedHat'
|
||||||
|
|
||||||
- import_tasks: Debian.yml
|
- import_tasks: Debian.yml
|
||||||
when: ansible_os_family == 'Debian'
|
when: ansible_os_family == 'Debian'
|
||||||
|
|
||||||
- name: Make sure Elasticsearch is running before proceeding.
|
|
||||||
wait_for: host={{ elasticsearch_network_host }} port={{ elasticsearch_http_port }} delay=3 timeout=300
|
|
||||||
tags: configure
|
|
||||||
ignore_errors: true
|
|
||||||
|
|
||||||
- name: Reload systemd
|
- name: Reload systemd
|
||||||
systemd: daemon_reload=true
|
systemd:
|
||||||
|
daemon_reload: true
|
||||||
ignore_errors: true
|
ignore_errors: true
|
||||||
when:
|
when:
|
||||||
- not (ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA")
|
- not (ansible_distribution == "Amazon" and ansible_distribution_version == "(Karoo)")
|
||||||
- not (ansible_distribution == "Ubuntu" and ansible_distribution_version is version('15.04', '<'))
|
- not (ansible_distribution == "Ubuntu" and ansible_distribution_version is version('15.04', '<'))
|
||||||
- not (ansible_distribution == "Debian" and ansible_distribution_version is version('8', '<'))
|
- not (ansible_distribution == "Debian" and ansible_distribution_version is version('8', '<'))
|
||||||
|
- not (ansible_os_family == "RedHat" and ansible_distribution_version is version('7', '<'))
|
||||||
|
|
||||||
|
- name: Copying node's certificate from master
|
||||||
|
copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0440
|
||||||
|
with_items:
|
||||||
|
- "{{ master_certs_path }}/{{ kibana_node_name }}/{{ kibana_node_name }}.key"
|
||||||
|
- "{{ master_certs_path }}/{{ kibana_node_name }}/{{ kibana_node_name }}.crt"
|
||||||
|
- "{{ master_certs_path }}/ca/ca.crt"
|
||||||
|
tags: xpack-security
|
||||||
|
when:
|
||||||
|
- kibana_xpack_security
|
||||||
|
- generate_CA
|
||||||
|
|
||||||
|
- name: Copying node's certificate from master (Custom CA)
|
||||||
|
copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0440
|
||||||
|
with_items:
|
||||||
|
- "{{ master_certs_path }}/{{ kibana_node_name }}/{{ kibana_node_name }}.key"
|
||||||
|
- "{{ master_certs_path }}/{{ kibana_node_name }}/{{ kibana_node_name }}.crt"
|
||||||
|
- "{{ master_certs_path }}/ca/{{ ca_cert_name }}"
|
||||||
|
when:
|
||||||
|
- kibana_xpack_security
|
||||||
|
- not generate_CA
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
|
- name: Ensuring certificates folder owner
|
||||||
|
file:
|
||||||
|
path: "{{ node_certs_destination }}/"
|
||||||
|
state: directory
|
||||||
|
recurse: yes
|
||||||
|
owner: kibana
|
||||||
|
group: kibana
|
||||||
|
when:
|
||||||
|
- kibana_xpack_security
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
|
- name: Ensuring certificates folder owner
|
||||||
|
file:
|
||||||
|
path: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0770
|
||||||
|
recurse: yes
|
||||||
|
when:
|
||||||
|
- kibana_xpack_security
|
||||||
|
notify: restart kibana
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
- name: Kibana configuration
|
- name: Kibana configuration
|
||||||
template:
|
template:
|
||||||
@ -24,38 +79,110 @@
|
|||||||
dest: /etc/kibana/kibana.yml
|
dest: /etc/kibana/kibana.yml
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: 0664
|
mode: 0644
|
||||||
notify: restart kibana
|
notify: restart kibana
|
||||||
tags: configure
|
tags: configure
|
||||||
|
|
||||||
- name: Checking Wazuh-APP version
|
- name: Checking Wazuh-APP version
|
||||||
shell: "grep -c -E 'version.*{{ elastic_stack_version }}' /usr/share/kibana/plugins/wazuh/package.json | xargs echo"
|
shell: >-
|
||||||
|
grep -c -E 'version.*{{ elastic_stack_version }}' /usr/share/kibana/plugins/wazuh/package.json
|
||||||
args:
|
args:
|
||||||
|
executable: /bin/bash
|
||||||
removes: /usr/share/kibana/plugins/wazuh/package.json
|
removes: /usr/share/kibana/plugins/wazuh/package.json
|
||||||
register: wazuh_app_verify
|
register: wazuh_app_verify
|
||||||
changed_when: false
|
changed_when: false
|
||||||
tags: install
|
failed_when:
|
||||||
|
- wazuh_app_verify.rc != 0
|
||||||
|
- wazuh_app_verify.rc != 1
|
||||||
|
|
||||||
- name: Removing old Wazuh-APP
|
- name: Removing old Wazuh-APP
|
||||||
command: /usr/share/kibana/bin/kibana-plugin remove wazuh
|
command: /usr/share/kibana/bin/kibana-plugin --allow-root remove wazuh
|
||||||
when: wazuh_app_verify.stdout == "0"
|
when: wazuh_app_verify.rc == 1
|
||||||
tags: install
|
tags: install
|
||||||
|
|
||||||
- name: Removing bundles
|
- name: Removing bundles
|
||||||
file: path=/usr/share/kibana/optimize/bundles state=absent
|
file:
|
||||||
when: wazuh_app_verify.stdout == "0"
|
path: /usr/share/kibana/optimize/bundles
|
||||||
|
state: absent
|
||||||
|
when: wazuh_app_verify.rc == 1
|
||||||
tags: install
|
tags: install
|
||||||
|
|
||||||
- name: Install Wazuh-APP (can take a while)
|
- name: Explicitly starting Kibana to generate "wazuh-"
|
||||||
shell: "/usr/share/kibana/bin/kibana-plugin install https://packages.wazuh.com/wazuhapp/wazuhapp-{{ wazuh_version }}_{{ elastic_stack_version }}.zip"
|
service:
|
||||||
environment:
|
name: kibana
|
||||||
NODE_OPTIONS: "--max-old-space-size=3072"
|
state: started
|
||||||
|
|
||||||
|
- name: Build and Install Wazuh Kibana Plugin from sources
|
||||||
|
import_tasks: build_wazuh_plugin.yml
|
||||||
|
when:
|
||||||
|
- build_from_sources is defined
|
||||||
|
- build_from_sources
|
||||||
|
|
||||||
|
- name: Install Wazuh Plugin (can take a while)
|
||||||
|
shell: >-
|
||||||
|
NODE_OPTIONS="{{ node_options }}" /usr/share/kibana/bin/kibana-plugin install
|
||||||
|
{{ wazuh_app_url }}-{{ wazuh_version }}_{{ elastic_stack_version }}.zip
|
||||||
args:
|
args:
|
||||||
|
executable: /bin/bash
|
||||||
creates: /usr/share/kibana/plugins/wazuh/package.json
|
creates: /usr/share/kibana/plugins/wazuh/package.json
|
||||||
|
chdir: /usr/share/kibana
|
||||||
|
become: yes
|
||||||
|
become_user: kibana
|
||||||
notify: restart kibana
|
notify: restart kibana
|
||||||
tags: install
|
tags:
|
||||||
|
- install
|
||||||
|
- skip_ansible_lint
|
||||||
|
when:
|
||||||
|
- not build_from_sources
|
||||||
|
|
||||||
- name: Ensure Kibana started and enabled
|
- name: Kibana optimization (can take a while)
|
||||||
|
shell: NODE_OPTIONS="{{ node_options }}" /usr/share/kibana/bin/kibana --optimize
|
||||||
|
args:
|
||||||
|
executable: /bin/bash
|
||||||
|
become: yes
|
||||||
|
become_user: kibana
|
||||||
|
changed_when: false
|
||||||
|
tags:
|
||||||
|
- skip_ansible_lint
|
||||||
|
|
||||||
|
- name: Wait for Elasticsearch port
|
||||||
|
wait_for: host={{ elasticsearch_network_host }} port={{ elasticsearch_http_port }}
|
||||||
|
|
||||||
|
- name: Select correct API protocol
|
||||||
|
set_fact:
|
||||||
|
elastic_api_protocol: "{% if kibana_xpack_security %}https{% else %}http{% endif %}"
|
||||||
|
|
||||||
|
- name: Attempting to delete legacy Wazuh index if exists
|
||||||
|
uri:
|
||||||
|
url: "{{ elastic_api_protocol }}://{{ elasticsearch_network_host }}:{{ elasticsearch_http_port }}/.wazuh"
|
||||||
|
method: DELETE
|
||||||
|
user: "{{ elasticsearch_xpack_security_user }}"
|
||||||
|
password: "{{ elasticsearch_xpack_security_password }}"
|
||||||
|
validate_certs: no
|
||||||
|
status_code: 200, 404
|
||||||
|
|
||||||
|
- name: Create wazuh plugin config directory
|
||||||
|
file:
|
||||||
|
path: /usr/share/kibana/optimize/wazuh/config/
|
||||||
|
state: directory
|
||||||
|
recurse: yes
|
||||||
|
owner: kibana
|
||||||
|
group: kibana
|
||||||
|
mode: '0755'
|
||||||
|
|
||||||
|
- name: Configure Wazuh Kibana Plugin
|
||||||
|
template:
|
||||||
|
src: wazuh.yml.j2
|
||||||
|
dest: /usr/share/kibana/optimize/wazuh/config/wazuh.yml
|
||||||
|
owner: kibana
|
||||||
|
group: root
|
||||||
|
mode: 0644
|
||||||
|
|
||||||
|
- name: Reload systemd configuration
|
||||||
|
systemd:
|
||||||
|
daemon_reload: true
|
||||||
|
|
||||||
|
- name: Ensure Kibana is started and enabled
|
||||||
service:
|
service:
|
||||||
name: kibana
|
name: kibana
|
||||||
enabled: true
|
enabled: true
|
||||||
|
|||||||
@ -19,7 +19,11 @@ server.host: {{ kibana_server_host }}
|
|||||||
#server.name: "your-hostname"
|
#server.name: "your-hostname"
|
||||||
|
|
||||||
# The URL of the Elasticsearch instance to use for all your queries.
|
# The URL of the Elasticsearch instance to use for all your queries.
|
||||||
|
{% if kibana_xpack_security %}
|
||||||
|
elasticsearch.hosts: "https://{{ elasticsearch_network_host }}:{{ elasticsearch_http_port }}"
|
||||||
|
{% else %}
|
||||||
elasticsearch.hosts: "http://{{ elasticsearch_network_host }}:{{ elasticsearch_http_port }}"
|
elasticsearch.hosts: "http://{{ elasticsearch_network_host }}:{{ elasticsearch_http_port }}"
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
# When this setting's value is true Kibana uses the hostname specified in the server.host
|
# When this setting's value is true Kibana uses the hostname specified in the server.host
|
||||||
# setting. When the value of this setting is false, Kibana uses the hostname of the host
|
# setting. When the value of this setting is false, Kibana uses the hostname of the host
|
||||||
@ -98,3 +102,17 @@ elasticsearch.hosts: "http://{{ elasticsearch_network_host }}:{{ elasticsearch_h
|
|||||||
# Set the interval in milliseconds to sample system and process performance
|
# Set the interval in milliseconds to sample system and process performance
|
||||||
# metrics. Minimum is 100ms. Defaults to 5000.
|
# metrics. Minimum is 100ms. Defaults to 5000.
|
||||||
#ops.interval: 5000
|
#ops.interval: 5000
|
||||||
|
|
||||||
|
# Xpack Security
|
||||||
|
{% if kibana_xpack_security %}
|
||||||
|
elasticsearch.username: "{{ elasticsearch_xpack_security_user }}"
|
||||||
|
elasticsearch.password: "{{ elasticsearch_xpack_security_password }}"
|
||||||
|
server.ssl.enabled: true
|
||||||
|
server.ssl.key: "{{node_certs_destination}}/{{ kibana_node_name }}.key"
|
||||||
|
server.ssl.certificate: "{{node_certs_destination}}/{{ kibana_node_name }}.crt"
|
||||||
|
{% if generate_CA == true %}
|
||||||
|
elasticsearch.ssl.certificateAuthorities: ["{{ node_certs_destination }}/ca.crt"]
|
||||||
|
{% elif generate_CA == false %}
|
||||||
|
elasticsearch.ssl.certificateAuthorities: ["{{ node_certs_destination }}/{{ca_cert_name}}"]
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
134
roles/elastic-stack/ansible-kibana/templates/wazuh.yml.j2
Normal file
134
roles/elastic-stack/ansible-kibana/templates/wazuh.yml.j2
Normal file
@ -0,0 +1,134 @@
|
|||||||
|
---
|
||||||
|
#
|
||||||
|
# Wazuh app - App configuration file
|
||||||
|
# Copyright (C) 2015-2019 Wazuh, Inc.
|
||||||
|
#
|
||||||
|
# This program is free software; you can redistribute it and/or modify
|
||||||
|
# it under the terms of the GNU General Public License as published by
|
||||||
|
# the Free Software Foundation; either version 2 of the License, or
|
||||||
|
# (at your option) any later version.
|
||||||
|
#
|
||||||
|
# Find more information about this on the LICENSE file.
|
||||||
|
#
|
||||||
|
# ======================== Wazuh app configuration file ========================
|
||||||
|
#
|
||||||
|
# Please check the documentation for more information on configuration options:
|
||||||
|
# https://documentation.wazuh.com/current/installation-guide/index.html
|
||||||
|
#
|
||||||
|
# Also, you can check our repository:
|
||||||
|
# https://github.com/wazuh/wazuh-kibana-app
|
||||||
|
#
|
||||||
|
# ------------------------------- Index patterns -------------------------------
|
||||||
|
#
|
||||||
|
# Default index pattern to use.
|
||||||
|
#pattern: wazuh-alerts-3.x-*
|
||||||
|
#
|
||||||
|
# ----------------------------------- Checks -----------------------------------
|
||||||
|
#
|
||||||
|
# Defines which checks must to be consider by the healthcheck
|
||||||
|
# step once the Wazuh app starts. Values must to be true or false.
|
||||||
|
#checks.pattern : true
|
||||||
|
#checks.template: true
|
||||||
|
#checks.api : true
|
||||||
|
#checks.setup : true
|
||||||
|
#
|
||||||
|
# --------------------------------- Extensions ---------------------------------
|
||||||
|
#
|
||||||
|
# Defines which extensions should be activated when you add a new API entry.
|
||||||
|
# You can change them after Wazuh app starts.
|
||||||
|
# Values must to be true or false.
|
||||||
|
#extensions.pci : true
|
||||||
|
#extensions.gdpr : true
|
||||||
|
#extensions.hipaa : true
|
||||||
|
#extensions.nist : true
|
||||||
|
#extensions.audit : true
|
||||||
|
#extensions.oscap : false
|
||||||
|
#extensions.ciscat : false
|
||||||
|
#extensions.aws : false
|
||||||
|
#extensions.virustotal: false
|
||||||
|
#extensions.osquery : false
|
||||||
|
#extensions.docker : false
|
||||||
|
#
|
||||||
|
# ---------------------------------- Time out ----------------------------------
|
||||||
|
#
|
||||||
|
# Defines maximum timeout to be used on the Wazuh app requests.
|
||||||
|
# It will be ignored if it is bellow 1500.
|
||||||
|
# It means milliseconds before we consider a request as failed.
|
||||||
|
# Default: 20000
|
||||||
|
#timeout: 20000
|
||||||
|
#
|
||||||
|
# ------------------------------ Advanced indices ------------------------------
|
||||||
|
#
|
||||||
|
# Configure .wazuh indices shards and replicas.
|
||||||
|
#wazuh.shards : 1
|
||||||
|
#wazuh.replicas : 0
|
||||||
|
#
|
||||||
|
# --------------------------- Index pattern selector ---------------------------
|
||||||
|
#
|
||||||
|
# Defines if the user is allowed to change the selected
|
||||||
|
# index pattern directly from the Wazuh app top menu.
|
||||||
|
# Default: true
|
||||||
|
#ip.selector: true
|
||||||
|
#
|
||||||
|
# List of index patterns to be ignored
|
||||||
|
#ip.ignore: []
|
||||||
|
#
|
||||||
|
# -------------------------------- X-Pack RBAC ---------------------------------
|
||||||
|
#
|
||||||
|
# Custom setting to enable/disable built-in X-Pack RBAC security capabilities.
|
||||||
|
# Default: enabled
|
||||||
|
#xpack.rbac.enabled: true
|
||||||
|
#
|
||||||
|
# ------------------------------ wazuh-monitoring ------------------------------
|
||||||
|
#
|
||||||
|
# Custom setting to enable/disable wazuh-monitoring indices.
|
||||||
|
# Values: true, false, worker
|
||||||
|
# If worker is given as value, the app will show the Agents status
|
||||||
|
# visualization but won't insert data on wazuh-monitoring indices.
|
||||||
|
# Default: true
|
||||||
|
#wazuh.monitoring.enabled: true
|
||||||
|
#
|
||||||
|
# Custom setting to set the frequency for wazuh-monitoring indices cron task.
|
||||||
|
# Default: 900 (s)
|
||||||
|
#wazuh.monitoring.frequency: 900
|
||||||
|
#
|
||||||
|
# Configure wazuh-monitoring-3.x-* indices shards and replicas.
|
||||||
|
#wazuh.monitoring.shards: 2
|
||||||
|
#wazuh.monitoring.replicas: 0
|
||||||
|
#
|
||||||
|
# Configure wazuh-monitoring-3.x-* indices custom creation interval.
|
||||||
|
# Values: h (hourly), d (daily), w (weekly), m (monthly)
|
||||||
|
# Default: d
|
||||||
|
#wazuh.monitoring.creation: d
|
||||||
|
#
|
||||||
|
# Default index pattern to use for Wazuh monitoring
|
||||||
|
#wazuh.monitoring.pattern: wazuh-monitoring-3.x-*
|
||||||
|
#
|
||||||
|
#
|
||||||
|
# ------------------------------- App privileges --------------------------------
|
||||||
|
#admin: true
|
||||||
|
#
|
||||||
|
# ------------------------------- App logging level -----------------------------
|
||||||
|
# Set the logging level for the Wazuh App log files.
|
||||||
|
# Default value: info
|
||||||
|
# Allowed values: info, debug
|
||||||
|
#logs.level: info
|
||||||
|
#
|
||||||
|
#-------------------------------- API entries -----------------------------------
|
||||||
|
#The following configuration is the default structure to define an API entry.
|
||||||
|
#
|
||||||
|
#hosts:
|
||||||
|
# - <id>:
|
||||||
|
# url: http(s)://<url>
|
||||||
|
# port: <port>
|
||||||
|
# user: <user>
|
||||||
|
# password: <password>
|
||||||
|
|
||||||
|
hosts:
|
||||||
|
{% for api in wazuh_api_credentials %}
|
||||||
|
- {{ api['id'] }}:
|
||||||
|
url: {{ api['url'] }}
|
||||||
|
port: {{ api['port'] }}
|
||||||
|
user: {{ api['user'] }}
|
||||||
|
password: {{ api['password'] }}
|
||||||
|
{% endfor %}
|
||||||
@ -1,4 +1,6 @@
|
|||||||
---
|
---
|
||||||
|
filebeat_version: 7.6.1
|
||||||
|
|
||||||
filebeat_create_config: true
|
filebeat_create_config: true
|
||||||
|
|
||||||
filebeat_prospectors:
|
filebeat_prospectors:
|
||||||
@ -10,6 +12,8 @@ filebeat_prospectors:
|
|||||||
json.keys_under_root: true
|
json.keys_under_root: true
|
||||||
json.overwrite_keys: true
|
json.overwrite_keys: true
|
||||||
|
|
||||||
|
filebeat_node_name: node-1
|
||||||
|
|
||||||
filebeat_output_elasticsearch_enabled: false
|
filebeat_output_elasticsearch_enabled: false
|
||||||
filebeat_output_elasticsearch_hosts:
|
filebeat_output_elasticsearch_hosts:
|
||||||
- "localhost:9200"
|
- "localhost:9200"
|
||||||
@ -23,3 +27,31 @@ filebeat_ssl_dir: /etc/pki/filebeat
|
|||||||
filebeat_ssl_certificate_file: ""
|
filebeat_ssl_certificate_file: ""
|
||||||
filebeat_ssl_key_file: ""
|
filebeat_ssl_key_file: ""
|
||||||
filebeat_ssl_insecure: "false"
|
filebeat_ssl_insecure: "false"
|
||||||
|
|
||||||
|
filebeat_module_package_url: https://packages.wazuh.com/3.x/filebeat
|
||||||
|
filebeat_module_package_name: wazuh-filebeat-0.1.tar.gz
|
||||||
|
filebeat_module_package_path: /tmp/
|
||||||
|
filebeat_module_destination: /usr/share/filebeat/module
|
||||||
|
filebeat_module_folder: /usr/share/filebeat/module/wazuh
|
||||||
|
|
||||||
|
# Xpack Security
|
||||||
|
filebeat_xpack_security: false
|
||||||
|
|
||||||
|
elasticsearch_xpack_security_user: elastic
|
||||||
|
elasticsearch_xpack_security_password: elastic_pass
|
||||||
|
|
||||||
|
node_certs_generator : false
|
||||||
|
node_certs_source: /usr/share/elasticsearch
|
||||||
|
node_certs_destination: /etc/filebeat/certs
|
||||||
|
|
||||||
|
|
||||||
|
# CA Generation
|
||||||
|
master_certs_path: /es_certs
|
||||||
|
generate_CA: true
|
||||||
|
ca_cert_name: ""
|
||||||
|
|
||||||
|
elasticrepo:
|
||||||
|
apt: 'https://artifacts.elastic.co/packages/7.x/apt'
|
||||||
|
yum: 'https://artifacts.elastic.co/packages/7.x/yum'
|
||||||
|
gpg: 'https://artifacts.elastic.co/GPG-KEY-elasticsearch'
|
||||||
|
key_id: '46095ACC8548582C1A2699A9D27D666CD88E42B4'
|
||||||
|
|||||||
@ -1,17 +1,22 @@
|
|||||||
---
|
---
|
||||||
- name: Debian/Ubuntu | Install apt-transport-https and ca-certificates
|
- name: Debian/Ubuntu | Install apt-transport-https and ca-certificates
|
||||||
apt:
|
apt:
|
||||||
name: ['apt-transport-https', 'ca-certificates']
|
name:
|
||||||
|
- apt-transport-https
|
||||||
|
- ca-certificates
|
||||||
state: present
|
state: present
|
||||||
|
register: filebeat_ca_packages_install
|
||||||
|
until: filebeat_ca_packages_install is succeeded
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Add Elasticsearch apt key.
|
- name: Debian/Ubuntu | Add Elasticsearch apt key.
|
||||||
apt_key:
|
apt_key:
|
||||||
url: https://artifacts.elastic.co/GPG-KEY-elasticsearch
|
url: "{{ elasticrepo.gpg }}"
|
||||||
|
id: "{{ elasticrepo.key_id }}"
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Add Filebeat repository.
|
- name: Debian/Ubuntu | Add Filebeat repository.
|
||||||
apt_repository:
|
apt_repository:
|
||||||
repo: 'deb https://artifacts.elastic.co/packages/7.x/apt stable main'
|
repo: "deb {{ elasticrepo.apt }} stable main"
|
||||||
state: present
|
state: present
|
||||||
update_cache: true
|
update_cache: true
|
||||||
|
changed_when: false
|
||||||
|
|||||||
@ -1,5 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: Debian/Ubuntu | Remove Filebeat repository (and clean up left-over metadata)
|
- name: Debian/Ubuntu | Remove Filebeat repository (and clean up left-over metadata)
|
||||||
apt_repository:
|
apt_repository:
|
||||||
repo: deb https://artifacts.elastic.co/packages/7.x/apt stable main
|
repo: "deb {{ elasticrepo.apt }} stable main"
|
||||||
state: absent
|
state: absent
|
||||||
|
changed_when: false
|
||||||
|
|||||||
@ -1,5 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: RedHat/CentOS/Fedora | Remove Filebeat repository (and clean up left-over metadata)
|
- name: RedHat/CentOS/Fedora | Remove Filebeat repository (and clean up left-over metadata)
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: elastic_repo
|
name: elastic_repo_7
|
||||||
state: absent
|
state: absent
|
||||||
|
changed_when: false
|
||||||
|
|||||||
@ -1,8 +1,9 @@
|
|||||||
---
|
---
|
||||||
- name: RedHat/CentOS/Fedora/Amazon Linux | Install Filebeats repo
|
- name: RedHat/CentOS/Fedora/Amazon Linux | Install Filebeats repo
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: elastic_repo
|
name: elastic_repo_7
|
||||||
description: Elastic repository for 6.x packages
|
description: Elastic repository for 7.x packages
|
||||||
baseurl: https://artifacts.elastic.co/packages/7.x/yum
|
baseurl: "{{ elasticrepo.yum }}"
|
||||||
gpgkey: https://artifacts.elastic.co/GPG-KEY-elasticsearch
|
gpgkey: "{{ elasticrepo.gpg }}"
|
||||||
gpgcheck: true
|
gpgcheck: true
|
||||||
|
changed_when: false
|
||||||
|
|||||||
@ -5,7 +5,7 @@
|
|||||||
dest: "/etc/filebeat/filebeat.yml"
|
dest: "/etc/filebeat/filebeat.yml"
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: 0644
|
mode: 0400
|
||||||
notify: restart filebeat
|
notify: restart filebeat
|
||||||
tags: configure
|
tags: configure
|
||||||
|
|
||||||
@ -15,7 +15,7 @@
|
|||||||
dest: "/etc/filebeat/wazuh-template.json"
|
dest: "/etc/filebeat/wazuh-template.json"
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: 0644
|
mode: 0400
|
||||||
notify: restart filebeat
|
notify: restart filebeat
|
||||||
tags: configure
|
tags: configure
|
||||||
|
|
||||||
@ -30,7 +30,7 @@
|
|||||||
copy:
|
copy:
|
||||||
src: "{{ item }}"
|
src: "{{ item }}"
|
||||||
dest: "{{ filebeat_ssl_dir }}/{{ item | basename }}"
|
dest: "{{ filebeat_ssl_dir }}/{{ item | basename }}"
|
||||||
mode: 0644
|
mode: 0400
|
||||||
with_items:
|
with_items:
|
||||||
- "{{ filebeat_ssl_key_file }}"
|
- "{{ filebeat_ssl_key_file }}"
|
||||||
- "{{ filebeat_ssl_certificate_file }}"
|
- "{{ filebeat_ssl_certificate_file }}"
|
||||||
|
|||||||
@ -1,17 +1,107 @@
|
|||||||
---
|
---
|
||||||
- import_tasks: RedHat.yml
|
- include_tasks: RedHat.yml
|
||||||
when: ansible_os_family == 'RedHat'
|
when: ansible_os_family == 'RedHat'
|
||||||
|
|
||||||
- import_tasks: Debian.yml
|
- include_tasks: Debian.yml
|
||||||
when: ansible_os_family == 'Debian'
|
when: ansible_os_family == 'Debian'
|
||||||
|
|
||||||
- name: Install Filebeat.
|
- name: CentOS/RedHat | Install Filebeat.
|
||||||
package: name=filebeat state=present
|
package: name=filebeat-{{ filebeat_version }} state=present
|
||||||
|
register: filebeat_installing_package
|
||||||
|
until: filebeat_installing_package is succeeded
|
||||||
|
when:
|
||||||
|
- ansible_distribution in ['CentOS','RedHat', 'Amazon']
|
||||||
tags:
|
tags:
|
||||||
- install
|
- install
|
||||||
|
|
||||||
|
- name: Debian/Ubuntu | Install Filebeat.
|
||||||
|
apt:
|
||||||
|
name: filebeat={{ filebeat_version }}
|
||||||
|
state: present
|
||||||
|
cache_valid_time: 3600
|
||||||
|
register: filebeat_installing_package_debian
|
||||||
|
until: filebeat_installing_package_debian is succeeded
|
||||||
|
when:
|
||||||
|
- not (ansible_distribution in ['CentOS','RedHat', 'Amazon'])
|
||||||
|
tags:
|
||||||
|
- init
|
||||||
|
|
||||||
|
- name: Copying node's certificate from master
|
||||||
|
copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0440
|
||||||
|
with_items:
|
||||||
|
- "{{ master_certs_path }}/{{ filebeat_node_name }}/{{ filebeat_node_name }}.key"
|
||||||
|
- "{{ master_certs_path }}/{{ filebeat_node_name }}/{{ filebeat_node_name }}.crt"
|
||||||
|
- "{{ master_certs_path }}/ca/ca.crt"
|
||||||
|
when:
|
||||||
|
- generate_CA
|
||||||
|
- filebeat_xpack_security
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
|
- name: Copying node's certificate from master (Custom CA)
|
||||||
|
copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0440
|
||||||
|
with_items:
|
||||||
|
- "{{ master_certs_path }}/{{ filebeat_node_name }}/{{ filebeat_node_name }}.key"
|
||||||
|
- "{{ master_certs_path }}/{{ filebeat_node_name }}/{{ filebeat_node_name }}.crt"
|
||||||
|
- "{{ master_certs_path }}/ca/{{ ca_cert_name }}"
|
||||||
|
when:
|
||||||
|
- not generate_CA
|
||||||
|
- filebeat_xpack_security
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
|
- name: Ensuring folder & certs permissions
|
||||||
|
file:
|
||||||
|
path: "{{ node_certs_destination }}/"
|
||||||
|
mode: 0774
|
||||||
|
state: directory
|
||||||
|
recurse: yes
|
||||||
|
when:
|
||||||
|
- filebeat_xpack_security
|
||||||
|
tags: xpack-security
|
||||||
|
|
||||||
|
- name: Checking if Filebeat Module folder file exists
|
||||||
|
stat:
|
||||||
|
path: "{{ filebeat_module_folder }}"
|
||||||
|
register: filebeat_module_folder
|
||||||
|
|
||||||
|
|
||||||
|
- name: Download Filebeat module package
|
||||||
|
get_url:
|
||||||
|
url: "{{ filebeat_module_package_url }}/{{ filebeat_module_package_name }}"
|
||||||
|
dest: "{{ filebeat_module_package_path }}"
|
||||||
|
when: not filebeat_module_folder.stat.exists
|
||||||
|
|
||||||
|
- name: Unpakcing Filebeat module package
|
||||||
|
unarchive:
|
||||||
|
src: "{{ filebeat_module_package_path }}/{{ filebeat_module_package_name }}"
|
||||||
|
dest: "{{ filebeat_module_destination }}"
|
||||||
|
remote_src: yes
|
||||||
|
when: not filebeat_module_folder.stat.exists
|
||||||
|
|
||||||
|
- name: Setting 0755 permission for Filebeat module folder
|
||||||
|
file: dest={{ filebeat_module_folder }} mode=u=rwX,g=rwX,o=rwX recurse=yes
|
||||||
|
when: not filebeat_module_folder.stat.exists
|
||||||
|
|
||||||
|
- name: Checking if Filebeat Module package file exists
|
||||||
|
stat:
|
||||||
|
path: "{{ filebeat_module_package_path }}/{{ filebeat_module_package_name }}"
|
||||||
|
register: filebeat_module_package
|
||||||
|
when: filebeat_module_package is not defined
|
||||||
|
|
||||||
|
- name: Delete Filebeat module package file
|
||||||
|
file:
|
||||||
|
state: absent
|
||||||
|
path: "{{ filebeat_module_package_path }}/{{ filebeat_module_package_name }}"
|
||||||
|
when: filebeat_module_package.stat.exists
|
||||||
|
|
||||||
- import_tasks: config.yml
|
- import_tasks: config.yml
|
||||||
when: filebeat_create_config
|
when: filebeat_create_config
|
||||||
|
notify: restart filebeat
|
||||||
|
|
||||||
- name: Reload systemd
|
- name: Reload systemd
|
||||||
systemd: daemon_reload=yes
|
systemd: daemon_reload=yes
|
||||||
@ -20,6 +110,7 @@
|
|||||||
- not (ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA")
|
- not (ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA")
|
||||||
- not (ansible_distribution == "Ubuntu" and ansible_distribution_version is version('15.04', '<'))
|
- not (ansible_distribution == "Ubuntu" and ansible_distribution_version is version('15.04', '<'))
|
||||||
- not (ansible_distribution == "Debian" and ansible_distribution_version is version('8', '<'))
|
- not (ansible_distribution == "Debian" and ansible_distribution_version is version('8', '<'))
|
||||||
|
- not (ansible_os_family == "RedHat" and ansible_distribution_version is version('7', '<'))
|
||||||
|
|
||||||
- name: Ensure Filebeat is started and enabled at boot.
|
- name: Ensure Filebeat is started and enabled at boot.
|
||||||
service:
|
service:
|
||||||
@ -27,8 +118,8 @@
|
|||||||
state: started
|
state: started
|
||||||
enabled: true
|
enabled: true
|
||||||
|
|
||||||
- import_tasks: "RMRedHat.yml"
|
- include_tasks: "RMRedHat.yml"
|
||||||
when: ansible_os_family == "RedHat"
|
when: ansible_os_family == "RedHat"
|
||||||
|
|
||||||
- import_tasks: "RMDebian.yml"
|
- include_tasks: "RMDebian.yml"
|
||||||
when: ansible_os_family == "Debian"
|
when: ansible_os_family == "Debian"
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@ -1,58 +1,39 @@
|
|||||||
# Wazuh - Filebeat configuration file
|
# Wazuh - Filebeat configuration file
|
||||||
|
|
||||||
filebeat.inputs:
|
# Wazuh - Filebeat configuration file
|
||||||
- type: log
|
filebeat.modules:
|
||||||
paths:
|
- module: wazuh
|
||||||
- '/var/ossec/logs/alerts/alerts.json'
|
alerts:
|
||||||
|
enabled: true
|
||||||
|
archives:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
setup.template.json.enabled: true
|
setup.template.json.enabled: true
|
||||||
setup.template.json.path: "/etc/filebeat/wazuh-template.json"
|
setup.template.json.path: '/etc/filebeat/wazuh-template.json'
|
||||||
setup.template.json.name: "wazuh"
|
setup.template.json.name: 'wazuh'
|
||||||
setup.template.overwrite: true
|
setup.template.overwrite: true
|
||||||
|
setup.ilm.enabled: false
|
||||||
|
|
||||||
processors:
|
|
||||||
- decode_json_fields:
|
|
||||||
fields: ['message']
|
|
||||||
process_array: true
|
|
||||||
max_depth: 200
|
|
||||||
target: ''
|
|
||||||
overwrite_keys: true
|
|
||||||
- drop_fields:
|
|
||||||
fields: ['message', 'ecs', 'beat', 'input_type', 'tags', 'count', '@version', 'log', 'offset', 'type', 'host']
|
|
||||||
- rename:
|
|
||||||
fields:
|
|
||||||
- from: "data.aws.sourceIPAddress"
|
|
||||||
to: "@src_ip"
|
|
||||||
ignore_missing: true
|
|
||||||
fail_on_error: false
|
|
||||||
when:
|
|
||||||
regexp:
|
|
||||||
data.aws.sourceIPAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
|
|
||||||
- rename:
|
|
||||||
fields:
|
|
||||||
- from: "data.srcip"
|
|
||||||
to: "@src_ip"
|
|
||||||
ignore_missing: true
|
|
||||||
fail_on_error: false
|
|
||||||
when:
|
|
||||||
regexp:
|
|
||||||
data.srcip: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
|
|
||||||
- rename:
|
|
||||||
fields:
|
|
||||||
- from: "data.win.eventdata.ipAddress"
|
|
||||||
to: "@src_ip"
|
|
||||||
ignore_missing: true
|
|
||||||
fail_on_error: false
|
|
||||||
when:
|
|
||||||
regexp:
|
|
||||||
data.win.eventdata.ipAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
|
|
||||||
|
|
||||||
# Send events directly to Elasticsearch
|
# Send events directly to Elasticsearch
|
||||||
output.elasticsearch:
|
output.elasticsearch:
|
||||||
hosts: {{ filebeat_output_elasticsearch_hosts | to_json }}
|
hosts: {{ filebeat_output_elasticsearch_hosts | to_json }}
|
||||||
#pipeline: geoip
|
|
||||||
indices:
|
{% if filebeat_xpack_security %}
|
||||||
- index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}'
|
username: {{ elasticsearch_xpack_security_user }}
|
||||||
|
password: {{ elasticsearch_xpack_security_password }}
|
||||||
|
protocol: https
|
||||||
|
{% if generate_CA == true %}
|
||||||
|
ssl.certificate_authorities:
|
||||||
|
- {{node_certs_destination}}/ca.crt
|
||||||
|
{% elif generate_CA == false %}
|
||||||
|
ssl.certificate_authorities:
|
||||||
|
- {{node_certs_destination}}/{{ca_cert_name}}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
ssl.certificate: "{{node_certs_destination}}/{{ filebeat_node_name }}.crt"
|
||||||
|
ssl.key: "{{node_certs_destination}}/{{ filebeat_node_name }}.key"
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
# Optional. Send events to Logstash instead of Elasticsearch
|
# Optional. Send events to Logstash instead of Elasticsearch
|
||||||
#output.logstash.hosts: ["YOUR_LOGSTASH_SERVER_IP:5000"]
|
#output.logstash.hosts: ["YOUR_LOGSTASH_SERVER_IP:5000"]
|
||||||
@ -32,16 +32,17 @@ The following is an example of how this role can be used:
|
|||||||
wazuh_managers:
|
wazuh_managers:
|
||||||
- address: 127.0.0.1
|
- address: 127.0.0.1
|
||||||
port: 1514
|
port: 1514
|
||||||
protocol: udp
|
protocol: tcp
|
||||||
api_port: 55000
|
api_port: 55000
|
||||||
api_proto: 'http'
|
api_proto: 'http'
|
||||||
api_user: 'ansible'
|
api_user: 'ansible'
|
||||||
wazuh_agent_authd:
|
wazuh_agent_authd:
|
||||||
|
registration_address: 127.0.0.1
|
||||||
enable: true
|
enable: true
|
||||||
port: 1515
|
port: 1515
|
||||||
ssl_agent_ca: null
|
ssl_agent_ca: null
|
||||||
ssl_auto_negotiate: 'no'
|
ssl_auto_negotiate: 'no'
|
||||||
|
|
||||||
|
|
||||||
License and copyright
|
License and copyright
|
||||||
---------------------
|
---------------------
|
||||||
|
|||||||
@ -1,16 +1,53 @@
|
|||||||
---
|
---
|
||||||
|
wazuh_agent_version: 3.12.0-1
|
||||||
|
|
||||||
|
|
||||||
|
# Custom packages installation
|
||||||
|
|
||||||
|
wazuh_custom_packages_installation_agent_enabled: false
|
||||||
|
wazuh_custom_packages_installation_agent_deb_url: ""
|
||||||
|
wazuh_custom_packages_installation_agent_rpm_url: ""
|
||||||
|
|
||||||
|
# Sources installation
|
||||||
|
|
||||||
|
wazuh_agent_sources_installation:
|
||||||
|
enabled: false
|
||||||
|
branch: "v3.12.0"
|
||||||
|
user_language: "y"
|
||||||
|
user_no_stop: "y"
|
||||||
|
user_install_type: "agent"
|
||||||
|
user_dir: "/var/ossec"
|
||||||
|
user_delete_dir: "y"
|
||||||
|
user_enable_active_response: "y"
|
||||||
|
user_enable_syscheck: "y"
|
||||||
|
user_enable_rootcheck: "y"
|
||||||
|
user_enable_openscap: "y"
|
||||||
|
user_enable_sca: "y"
|
||||||
|
user_enable_authd: "y"
|
||||||
|
user_generate_authd_cert: "n"
|
||||||
|
user_update: "y"
|
||||||
|
user_binaryinstall: null
|
||||||
|
user_agent_server_ip: "YOUR_MANAGER_IP"
|
||||||
|
user_agent_server_name: null
|
||||||
|
user_agent_config_profile: null
|
||||||
|
user_ca_store: "/var/ossec/wpk_root.pem"
|
||||||
|
|
||||||
wazuh_managers:
|
wazuh_managers:
|
||||||
- address: 127.0.0.1
|
- address: 127.0.0.1
|
||||||
port: 1514
|
port: 1514
|
||||||
protocol: tcp
|
protocol: udp
|
||||||
api_port: 55000
|
api_port: 55000
|
||||||
api_proto: 'http'
|
api_proto: 'http'
|
||||||
api_user: null
|
api_user: null
|
||||||
wazuh_profile: null
|
wazuh_profile_centos: 'centos, centos7, centos7.6'
|
||||||
|
wazuh_profile_ubuntu: 'ubuntu, ubuntu18, ubuntu18.04'
|
||||||
wazuh_auto_restart: 'yes'
|
wazuh_auto_restart: 'yes'
|
||||||
wazuh_agent_authd:
|
wazuh_agent_authd:
|
||||||
|
registration_address: 127.0.0.1
|
||||||
enable: false
|
enable: false
|
||||||
port: 1515
|
port: 1515
|
||||||
|
agent_name: null
|
||||||
|
groups: []
|
||||||
ssl_agent_ca: null
|
ssl_agent_ca: null
|
||||||
ssl_agent_cert: null
|
ssl_agent_cert: null
|
||||||
ssl_agent_key: null
|
ssl_agent_key: null
|
||||||
@ -19,15 +56,22 @@ wazuh_notify_time: '10'
|
|||||||
wazuh_time_reconnect: '60'
|
wazuh_time_reconnect: '60'
|
||||||
wazuh_crypto_method: 'aes'
|
wazuh_crypto_method: 'aes'
|
||||||
wazuh_winagent_config:
|
wazuh_winagent_config:
|
||||||
install_dir: 'C:\Program Files\ossec-agent\'
|
download_dir: C:\
|
||||||
install_dir_x86: 'C:\Program Files (x86)\ossec-agent\'
|
install_dir: C:\Program Files\ossec-agent\
|
||||||
auth_path: C:\'Program Files'\ossec-agent\agent-auth.exe
|
install_dir_x86: C:\Program Files (x86)\ossec-agent\
|
||||||
|
auth_path: C:\Program Files\ossec-agent\agent-auth.exe
|
||||||
|
# Adding quotes to auth_path_x86 since win_shell outputs error otherwise
|
||||||
auth_path_x86: C:\'Program Files (x86)'\ossec-agent\agent-auth.exe
|
auth_path_x86: C:\'Program Files (x86)'\ossec-agent\agent-auth.exe
|
||||||
version: '3.9.2'
|
check_md5: True
|
||||||
revision: '1'
|
md5: 91efaefae4e1977670eab0c768a22a93
|
||||||
repo: https://packages.wazuh.com/3.x/windows/
|
wazuh_winagent_config_url: https://packages.wazuh.com/3.x/windows/wazuh-agent-3.12.0-1.msi
|
||||||
md5: 43936e7bc7eb51bd186f47dac4a6f477
|
wazuh_winagent_package_name: wazuh-agent-3.12.0-1.msi
|
||||||
wazuh_agent_config:
|
wazuh_agent_config:
|
||||||
|
repo:
|
||||||
|
apt: 'deb https://packages.wazuh.com/3.x/apt/ stable main'
|
||||||
|
yum: 'https://packages.wazuh.com/3.x/yum/'
|
||||||
|
gpg: 'https://packages.wazuh.com/key/GPG-KEY-WAZUH'
|
||||||
|
key_id: '0DCFCA5547B19D2A6099506096B3EE5F29111145'
|
||||||
active_response:
|
active_response:
|
||||||
ar_disabled: 'no'
|
ar_disabled: 'no'
|
||||||
ca_store: '/var/ossec/etc/wpk_root.pem'
|
ca_store: '/var/ossec/etc/wpk_root.pem'
|
||||||
@ -43,10 +87,17 @@ wazuh_agent_config:
|
|||||||
scan_on_start: 'yes'
|
scan_on_start: 'yes'
|
||||||
auto_ignore: 'no'
|
auto_ignore: 'no'
|
||||||
alert_new_files: 'yes'
|
alert_new_files: 'yes'
|
||||||
remove_old_diff: 'yes'
|
win_audit_interval: 60
|
||||||
restart_audit: 'yes'
|
|
||||||
win_audit_interval: 300
|
|
||||||
skip_nfs: 'yes'
|
skip_nfs: 'yes'
|
||||||
|
skip_dev: 'yes'
|
||||||
|
skip_proc: 'yes'
|
||||||
|
skip_sys: 'yes'
|
||||||
|
process_priority: 10
|
||||||
|
max_eps: 100
|
||||||
|
sync_enabled: 'yes'
|
||||||
|
sync_interval: '5m'
|
||||||
|
sync_max_interval: '1h'
|
||||||
|
sync_max_eps: 10
|
||||||
ignore:
|
ignore:
|
||||||
- /etc/mtab
|
- /etc/mtab
|
||||||
- /etc/hosts.deny
|
- /etc/hosts.deny
|
||||||
@ -60,114 +111,47 @@ wazuh_agent_config:
|
|||||||
- /etc/cups/certs
|
- /etc/cups/certs
|
||||||
- /etc/dumpdates
|
- /etc/dumpdates
|
||||||
- /etc/svc/volatile
|
- /etc/svc/volatile
|
||||||
- /sys/kernel/security
|
ignore_linux_type:
|
||||||
- /sys/kernel/debug
|
- '.log$|.swp$'
|
||||||
ignore_win:
|
ignore_win:
|
||||||
- '.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$'
|
- '.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$'
|
||||||
no_diff:
|
no_diff:
|
||||||
- /etc/ssl/private.key
|
- /etc/ssl/private.key
|
||||||
directories:
|
directories:
|
||||||
- dirs: /etc,/usr/bin,/usr/sbin
|
- dirs: /etc,/usr/bin,/usr/sbin
|
||||||
checks: 'check_all="yes"'
|
checks: ''
|
||||||
- dirs: /bin,/sbin
|
- dirs: /bin,/sbin,/boot
|
||||||
checks: 'check_all="yes"'
|
checks: ''
|
||||||
win_directories:
|
win_directories:
|
||||||
- dirs: '%WINDIR%\regedit.exe'
|
- dirs: '%WINDIR%'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0" restrict="regedit.exe$|system.ini$|win.ini$"'
|
||||||
- dirs: '%WINDIR%\system.ini'
|
- dirs: '%WINDIR%\SysNative'
|
||||||
checks: 'check_all="yes"'
|
checks: >-
|
||||||
- dirs: '%WINDIR%\win.ini'
|
recursion_level="0" restrict="at.exe$|attrib.exe$|cacls.exe$|cmd.exe$|eventcreate.exe$|ftp.exe$|lsass.exe$|
|
||||||
checks: 'check_all="yes"'
|
net.exe$|net1.exe$|netsh.exe$|reg.exe$|regedt32.exe|regsvr32.exe|runas.exe|sc.exe|schtasks.exe|sethc.exe|subst.exe$"
|
||||||
- dirs: '%WINDIR%\SysNative\at.exe'
|
- dirs: '%WINDIR%\SysNative\drivers\etc%'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0"'
|
||||||
- dirs: '%WINDIR%\SysNative\attrib.exe'
|
- dirs: '%WINDIR%\SysNative\wbem'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0" restrict="WMIC.exe$"'
|
||||||
- dirs: '%WINDIR%\SysNative\cacls.exe'
|
- dirs: '%WINDIR%\SysNative\WindowsPowerShell\v1.0'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0" restrict="powershell.exe$"'
|
||||||
- dirs: '%WINDIR%\SysNative\cmd.exe'
|
- dirs: '%WINDIR%\SysNative'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0" restrict="winrm.vbs$"'
|
||||||
- dirs: '%WINDIR%\SysNative\drivers\etc'
|
- dirs: '%WINDIR%\System32'
|
||||||
checks: 'check_all="yes"'
|
checks: >-
|
||||||
- dirs: '%WINDIR%\SysNative\eventcreate.exe'
|
recursion_level="0" restrict="at.exe$|attrib.exe$|cacls.exe$|cmd.exe$|eventcreate.exe$|ftp.exe$|lsass.exe$|net.exe$|net1.exe$|
|
||||||
checks: 'check_all="yes"'
|
netsh.exe$|reg.exe$|regedit.exe$|regedt32.exe$|regsvr32.exe$|runas.exe$|sc.exe$|schtasks.exe$|sethc.exe$|subst.exe$"
|
||||||
- dirs: '%WINDIR%\SysNative\ftp.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\lsass.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\net.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\net1.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\netsh.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\reg.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\regedt32.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\regsvr32.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\runas.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\sc.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\schtasks.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\sethc.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\subst.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\wbem\WMIC.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\WindowsPowerShell\v1.0\powershell.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\SysNative\winrm.vbs'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\at.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\attrib.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\cacls.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\cmd.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\drivers\etc'
|
- dirs: '%WINDIR%\System32\drivers\etc'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0"'
|
||||||
- dirs: '%WINDIR%\System32\eventcreate.exe'
|
- dirs: '%WINDIR%\System32\wbem'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0" restrict="WMIC.exe$"'
|
||||||
- dirs: '%WINDIR%\System32\ftp.exe'
|
- dirs: '%WINDIR%\System32\WindowsPowerShell\v1.0'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0" restrict="powershell.exe$"'
|
||||||
- dirs: '%WINDIR%\System32\net.exe'
|
- dirs: '%WINDIR%\System32'
|
||||||
checks: 'check_all="yes"'
|
checks: 'recursion_level="0" restrict="winrm.vbs$"'
|
||||||
- dirs: '%WINDIR%\System32\net1.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\netsh.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\reg.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\regedit.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\regedt32.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\regsvr32.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\runas.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\sc.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\schtasks.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\sethc.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\subst.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\wbem\WMIC.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\WindowsPowerShell\v1.0\powershell.exe'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%WINDIR%\System32\winrm.vbs'
|
|
||||||
checks: 'check_all="yes"'
|
|
||||||
- dirs: '%PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\Startup'
|
- dirs: '%PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\Startup'
|
||||||
checks: 'check_all="yes" realtime="yes"'
|
checks: 'realtime="yes"'
|
||||||
|
|
||||||
windows_registry:
|
windows_registry:
|
||||||
- key: 'HKEY_LOCAL_MACHINE\Software\Classes\batfile'
|
- key: 'HKEY_LOCAL_MACHINE\Software\Classes\batfile'
|
||||||
- key: 'HKEY_LOCAL_MACHINE\Software\Classes\cmdfile'
|
- key: 'HKEY_LOCAL_MACHINE\Software\Classes\cmdfile'
|
||||||
@ -210,18 +194,18 @@ wazuh_agent_config:
|
|||||||
rootcheck:
|
rootcheck:
|
||||||
frequency: 43200
|
frequency: 43200
|
||||||
openscap:
|
openscap:
|
||||||
disable: 'no'
|
disable: 'yes'
|
||||||
timeout: 1800
|
timeout: 1800
|
||||||
interval: '1d'
|
interval: '1d'
|
||||||
scan_on_start: 'yes'
|
scan_on_start: 'yes'
|
||||||
osquery:
|
osquery:
|
||||||
disable: 'yes'
|
disable: 'yes'
|
||||||
run_daemon: 'yes'
|
run_daemon: 'yes'
|
||||||
bin_path_win: 'C:\ProgramData\osquery\osqueryd'
|
bin_path_win: 'C:\Program Files\osquery\osqueryd'
|
||||||
log_path: '/var/log/osquery/osqueryd.results.log'
|
log_path: '/var/log/osquery/osqueryd.results.log'
|
||||||
log_path_win: 'C:\ProgramData\osquery\log\osqueryd.results.log'
|
log_path_win: 'C:\Program Files\osquery\log\osqueryd.results.log'
|
||||||
config_path: '/etc/osquery/osquery.conf'
|
config_path: '/etc/osquery/osquery.conf'
|
||||||
config_path_win: 'C:\ProgramData\osquery\osquery.conf'
|
config_path_win: 'C:\Program Files\osquery\osquery.conf'
|
||||||
add_labels: 'yes'
|
add_labels: 'yes'
|
||||||
syscollector:
|
syscollector:
|
||||||
disable: 'no'
|
disable: 'no'
|
||||||
@ -233,20 +217,24 @@ wazuh_agent_config:
|
|||||||
packages: 'yes'
|
packages: 'yes'
|
||||||
ports_no: 'yes'
|
ports_no: 'yes'
|
||||||
processes: 'yes'
|
processes: 'yes'
|
||||||
|
sca:
|
||||||
|
enabled: 'yes'
|
||||||
|
scan_on_start: 'yes'
|
||||||
|
interval: '12h'
|
||||||
|
skip_nfs: 'yes'
|
||||||
|
day: ''
|
||||||
|
wday: ''
|
||||||
|
time: ''
|
||||||
cis_cat:
|
cis_cat:
|
||||||
disable: 'yes'
|
disable: 'yes'
|
||||||
install_java: 'yes'
|
install_java: 'no'
|
||||||
timeout: 1800
|
timeout: 1800
|
||||||
interval: '1d'
|
interval: '1d'
|
||||||
scan_on_start: 'yes'
|
scan_on_start: 'yes'
|
||||||
java_path: '/usr/lib/jvm/java-1.8.0-openjdk-amd64/jre/bin'
|
java_path: 'wodles/java'
|
||||||
java_path_win: '\\server\jre\bin\java.exe'
|
java_path_win: '\\server\jre\bin\java.exe'
|
||||||
ciscat_path: '/var/ossec/wodles/ciscat'
|
ciscat_path: 'wodles/ciscat'
|
||||||
ciscat_path_win: 'C:\cis-cat'
|
ciscat_path_win: 'C:\cis-cat'
|
||||||
content:
|
|
||||||
- type: 'xccdf'
|
|
||||||
path: 'benchmarks/CIS_Ubuntu_Linux_16.04_LTS_Benchmark_v1.0.0-xccdf.xml'
|
|
||||||
profile: 'xccdf_org.cisecurity.benchmarks_profile_Level_1_-_Server'
|
|
||||||
vuls:
|
vuls:
|
||||||
disable: 'yes'
|
disable: 'yes'
|
||||||
interval: '1d'
|
interval: '1d'
|
||||||
@ -279,16 +267,16 @@ wazuh_agent_config:
|
|||||||
linux:
|
linux:
|
||||||
- format: 'syslog'
|
- format: 'syslog'
|
||||||
location: '/var/ossec/logs/active-responses.log'
|
location: '/var/ossec/logs/active-responses.log'
|
||||||
- format: 'command'
|
|
||||||
command: df -P -x squashfs -x tmpfs -x devtmpfs
|
|
||||||
frequency: '360'
|
|
||||||
- format: 'full_command'
|
|
||||||
command: ss -nutal | awk '{print $1,$5,$6;}' | sort -b | column -t
|
|
||||||
alias: 'netstat listening ports'
|
|
||||||
frequency: '360'
|
|
||||||
- format: 'full_command'
|
- format: 'full_command'
|
||||||
command: 'last -n 20'
|
command: 'last -n 20'
|
||||||
frequency: '360'
|
frequency: '360'
|
||||||
|
- format: 'command'
|
||||||
|
command: df -P
|
||||||
|
frequency: '360'
|
||||||
|
- format: 'full_command'
|
||||||
|
command: netstat -tulpn | sed 's/\([[:alnum:]]\+\)\ \+[[:digit:]]\+\ \+[[:digit:]]\+\ \+\(.*\):\([[:digit:]]*\)\ \+\([0-9\.\:\*]\+\).\+\ \([[:digit:]]*\/[[:alnum:]\-]*\).*/\1 \2 == \3 == \4 \5/' | sort -k 4 -g | sed 's/ == \(.*\) ==/:\1/' | sed 1,2d
|
||||||
|
alias: 'netstat listening ports'
|
||||||
|
frequency: '360'
|
||||||
windows:
|
windows:
|
||||||
- format: 'eventlog'
|
- format: 'eventlog'
|
||||||
location: 'Application'
|
location: 'Application'
|
||||||
@ -304,3 +292,4 @@ wazuh_agent_config:
|
|||||||
list:
|
list:
|
||||||
- key: Env
|
- key: Env
|
||||||
value: Production
|
value: Production
|
||||||
|
wazuh_agent_nat: false
|
||||||
|
|||||||
@ -2,5 +2,5 @@
|
|||||||
- name: restart wazuh-agent
|
- name: restart wazuh-agent
|
||||||
service: name=wazuh-agent state=restarted enabled=yes
|
service: name=wazuh-agent state=restarted enabled=yes
|
||||||
|
|
||||||
- name: restart wazuh-agent windows
|
- name: Windows | Restart Wazuh Agent
|
||||||
win_service: name=OssecSvc start_mode=auto state=restarted
|
win_service: name=OssecSvc start_mode=auto state=restarted
|
||||||
|
|||||||
@ -20,17 +20,27 @@
|
|||||||
when:
|
when:
|
||||||
- ansible_distribution == "Ubuntu"
|
- ansible_distribution == "Ubuntu"
|
||||||
- ansible_distribution_major_version | int == 14
|
- ansible_distribution_major_version | int == 14
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_agent_enabled
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Installing Wazuh repository key
|
- name: Debian/Ubuntu | Installing Wazuh repository key
|
||||||
apt_key: url=https://packages.wazuh.com/key/GPG-KEY-WAZUH
|
apt_key:
|
||||||
|
url: "{{ wazuh_agent_config.repo.gpg }}"
|
||||||
|
id: "{{ wazuh_agent_config.repo.key_id }}"
|
||||||
when:
|
when:
|
||||||
- not (ansible_distribution == "Ubuntu" and ansible_distribution_major_version | int == 14)
|
- not (ansible_distribution == "Ubuntu" and ansible_distribution_major_version | int == 14)
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_agent_enabled
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Add Wazuh repositories
|
- name: Debian/Ubuntu | Add Wazuh repositories
|
||||||
apt_repository:
|
apt_repository:
|
||||||
repo: 'deb https://packages.wazuh.com/3.x/apt/ stable main'
|
filename: wazuh_repo
|
||||||
|
repo: "{{ wazuh_agent_config.repo.apt }}"
|
||||||
state: present
|
state: present
|
||||||
update_cache: true
|
update_cache: true
|
||||||
|
when:
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_agent_enabled
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Set Distribution CIS filename for debian
|
- name: Debian/Ubuntu | Set Distribution CIS filename for debian
|
||||||
set_fact:
|
set_fact:
|
||||||
|
|||||||
@ -1,14 +1,40 @@
|
|||||||
---
|
---
|
||||||
- import_tasks: "RedHat.yml"
|
- include_tasks: "RedHat.yml"
|
||||||
when: ansible_os_family == "RedHat"
|
when: ansible_os_family == "RedHat"
|
||||||
|
|
||||||
- import_tasks: "Debian.yml"
|
- include_tasks: "Debian.yml"
|
||||||
when: ansible_os_family == "Debian"
|
when: ansible_os_family == "Debian"
|
||||||
|
|
||||||
- name: Linux | Install wazuh-agent
|
- include_tasks: "installation_from_sources.yml"
|
||||||
package: name=wazuh-agent state=present
|
when:
|
||||||
|
- wazuh_agent_sources_installation.enabled
|
||||||
|
|
||||||
|
- include_tasks: "installation_from_custom_packages.yml"
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_agent_enabled
|
||||||
|
|
||||||
|
- name: Linux CentOS/RedHat | Install wazuh-agent
|
||||||
|
package:
|
||||||
|
name: wazuh-agent-{{ wazuh_agent_version }}
|
||||||
|
state: present
|
||||||
async: 90
|
async: 90
|
||||||
poll: 15
|
poll: 30
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "redhat"
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_agent_enabled
|
||||||
|
tags:
|
||||||
|
- init
|
||||||
|
|
||||||
|
- name: Linux Debian | Install wazuh-agent
|
||||||
|
apt:
|
||||||
|
name: "wazuh-agent={{ wazuh_agent_version }}"
|
||||||
|
state: present
|
||||||
|
cache_valid_time: 3600
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower != "redhat"
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_agent_enabled
|
||||||
tags:
|
tags:
|
||||||
- init
|
- init
|
||||||
when: not ansible_check_mode
|
when: not ansible_check_mode
|
||||||
@ -40,28 +66,39 @@
|
|||||||
- name: Linux | Register agent (via authd)
|
- name: Linux | Register agent (via authd)
|
||||||
shell: >
|
shell: >
|
||||||
/var/ossec/bin/agent-auth
|
/var/ossec/bin/agent-auth
|
||||||
-A {{ agent_name }}
|
{% if wazuh_agent_authd.agent_name is defined and wazuh_agent_authd.agent_name != None %}
|
||||||
-m {{ wazuh_managers.0.address }}
|
-A {{ wazuh_agent_authd.agent_name }}
|
||||||
|
{% endif %}
|
||||||
|
-m {{ wazuh_agent_authd.registration_address }}
|
||||||
-p {{ wazuh_agent_authd.port }}
|
-p {{ wazuh_agent_authd.port }}
|
||||||
{% if authd_pass is defined %}-P {{ authd_pass }}{% endif %}
|
{% if wazuh_agent_nat %} -I "any" {% endif %}
|
||||||
{% if wazuh_agent_authd.ssl_agent_ca is not none %}
|
{% if authd_pass is defined %} -P {{ authd_pass }} {% endif %}
|
||||||
|
{% if wazuh_agent_authd.ssl_agent_ca is defined and wazuh_agent_authd.ssl_agent_ca != None %}
|
||||||
-v "/var/ossec/etc/{{ wazuh_agent_authd.ssl_agent_ca | basename }}"
|
-v "/var/ossec/etc/{{ wazuh_agent_authd.ssl_agent_ca | basename }}"
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_agent_authd.ssl_agent_cert is defined and wazuh_agent_authd.ssl_agent_cert != None %}
|
||||||
-x "/var/ossec/etc/{{ wazuh_agent_authd.ssl_agent_cert | basename }}"
|
-x "/var/ossec/etc/{{ wazuh_agent_authd.ssl_agent_cert | basename }}"
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_agent_authd.ssl_agent_key is defined and wazuh_agent_authd.ssl_agent_key != None %}
|
||||||
-k "/var/ossec/etc/{{ wazuh_agent_authd.ssl_agent_key | basename }}"
|
-k "/var/ossec/etc/{{ wazuh_agent_authd.ssl_agent_key | basename }}"
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if wazuh_agent_authd.ssl_auto_negotiate == 'yes' %}-a{% endif %}
|
{% if wazuh_agent_authd.ssl_auto_negotiate == 'yes' %} -a {% endif %}
|
||||||
|
{% if wazuh_agent_authd.groups is defined and wazuh_agent_authd.groups | length > 0 %}
|
||||||
|
-G "{{ wazuh_agent_authd.groups | join(',') }}"
|
||||||
|
{% endif %}
|
||||||
register: agent_auth_output
|
register: agent_auth_output
|
||||||
|
notify: restart wazuh-agent
|
||||||
vars:
|
vars:
|
||||||
agent_name: "{% if single_agent_name is defined %}{{ single_agent_name }}{% else %}{{ ansible_hostname }}{% endif %}"
|
agent_name: "{% if single_agent_name is defined %}{{ single_agent_name }}{% else %}{{ ansible_hostname }}{% endif %}"
|
||||||
when:
|
when:
|
||||||
- not check_keys.stat.exists or check_keys.stat.size == 0
|
- not check_keys.stat.exists or check_keys.stat.size == 0
|
||||||
- wazuh_managers.0.address is not none
|
- wazuh_agent_authd.registration_address is not none
|
||||||
|
|
||||||
- name: Linux | Verify agent registration
|
- name: Linux | Verify agent registration
|
||||||
shell: echo {{ agent_auth_output }} | grep "Valid key created"
|
shell: echo {{ agent_auth_output }} | grep "Valid key created"
|
||||||
when:
|
when:
|
||||||
- not check_keys.stat.exists or check_keys.stat.size == 0
|
- not check_keys.stat.exists or check_keys.stat.size == 0
|
||||||
- wazuh_managers.0.address is not none
|
- wazuh_agent_authd.registration_address is not none
|
||||||
|
|
||||||
when: wazuh_agent_authd.enable
|
when: wazuh_agent_authd.enable
|
||||||
tags:
|
tags:
|
||||||
@ -76,7 +113,7 @@
|
|||||||
|
|
||||||
- name: Linux | Create the agent key via rest-API
|
- name: Linux | Create the agent key via rest-API
|
||||||
uri:
|
uri:
|
||||||
url: "{{ wazuh_managers.0.api_proto }}://{{ wazuh_managers.0.address }}:{{ wazuh_managers.0.api_port }}/agents/"
|
url: "{{ wazuh_managers.0.api_proto }}://{{ wazuh_agent_authd.registration_address }}:{{ wazuh_managers.0.api_port }}/agents/"
|
||||||
validate_certs: false
|
validate_certs: false
|
||||||
method: POST
|
method: POST
|
||||||
body: '{"name":"{{ agent_name }}"}'
|
body: '{"name":"{{ agent_name }}"}'
|
||||||
@ -87,18 +124,21 @@
|
|||||||
user: "{{ wazuh_managers.0.api_user }}"
|
user: "{{ wazuh_managers.0.api_user }}"
|
||||||
password: "{{ api_pass }}"
|
password: "{{ api_pass }}"
|
||||||
register: newagent_api
|
register: newagent_api
|
||||||
|
notify: restart wazuh-agent
|
||||||
# changed_when: newagent_api.json.error == 0
|
# changed_when: newagent_api.json.error == 0
|
||||||
vars:
|
vars:
|
||||||
agent_name: "{% if single_agent_name is defined %}{{ single_agent_name }}{% else %}{{ inventory_hostname }}{% endif %}"
|
agent_name: "{% if single_agent_name is defined %}{{ single_agent_name }}{% else %}{{ inventory_hostname }}{% endif %}"
|
||||||
when:
|
when:
|
||||||
- not check_keys.stat.exists or check_keys.stat.size == 0
|
- not check_keys.stat.exists or check_keys.stat.size == 0
|
||||||
- wazuh_managers.0.address is not none
|
- wazuh_agent_authd.registration_address is not none
|
||||||
become: false
|
become: false
|
||||||
ignore_errors: true
|
ignore_errors: true
|
||||||
|
|
||||||
- name: Linux | Retieve new agent data via rest-API
|
- name: Linux | Retieve new agent data via rest-API
|
||||||
uri:
|
uri:
|
||||||
url: "{{ wazuh_managers.0.api_proto }}://{{ wazuh_managers.0.address }}:{{ wazuh_managers.0.api_port }}/agents/{{ newagent_api.json.data.id }}"
|
url: >-
|
||||||
|
"{{ wazuh_managers.0.api_proto }}://{{ wazuh_agent_authd.registration_address
|
||||||
|
}}:{{ wazuh_managers.0.api_port }}/agents/{{ newagent_api.json.data.id }}"
|
||||||
validate_certs: false
|
validate_certs: false
|
||||||
method: GET
|
method: GET
|
||||||
return_content: true
|
return_content: true
|
||||||
@ -106,7 +146,7 @@
|
|||||||
password: "{{ api_pass }}"
|
password: "{{ api_pass }}"
|
||||||
when:
|
when:
|
||||||
- not check_keys.stat.exists or check_keys.stat.size == 0
|
- not check_keys.stat.exists or check_keys.stat.size == 0
|
||||||
- wazuh_managers.0.address is not none
|
- wazuh_agent_authd.registration_address is not none
|
||||||
- newagent_api.json.error == 0
|
- newagent_api.json.error == 0
|
||||||
register: newagentdata_api
|
register: newagentdata_api
|
||||||
delegate_to: localhost
|
delegate_to: localhost
|
||||||
@ -117,14 +157,14 @@
|
|||||||
environment:
|
environment:
|
||||||
OSSEC_ACTION: i
|
OSSEC_ACTION: i
|
||||||
OSSEC_AGENT_NAME: '{{ newagentdata_api.json.data.name }}'
|
OSSEC_AGENT_NAME: '{{ newagentdata_api.json.data.name }}'
|
||||||
OSSEC_AGENT_IP: '{{ newagentdata_api.json.data.ip }}'
|
OSSEC_AGENT_IP: '{% if wazuh_agent_nat %}any{% else %}{{ newagentdata_api.json.data.ip }}{% endif %}'
|
||||||
OSSEC_AGENT_ID: '{{ newagent_api.json.data.id }}'
|
OSSEC_AGENT_ID: '{{ newagent_api.json.data.id }}'
|
||||||
OSSEC_AGENT_KEY: '{{ newagent_api.json.data.key }}'
|
OSSEC_AGENT_KEY: '{{ newagent_api.json.data.key }}'
|
||||||
OSSEC_ACTION_CONFIRMED: y
|
OSSEC_ACTION_CONFIRMED: y
|
||||||
register: manage_agents_output
|
register: manage_agents_output
|
||||||
when:
|
when:
|
||||||
- not check_keys.stat.exists or check_keys.stat.size == 0
|
- not check_keys.stat.exists or check_keys.stat.size == 0
|
||||||
- wazuh_managers.0.address is not none
|
- wazuh_agent_authd.registration_address is not none
|
||||||
- newagent_api.changed
|
- newagent_api.changed
|
||||||
notify: restart wazuh-agent
|
notify: restart wazuh-agent
|
||||||
|
|
||||||
@ -174,9 +214,14 @@
|
|||||||
name: wazuh-agent
|
name: wazuh-agent
|
||||||
enabled: true
|
enabled: true
|
||||||
state: started
|
state: started
|
||||||
|
tags: config
|
||||||
|
|
||||||
- import_tasks: "RMRedHat.yml"
|
- include_tasks: "RMRedHat.yml"
|
||||||
when: ansible_os_family == "RedHat"
|
when:
|
||||||
|
- ansible_os_family == "RedHat"
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
|
||||||
- import_tasks: "RMDebian.yml"
|
- include_tasks: "RMDebian.yml"
|
||||||
when: ansible_os_family == "Debian"
|
when:
|
||||||
|
- ansible_os_family == "Debian"
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
|||||||
@ -1,36 +1,31 @@
|
|||||||
---
|
---
|
||||||
- name: RedHat/CentOS/Fedora | Install Wazuh repo
|
|
||||||
yum_repository:
|
|
||||||
name: wazuh_repo
|
|
||||||
description: Wazuh repository
|
|
||||||
baseurl: https://packages.wazuh.com/3.x/yum/
|
|
||||||
gpgkey: https://packages.wazuh.com/key/GPG-KEY-WAZUH
|
|
||||||
gpgcheck: true
|
|
||||||
changed_when: false
|
|
||||||
when:
|
|
||||||
- ansible_distribution_major_version|int > 5
|
|
||||||
|
|
||||||
- name: RedHat/CentOS 5 | Install Wazuh repo
|
- name: RedHat/CentOS 5 | Install Wazuh repo
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: wazuh_repo
|
name: wazuh_repo
|
||||||
description: Wazuh repository
|
description: Wazuh repository
|
||||||
baseurl: https://packages.wazuh.com/3.x/yum/5/
|
baseurl: "{{ wazuh_agent_config.repo.yum }}5/"
|
||||||
gpgkey: https://packages.wazuh.com/key/GPG-KEY-WAZUH-5
|
gpgkey: "{{ wazuh_agent_config.repo.gpg }}-5"
|
||||||
gpgcheck: true
|
gpgcheck: true
|
||||||
changed_when: false
|
changed_when: false
|
||||||
when:
|
when:
|
||||||
- ansible_distribution_major_version|int == 5
|
- (ansible_facts['os_family']|lower == 'redhat') and (ansible_distribution|lower != 'amazon')
|
||||||
|
- (ansible_distribution_major_version|int <= 5)
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_agent_enabled
|
||||||
|
register: repo_v5_installed
|
||||||
|
|
||||||
- name: AmazonLinux | Install Wazuh repo
|
- name: RedHat/CentOS/Fedora | Install Wazuh repo
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: wazuh_repo
|
name: wazuh_repo
|
||||||
description: Wazuh repository
|
description: Wazuh repository
|
||||||
baseurl: https://packages.wazuh.com/3.x/yum/
|
baseurl: "{{ wazuh_agent_config.repo.yum }}"
|
||||||
gpgkey: https://packages.wazuh.com/key/GPG-KEY-WAZUH
|
gpgkey: "{{ wazuh_agent_config.repo.gpg }}"
|
||||||
gpgcheck: true
|
gpgcheck: true
|
||||||
changed_when: false
|
changed_when: false
|
||||||
when:
|
when:
|
||||||
- ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA"
|
- repo_v5_installed is skipped
|
||||||
|
- not wazuh_agent_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_agent_enabled
|
||||||
|
|
||||||
- name: RedHat/CentOS/Fedora | download Oracle Java RPM
|
- name: RedHat/CentOS/Fedora | download Oracle Java RPM
|
||||||
get_url:
|
get_url:
|
||||||
|
|||||||
@ -4,54 +4,53 @@
|
|||||||
path: C:\Program Files (x86)
|
path: C:\Program Files (x86)
|
||||||
register: check_path
|
register: check_path
|
||||||
|
|
||||||
- name: "Set Win Path"
|
- name: Windows | Set Win Path (x86)
|
||||||
set_fact:
|
set_fact:
|
||||||
wazuh_agent_win_path: "{% wazuh_winagent_config.install_dir_x86 if check_path.stat.exists else wazuh_winagent_config.install_dir %}"
|
wazuh_agent_win_path: "{{ wazuh_winagent_config.install_dir_x86 }}"
|
||||||
|
wazuh_agent_win_auth_path: "{{ wazuh_winagent_config.auth_path_x86 }}"
|
||||||
- name: Windows | Get current installed version
|
|
||||||
win_shell: "{% if check_path.stat.exists %}{{ wazuh_winagent_config.install_dir_x86 }}{% else %}
|
|
||||||
{{ wazuh_winagent_config.install_dir }}{% endif %}ossec-agent.exe -h"
|
|
||||||
args:
|
|
||||||
removes: "{% if check_path.stat.exists %}{{ wazuh_winagent_config.install_dir_x86 }}{% else %}
|
|
||||||
{{ wazuh_winagent_config.install_dir }}{% endif %}ossec-agent.exe"
|
|
||||||
register: agent_version
|
|
||||||
failed_when: false
|
|
||||||
changed_when: false
|
|
||||||
|
|
||||||
- name: Windows | Check Wazuh agent version installed
|
|
||||||
set_fact: correct_version=true
|
|
||||||
when:
|
when:
|
||||||
- agent_version.stdout is defined
|
- check_path.stat.exists
|
||||||
- wazuh_winagent_config.version in agent_version.stdout
|
|
||||||
|
|
||||||
- name: Windows | Downloading windows Wazuh agent installer
|
- name: Windows | Set Win Path (x64)
|
||||||
win_get_url:
|
set_fact:
|
||||||
dest: C:\wazuh-agent-installer.msi
|
wazuh_agent_win_path: "{{ wazuh_winagent_config.install_dir }}"
|
||||||
url: "{{ wazuh_winagent_config.repo }}wazuh-agent-{{ wazuh_winagent_config.version }}-{{ wazuh_winagent_config.revision }}.msi"
|
wazuh_agent_win_auth_path: "{{ wazuh_winagent_config.auth_path }}"
|
||||||
when:
|
when:
|
||||||
- correct_version is not defined
|
- not check_path.stat.exists
|
||||||
|
|
||||||
- name: Windows | Verify the downloaded Wazuh agent installer
|
- name: Windows | Check if Wazuh installer is already downloaded
|
||||||
win_stat:
|
win_stat:
|
||||||
path: C:\wazuh-agent-installer.msi
|
path: "{{ wazuh_winagent_config.download_dir }}{{ wazuh_winagent_package_name }}"
|
||||||
|
register: wazuh_package_downloaded
|
||||||
|
|
||||||
|
- name: Windows | Download Wazuh Agent package
|
||||||
|
win_get_url:
|
||||||
|
url: "{{ wazuh_winagent_config_url }}"
|
||||||
|
dest: "{{ wazuh_winagent_config.download_dir }}"
|
||||||
|
when:
|
||||||
|
- not wazuh_package_downloaded.stat.exists
|
||||||
|
|
||||||
|
- name: Windows | Verify the Wazuh Agent installer
|
||||||
|
win_stat:
|
||||||
|
path: "{{ wazuh_winagent_config.download_dir }}{{ wazuh_winagent_package_name }}"
|
||||||
get_checksum: true
|
get_checksum: true
|
||||||
checksum_algorithm: md5
|
checksum_algorithm: md5
|
||||||
register: installer_md5
|
register: wazuh_agent_status
|
||||||
when:
|
|
||||||
- correct_version is not defined
|
|
||||||
failed_when:
|
failed_when:
|
||||||
- installer_md5.stat.checksum != wazuh_winagent_config.md5
|
- wazuh_agent_status.stat.checksum != wazuh_winagent_config.md5
|
||||||
|
|
||||||
- name: Windows | Install Wazuh agent
|
|
||||||
win_package:
|
|
||||||
path: C:\wazuh-agent-installer.msi
|
|
||||||
when:
|
when:
|
||||||
- correct_version is not defined
|
- wazuh_winagent_config.check_md5
|
||||||
|
|
||||||
|
|
||||||
|
- name: Windows | Install Agent if not already installed
|
||||||
|
win_package:
|
||||||
|
path: "{{ wazuh_winagent_config.download_dir }}{{ wazuh_winagent_package_name }}"
|
||||||
|
state: present
|
||||||
|
|
||||||
- name: Windows | Check if client.keys exists
|
- name: Windows | Check if client.keys exists
|
||||||
win_stat: path="{{ wazuh_agent_win_path }}"
|
win_stat:
|
||||||
|
path: "{{ wazuh_agent_win_path }}client.keys"
|
||||||
register: check_windows_key
|
register: check_windows_key
|
||||||
notify: restart wazuh-agent windows
|
|
||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
@ -62,27 +61,30 @@
|
|||||||
|
|
||||||
- name: Windows | Register agent
|
- name: Windows | Register agent
|
||||||
win_shell: >
|
win_shell: >
|
||||||
{% if check_path.stat.exists %}{{ wazuh_winagent_config.auth_path_x86 }}{% else %}
|
{{ wazuh_agent_win_auth_path }}
|
||||||
{{ wazuh_winagent_config.auth_path }}{% endif %}
|
-m {{ wazuh_agent_authd.registration_address }}
|
||||||
-m {{ wazuh_managers.0.address }}
|
|
||||||
-p {{ wazuh_agent_authd.port }}
|
-p {{ wazuh_agent_authd.port }}
|
||||||
|
{% if wazuh_agent_authd.agent_name is defined %}-A {{ wazuh_agent_authd.agent_name }} {% endif %}
|
||||||
{% if authd_pass is defined %} -P {{ authd_pass }}{% endif %}
|
{% if authd_pass is defined %} -P {{ authd_pass }}{% endif %}
|
||||||
args:
|
|
||||||
chdir: "{{ wazuh_agent_win_path }}"
|
|
||||||
register: agent_auth_output
|
register: agent_auth_output
|
||||||
notify: restart wazuh-agent windows
|
notify: Windows | Restart Wazuh Agent
|
||||||
when:
|
when:
|
||||||
- wazuh_agent_authd.enable
|
- wazuh_agent_authd.enable
|
||||||
- not check_windows_key.stat.exists or check_windows_key.stat.size == 0
|
- not check_windows_key.stat.exists or check_windows_key.stat.size == 0
|
||||||
- wazuh_managers.0.address is not none
|
- wazuh_agent_authd.registration_address is not none
|
||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
|
- name: Windows | Check if ossec folder is accessible
|
||||||
|
win_file:
|
||||||
|
path: "{{ wazuh_agent_win_path }}"
|
||||||
|
state: directory
|
||||||
|
|
||||||
- name: Windows | Installing agent configuration (ossec.conf)
|
- name: Windows | Installing agent configuration (ossec.conf)
|
||||||
win_template:
|
template:
|
||||||
src: var-ossec-etc-ossec-agent.conf.j2
|
src: var-ossec-etc-ossec-agent.conf.j2
|
||||||
dest: "{{ wazuh_agent_win_path }}ossec.conf"
|
dest: "{{ wazuh_agent_win_path }}ossec.conf"
|
||||||
notify: restart wazuh-agent windows
|
notify: Windows | Restart Wazuh Agent
|
||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
@ -90,11 +92,11 @@
|
|||||||
win_template:
|
win_template:
|
||||||
src: var-ossec-etc-local-internal-options.conf.j2
|
src: var-ossec-etc-local-internal-options.conf.j2
|
||||||
dest: "{{ wazuh_agent_win_path }}local_internal_options.conf"
|
dest: "{{ wazuh_agent_win_path }}local_internal_options.conf"
|
||||||
notify: restart wazuh-agent windows
|
notify: Windows | Restart Wazuh Agent
|
||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
- name: Windows | Delete downloaded Wazuh agent installer file
|
- name: Windows | Delete downloaded Wazuh agent installer file
|
||||||
win_file:
|
win_file:
|
||||||
path: C:\wazuh-agent-installer.msi
|
path: "{{ wazuh_winagent_config.download_dir }}{{ wazuh_winagent_package_name }}"
|
||||||
state: absent
|
state: absent
|
||||||
|
|||||||
@ -0,0 +1,28 @@
|
|||||||
|
---
|
||||||
|
- name: Install Wazuh Agent from .deb packages
|
||||||
|
apt:
|
||||||
|
deb: "{{ wazuh_custom_packages_installation_agent_deb_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "debian"
|
||||||
|
- wazuh_custom_packages_installation_agent_enabled
|
||||||
|
|
||||||
|
- name: Install Wazuh Agent from .rpm packages | yum
|
||||||
|
yum:
|
||||||
|
name: "{{ wazuh_custom_packages_installation_agent_rpm_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "redhat"
|
||||||
|
- wazuh_custom_packages_installation_agent_enabled
|
||||||
|
- not (ansible_distribution|lower == "centos" and ansible_distribution_major_version >= "8")
|
||||||
|
- not (ansible_distribution|lower == "redhat" and ansible_distribution_major_version >= "8")
|
||||||
|
|
||||||
|
- name: Install Wazuh Agent from .rpm packages | dnf
|
||||||
|
dnf:
|
||||||
|
name: "{{ wazuh_custom_packages_installation_agent_rpm_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "redhat"
|
||||||
|
- wazuh_custom_packages_installation_agent_enabled
|
||||||
|
- (ansible_distribution|lower == "centos" and ansible_distribution_major_version >= "8") or
|
||||||
|
(ansible_distribution|lower == "redhat" and ansible_distribution_major_version >= "8")
|
||||||
@ -0,0 +1,99 @@
|
|||||||
|
---
|
||||||
|
- name: Install dependencies to build Wazuh packages
|
||||||
|
package:
|
||||||
|
name:
|
||||||
|
- make
|
||||||
|
- gcc
|
||||||
|
- automake
|
||||||
|
- autoconf
|
||||||
|
- libtool
|
||||||
|
- tar
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Removing old files
|
||||||
|
file:
|
||||||
|
path: "/tmp/{{ wazuh_agent_sources_installation.branch }}.tar.gz"
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- name: Removing old folders
|
||||||
|
file:
|
||||||
|
path: "/tmp/wazuh-{{ wazuh_agent_sources_installation.branch }}"
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- name: Installing policycoreutils-python (RedHat families)
|
||||||
|
package:
|
||||||
|
name:
|
||||||
|
- policycoreutils-python
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "redhat"
|
||||||
|
|
||||||
|
- name: Installing policycoreutils-python-utils (Debian families)
|
||||||
|
package:
|
||||||
|
name:
|
||||||
|
- libc6-dev
|
||||||
|
- curl
|
||||||
|
- policycoreutils
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "debian"
|
||||||
|
|
||||||
|
- name: Download required packages from github.com/wazuh/wazuh
|
||||||
|
get_url:
|
||||||
|
url: "https://github.com/wazuh/wazuh/archive/{{ wazuh_agent_sources_installation.branch }}.tar.gz"
|
||||||
|
dest: "/tmp/{{ wazuh_agent_sources_installation.branch }}.tar.gz"
|
||||||
|
delegate_to: "{{ inventory_hostname }}"
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Create folder to extract Wazuh branch
|
||||||
|
file:
|
||||||
|
path: "/tmp/wazuh-{{ wazuh_agent_sources_installation.branch }}"
|
||||||
|
state: directory
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Extract downloaded Wazuh branch from Github # Using shell instead of unarchive due to that module not working properlyh with --strip
|
||||||
|
command: >-
|
||||||
|
tar -xzvf /tmp/{{ wazuh_agent_sources_installation.branch }}.tar.gz
|
||||||
|
--strip 1
|
||||||
|
--directory /tmp/wazuh-{{ wazuh_agent_sources_installation.branch }}
|
||||||
|
register: wazuh_untar
|
||||||
|
changed_when: false
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
|
||||||
|
- name: Clean remaining files from others builds
|
||||||
|
command: "make -C src {{ item }}"
|
||||||
|
args:
|
||||||
|
chdir: "/tmp/wazuh-{{ wazuh_agent_sources_installation.branch }}/src/"
|
||||||
|
with_items:
|
||||||
|
- "clean"
|
||||||
|
- "clean-deps"
|
||||||
|
register: clean_result
|
||||||
|
changed_when: clean_result.rc == 0
|
||||||
|
failed_when: false
|
||||||
|
|
||||||
|
- name: Render the "preloaded-vars.conf" file
|
||||||
|
template:
|
||||||
|
src: "templates/preloaded_vars_agent.conf.j2"
|
||||||
|
dest: "/tmp/wazuh-{{ wazuh_agent_sources_installation.branch }}/etc/preloaded-vars.conf"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: 0644
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Executing "install.sh" script to build and install the Wazuh Agent
|
||||||
|
shell: ./install.sh > /tmp/build_agent_log.txt
|
||||||
|
register: installation_result
|
||||||
|
changed_when: installation_result == 0
|
||||||
|
args:
|
||||||
|
chdir: "/tmp/wazuh-{{ wazuh_agent_sources_installation.branch }}"
|
||||||
|
|
||||||
|
- name: Cleanup downloaded files
|
||||||
|
file:
|
||||||
|
path: "/tmp/{{ wazuh_agent_sources_installation.branch }}.tar.gz"
|
||||||
|
state: absent
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Cleanup created folders
|
||||||
|
file:
|
||||||
|
path: "/tmp/wazuh-{{ wazuh_agent_sources_installation.branch }}"
|
||||||
|
state: absent
|
||||||
|
changed_when: false
|
||||||
@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
- import_tasks: "Windows.yml"
|
- include_tasks: "Windows.yml"
|
||||||
when: ansible_os_family == "Windows"
|
when: ansible_os_family == "Windows"
|
||||||
|
|
||||||
- import_tasks: "Linux.yml"
|
- include_tasks: "Linux.yml"
|
||||||
when: ansible_system == "Linux"
|
when: ansible_system == "Linux"
|
||||||
|
|||||||
@ -0,0 +1,7 @@
|
|||||||
|
{% for key, value in wazuh_agent_sources_installation.items() %}
|
||||||
|
{% if "user_" in key %}
|
||||||
|
{% if value is defined and value is not none %}
|
||||||
|
{{ key|upper }}="{{ value }}"
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
@ -1,4 +1,4 @@
|
|||||||
#jinja2: trim_blocks: False
|
#jinja2: lstrip_blocks: True
|
||||||
<!-- {{ ansible_managed }} -->
|
<!-- {{ ansible_managed }} -->
|
||||||
<!--
|
<!--
|
||||||
Wazuh - Agent
|
Wazuh - Agent
|
||||||
@ -8,7 +8,6 @@
|
|||||||
|
|
||||||
<ossec_config>
|
<ossec_config>
|
||||||
<client>
|
<client>
|
||||||
|
|
||||||
{% for manager in wazuh_managers %}
|
{% for manager in wazuh_managers %}
|
||||||
<server>
|
<server>
|
||||||
<address>{{ manager.address }}</address>
|
<address>{{ manager.address }}</address>
|
||||||
@ -20,9 +19,12 @@
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
</server>
|
</server>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
{% if wazuh_profile_centos is not none or wazuh_profile_ubuntu is not none %}
|
||||||
{% if wazuh_profile is not none %}
|
{% if ansible_distribution == 'CentOS' %}
|
||||||
<config-profile>{{ wazuh_profile }}</config-profile>
|
<config-profile>{{ wazuh_profile_centos }}</config-profile>
|
||||||
|
{% elif ansible_distribution == "Ubuntu" %}
|
||||||
|
<config-profile>{{ wazuh_profile_ubuntu }}</config-profile>
|
||||||
|
{% endif %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if wazuh_notify_time is not none and wazuh_time_reconnect is not none %}
|
{% if wazuh_notify_time is not none and wazuh_time_reconnect is not none %}
|
||||||
<notify_time>{{ wazuh_notify_time }}</notify_time>
|
<notify_time>{{ wazuh_notify_time }}</notify_time>
|
||||||
@ -31,27 +33,18 @@
|
|||||||
<auto_restart>{{ wazuh_auto_restart }}</auto_restart>
|
<auto_restart>{{ wazuh_auto_restart }}</auto_restart>
|
||||||
<crypto_method>{{ wazuh_crypto_method }}</crypto_method>
|
<crypto_method>{{ wazuh_crypto_method }}</crypto_method>
|
||||||
</client>
|
</client>
|
||||||
|
|
||||||
<client_buffer>
|
<client_buffer>
|
||||||
<!-- Agent buffer options -->
|
<!-- Agent buffer options -->
|
||||||
<disabled>{{ wazuh_agent_config.client_buffer.disable }}</disabled>
|
<disabled>{{ wazuh_agent_config.client_buffer.disable }}</disabled>
|
||||||
<queue_size>{{ wazuh_agent_config.client_buffer.queue_size }}</queue_size>
|
<queue_size>{{ wazuh_agent_config.client_buffer.queue_size }}</queue_size>
|
||||||
<events_per_second>{{ wazuh_agent_config.client_buffer.events_per_sec }}</events_per_second>
|
<events_per_second>{{ wazuh_agent_config.client_buffer.events_per_sec }}</events_per_second>
|
||||||
</client_buffer>
|
</client_buffer>
|
||||||
<logging>
|
|
||||||
<log_format>{{ wazuh_agent_config.log_format }}</log_format>
|
|
||||||
</logging>
|
|
||||||
|
|
||||||
<active-response>
|
|
||||||
<disabled>{{ wazuh_agent_config.active_response.ar|default('no') }}</disabled>
|
|
||||||
<ca_store>{% if ansible_os_family == "Windows" %}{{ wazuh_agent_config.active_response.ca_store_win }}{% else %}{{ wazuh_agent_config.active_response.ca_store }}{% endif %}</ca_store>
|
|
||||||
<ca_verification>{{ wazuh_agent_config.active_response.ca_verification }}</ca_verification>
|
|
||||||
</active-response>
|
|
||||||
|
|
||||||
{% if wazuh_agent_config.rootcheck is defined %}
|
{% if wazuh_agent_config.rootcheck is defined %}
|
||||||
<rootcheck>
|
<rootcheck>
|
||||||
<disabled>no</disabled>
|
<disabled>no</disabled>
|
||||||
{% if ansible_system == "Linux" %}
|
{% if ansible_system == "Linux" %}
|
||||||
<check_unixaudit>yes</check_unixaudit>
|
|
||||||
<check_files>yes</check_files>
|
<check_files>yes</check_files>
|
||||||
<check_trojans>yes</check_trojans>
|
<check_trojans>yes</check_trojans>
|
||||||
<check_dev>yes</check_dev>
|
<check_dev>yes</check_dev>
|
||||||
@ -65,16 +58,9 @@
|
|||||||
|
|
||||||
<rootkit_files>/var/ossec/etc/shared/rootkit_files.txt</rootkit_files>
|
<rootkit_files>/var/ossec/etc/shared/rootkit_files.txt</rootkit_files>
|
||||||
<rootkit_trojans>/var/ossec/etc/shared/rootkit_trojans.txt</rootkit_trojans>
|
<rootkit_trojans>/var/ossec/etc/shared/rootkit_trojans.txt</rootkit_trojans>
|
||||||
<system_audit>/var/ossec/etc/shared/system_audit_rcl.txt</system_audit>
|
|
||||||
<system_audit>/var/ossec/etc/shared/system_audit_ssh.txt</system_audit>
|
|
||||||
{% if cis_distribution_filename is defined %}
|
|
||||||
<system_audit>/var/ossec/etc/shared/{{ cis_distribution_filename }}</system_audit>
|
|
||||||
{% endif %}
|
|
||||||
<skip_nfs>yes</skip_nfs>
|
<skip_nfs>yes</skip_nfs>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
{% if ansible_os_family == "Windows" %}
|
{% if ansible_os_family == "Windows" %}
|
||||||
<windows_audit>./shared/win_audit_rcl.txt</windows_audit>
|
|
||||||
<windows_apps>./shared/win_applications_rcl.txt</windows_apps>
|
<windows_apps>./shared/win_applications_rcl.txt</windows_apps>
|
||||||
<windows_malware>./shared/win_malware_rcl.txt</windows_malware>
|
<windows_malware>./shared/win_malware_rcl.txt</windows_malware>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
@ -82,95 +68,10 @@
|
|||||||
</rootcheck>
|
</rootcheck>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
<!-- Directories to check (perform all possible verifications) -->
|
|
||||||
{% if wazuh_agent_config.syscheck is defined %}
|
|
||||||
<syscheck>
|
|
||||||
<disabled>no</disabled>
|
|
||||||
<!-- #<alert_new_files>{{ wazuh_agent_config.syscheck.alert_new_files }}</alert_new_files> -->
|
|
||||||
<!-- Frequency that syscheck is executed -- default every 20 hours -->
|
|
||||||
<frequency>{{ wazuh_agent_config.syscheck.frequency }}</frequency>
|
|
||||||
{% if ansible_system == "Linux" %}
|
|
||||||
<!-- #<directories check_all="yes" realtime="yes" restrict="^/var/ossec/etc/shared/agent.conf$">/var/ossec/etc/shared</directories> -->
|
|
||||||
<directories check_all="yes">/etc,/usr/bin,/usr/sbin</directories>
|
|
||||||
<directories check_all="yes">/bin,/sbin,/boot</directories>
|
|
||||||
|
|
||||||
<auto_ignore>{{ wazuh_agent_config.syscheck.auto_ignore }}</auto_ignore>
|
{% if ansible_system == "Linux" %}
|
||||||
<scan_on_start>{{ wazuh_agent_config.syscheck.scan_on_start }}</scan_on_start>
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
<!-- Directories to check (perform all possible verifications) -->
|
|
||||||
{% if wazuh_agent_config.syscheck.directories is defined and ansible_os_family == "Linux" %}
|
|
||||||
{% for directory in wazuh_agent_config.syscheck.directories %}
|
|
||||||
<directories {{ directory.checks }}>{{ directory.dirs }}</directories>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
<!-- Directories to check (perform all possible verifications) -->
|
|
||||||
{% if wazuh_agent_config.syscheck.win_directories is defined and ansible_os_family == "Windows" %}
|
|
||||||
{% for directory in wazuh_agent_config.syscheck.win_directories %}
|
|
||||||
<directories {{ directory.checks }}>{{ directory.dirs }}</directories>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
<!-- Files/directories to ignore -->
|
|
||||||
{% if wazuh_agent_config.syscheck.ignore is defined and ansible_system == "Linux" %}
|
|
||||||
{% for ignore in wazuh_agent_config.syscheck.ignore %}
|
|
||||||
<ignore>{{ ignore }}</ignore>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if wazuh_agent_config.syscheck.ignore is defined and ansible_system == "Windows" %}
|
|
||||||
{% for ignore in wazuh_agent_config.syscheck.ignore_win %}
|
|
||||||
<ignore type="sregex">{{ ignore }}</ignore>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if ansible_system == "Linux" %}
|
|
||||||
<!-- Files no diff -->
|
|
||||||
{% for no_diff in wazuh_agent_config.syscheck.no_diff %}
|
|
||||||
<nodiff>{{ no_diff }}</nodiff>
|
|
||||||
{% endfor %}
|
|
||||||
|
|
||||||
<skip_nfs>{{ wazuh_agent_config.syscheck.skip_nfs }}</skip_nfs>
|
|
||||||
{% endif %}
|
|
||||||
<!-- Remove not monitored files -->
|
|
||||||
<remove_old_diff>{{ wazuh_agent_config.syscheck.remove_old_diff }}</remove_old_diff>
|
|
||||||
|
|
||||||
{% if ansible_system == "Linux"%}
|
|
||||||
<!-- Allow the system to restart Auditd after installing the plugin -->
|
|
||||||
<restart_audit>{{ wazuh_agent_config.syscheck.restart_audit }}</restart_audit>
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if ansible_os_family == "Windows" %}
|
|
||||||
{% for registry_key in wazuh_agent_config.syscheck.windows_registry %}
|
|
||||||
{% if registry_key.arch is defined %}
|
|
||||||
<windows_registry arch="{{ registry_key.arch }}">{{ registry_key.key }}</windows_registry>
|
|
||||||
{% else %}
|
|
||||||
<windows_registry>{{ registry_key.key }}</windows_registry>
|
|
||||||
{% endif %}
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if ansible_os_family == "Windows" %}
|
|
||||||
{% for registry_key in wazuh_agent_config.syscheck.windows_registry_ignore %}
|
|
||||||
{% if registry_key.type is defined %}
|
|
||||||
<registry_ignore type="{{ registry_key.type }}">{{ registry_key.key }}</registry_ignore>
|
|
||||||
{% else %}
|
|
||||||
<registry_ignore>{{ registry_key.key }}</registry_ignore>
|
|
||||||
{% endif %}
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if ansible_os_family == "Windows" %}
|
|
||||||
<!-- Frequency for ACL checking (seconds) -->
|
|
||||||
<windows_audit_interval>{{ wazuh_agent_config.syscheck.win_audit_interval }}</windows_audit_interval>
|
|
||||||
{% endif %}
|
|
||||||
</syscheck>
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if ansible_system == "Linux" and wazuh_agent_config.openscap.disable == 'no' %}
|
|
||||||
<wodle name="open-scap">
|
<wodle name="open-scap">
|
||||||
<disabled>no</disabled>
|
<disabled>{{ wazuh_agent_config.openscap.disable }}</disabled>
|
||||||
<timeout>{{ wazuh_agent_config.openscap.timeout }}</timeout>
|
<timeout>{{ wazuh_agent_config.openscap.timeout }}</timeout>
|
||||||
<interval>{{ wazuh_agent_config.openscap.interval }}</interval>
|
<interval>{{ wazuh_agent_config.openscap.interval }}</interval>
|
||||||
<scan-on-start>{{ wazuh_agent_config.openscap.scan_on_start }}</scan-on-start>
|
<scan-on-start>{{ wazuh_agent_config.openscap.scan_on_start }}</scan-on-start>
|
||||||
@ -190,23 +91,33 @@
|
|||||||
<content type="oval" path="cve-debian-9-oval.xml"/>
|
<content type="oval" path="cve-debian-9-oval.xml"/>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% elif ansible_distribution == 'CentOS' %}
|
{% elif ansible_distribution == 'CentOS' %}
|
||||||
{% if ansible_distribution_major_version == '7' %}
|
{% if ansible_distribution_major_version == '8' %}
|
||||||
|
{# Policy not available #}
|
||||||
|
{% elif ansible_distribution_major_version == '7' %}
|
||||||
<content type="xccdf" path="ssg-centos-7-ds.xml">
|
<content type="xccdf" path="ssg-centos-7-ds.xml">
|
||||||
|
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
||||||
|
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
||||||
|
</content>
|
||||||
{% elif ansible_distribution_major_version == '6' %}
|
{% elif ansible_distribution_major_version == '6' %}
|
||||||
<content type="xccdf" path="ssg-centos-6-ds.xml">
|
<content type="xccdf" path="ssg-centos-6-ds.xml">
|
||||||
{% endif %}
|
|
||||||
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
||||||
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
||||||
</content>
|
</content>
|
||||||
|
{% endif %}
|
||||||
{% elif ansible_distribution == 'RedHat' %}
|
{% elif ansible_distribution == 'RedHat' %}
|
||||||
{% if ansible_distribution_major_version == '7' %}
|
{% if ansible_distribution_major_version == '8' %}
|
||||||
|
{# Policy not available #}
|
||||||
|
{% elif ansible_distribution_major_version == '7' %}
|
||||||
<content type="xccdf" path="ssg-rhel-7-ds.xml">
|
<content type="xccdf" path="ssg-rhel-7-ds.xml">
|
||||||
|
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
||||||
|
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
||||||
|
</content>
|
||||||
{% elif ansible_distribution_major_version == '6' %}
|
{% elif ansible_distribution_major_version == '6' %}
|
||||||
<content type="xccdf" path="ssg-rhel-6-ds.xml">
|
<content type="xccdf" path="ssg-rhel-6-ds.xml">
|
||||||
{% endif %}
|
|
||||||
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
||||||
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
||||||
</content>
|
</content>
|
||||||
|
{% endif %}
|
||||||
{% if ansible_distribution_major_version == '7' %}
|
{% if ansible_distribution_major_version == '7' %}
|
||||||
<content type="oval" path="cve-redhat-7-ds.xml"/>
|
<content type="oval" path="cve-redhat-7-ds.xml"/>
|
||||||
{% elif ansible_distribution_major_version == '6' %}
|
{% elif ansible_distribution_major_version == '6' %}
|
||||||
@ -221,9 +132,8 @@
|
|||||||
</wodle>
|
</wodle>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
{% if wazuh_agent_config.cis_cat.disable == 'no' %}
|
|
||||||
<wodle name="cis-cat">
|
<wodle name="cis-cat">
|
||||||
<disabled>no</disabled>
|
<disabled>{{ wazuh_agent_config.cis_cat.disable }}</disabled>
|
||||||
<timeout>{{ wazuh_agent_config.cis_cat.timeout }}</timeout>
|
<timeout>{{ wazuh_agent_config.cis_cat.timeout }}</timeout>
|
||||||
<interval>{{ wazuh_agent_config.cis_cat.interval }}</interval>
|
<interval>{{ wazuh_agent_config.cis_cat.interval }}</interval>
|
||||||
<scan-on-start>{{ wazuh_agent_config.cis_cat.scan_on_start }}</scan-on-start>
|
<scan-on-start>{{ wazuh_agent_config.cis_cat.scan_on_start }}</scan-on-start>
|
||||||
@ -235,15 +145,7 @@
|
|||||||
<java_path>{{ wazuh_agent_config.cis_cat.java_path }}</java_path>
|
<java_path>{{ wazuh_agent_config.cis_cat.java_path }}</java_path>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
<ciscat_path>{% if ansible_os_family == "Windows" %}{{ wazuh_agent_config.cis_cat.ciscat_path_win }}{% else %}{{ wazuh_agent_config.cis_cat.ciscat_path }}{% endif %}</ciscat_path>
|
<ciscat_path>{% if ansible_os_family == "Windows" %}{{ wazuh_agent_config.cis_cat.ciscat_path_win }}{% else %}{{ wazuh_agent_config.cis_cat.ciscat_path }}{% endif %}</ciscat_path>
|
||||||
{% if ansible_system == "Linux" %}
|
|
||||||
{% for benchmark in wazuh_agent_config.cis_cat.content %}
|
|
||||||
<content type="{{ benchmark.type }}" path="{{ benchmark.path }}">
|
|
||||||
<profile>{{ benchmark.profile }}</profile>
|
|
||||||
</content>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
</wodle>
|
</wodle>
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
<!-- Osquery integration -->
|
<!-- Osquery integration -->
|
||||||
<wodle name="osquery">
|
<wodle name="osquery">
|
||||||
@ -270,6 +172,126 @@
|
|||||||
<processes>{{ wazuh_agent_config.syscollector.processes }}</processes>
|
<processes>{{ wazuh_agent_config.syscollector.processes }}</processes>
|
||||||
</wodle>
|
</wodle>
|
||||||
|
|
||||||
|
<sca>
|
||||||
|
{% if wazuh_agent_config.sca.enabled | length > 0 %}
|
||||||
|
<enabled>{{ wazuh_agent_config.sca.enabled }}</enabled>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_agent_config.sca.scan_on_start | length > 0 %}
|
||||||
|
<scan_on_start>{{ wazuh_agent_config.sca.scan_on_start }}</scan_on_start>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_agent_config.sca.interval | length > 0 %}
|
||||||
|
<interval>{{ wazuh_agent_config.sca.interval }}</interval>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_agent_config.sca.skip_nfs | length > 0 %}
|
||||||
|
<skip_nfs>yes</skip_nfs>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_agent_config.sca.day | length > 0 %}
|
||||||
|
<day>yes</day>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_agent_config.sca.wday | length > 0 %}
|
||||||
|
<wday>yes</wday>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_agent_config.sca.time | length > 0 %}
|
||||||
|
<time>yes</time>
|
||||||
|
{% endif %}
|
||||||
|
</sca>
|
||||||
|
|
||||||
|
|
||||||
|
<!-- Directories to check (perform all possible verifications) -->
|
||||||
|
{% if wazuh_agent_config.syscheck is defined %}
|
||||||
|
<syscheck>
|
||||||
|
<disabled>no</disabled>
|
||||||
|
<!-- <alert_new_files>{{ wazuh_agent_config.syscheck.alert_new_files }}</alert_new_files> -->
|
||||||
|
<frequency>{{ wazuh_agent_config.syscheck.frequency }}</frequency>
|
||||||
|
{% if ansible_system == "Linux" %}
|
||||||
|
<scan_on_start>{{ wazuh_agent_config.syscheck.scan_on_start }}</scan_on_start>
|
||||||
|
<!-- Directories to check (perform all possible verifications) -->
|
||||||
|
{% if wazuh_agent_config.syscheck.directories is defined and ansible_system == "Linux" %}
|
||||||
|
{% for directory in wazuh_agent_config.syscheck.directories %}
|
||||||
|
<directories {{ directory.checks }}>{{ directory.dirs }}</directories>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
<!-- Directories to check (perform all possible verifications) -->
|
||||||
|
{% if wazuh_agent_config.syscheck.win_directories is defined and ansible_system == "Windows" %}
|
||||||
|
{% for directory in wazuh_agent_config.syscheck.win_directories %}
|
||||||
|
<directories {{ directory.checks }}>{{ directory.dirs }}</directories>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
<!-- Files/directories to ignore -->
|
||||||
|
{% if wazuh_agent_config.syscheck.ignore is defined and ansible_system == "Linux" %}
|
||||||
|
{% for ignore in wazuh_agent_config.syscheck.ignore %}
|
||||||
|
<ignore>{{ ignore }}</ignore>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
<!-- File types to ignore -->
|
||||||
|
{% if wazuh_agent_config.syscheck.ignore_linux_type is defined %}
|
||||||
|
{% for ignore in wazuh_agent_config.syscheck.ignore_linux_type %}
|
||||||
|
<ignore type="sregex">{{ ignore }}</ignore>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
{% if wazuh_agent_config.syscheck.ignore is defined and ansible_system == "Windows" %}
|
||||||
|
{% for ignore in wazuh_agent_config.syscheck.ignore_win %}
|
||||||
|
<ignore type="sregex">{{ ignore }}</ignore>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
{% if ansible_system == "Linux" %}
|
||||||
|
<!-- Files no diff -->
|
||||||
|
{% for no_diff in wazuh_agent_config.syscheck.no_diff %}
|
||||||
|
<nodiff>{{ no_diff }}</nodiff>
|
||||||
|
{% endfor %}
|
||||||
|
|
||||||
|
<skip_nfs>{{ wazuh_agent_config.syscheck.skip_nfs }}</skip_nfs>
|
||||||
|
<skip_dev>{{ wazuh_agent_config.syscheck.skip_dev }}</skip_dev>
|
||||||
|
<skip_proc>{{ wazuh_agent_config.syscheck.skip_proc }}</skip_proc>
|
||||||
|
<skip_sys>{{ wazuh_agent_config.syscheck.skip_sys }}</skip_sys>
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
{% if ansible_os_family == "Windows" %}
|
||||||
|
{% for registry_key in wazuh_agent_config.syscheck.windows_registry %}
|
||||||
|
{% if registry_key.arch is defined %}
|
||||||
|
<windows_registry arch="{{ registry_key.arch }}">{{ registry_key.key }}</windows_registry>
|
||||||
|
{% else %}
|
||||||
|
<windows_registry>{{ registry_key.key }}</windows_registry>
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
{% if ansible_os_family == "Windows" %}
|
||||||
|
{% for registry_key in wazuh_agent_config.syscheck.windows_registry_ignore %}
|
||||||
|
{% if registry_key.type is defined %}
|
||||||
|
<registry_ignore type="{{ registry_key.type }}">{{ registry_key.key }}</registry_ignore>
|
||||||
|
{% else %}
|
||||||
|
<registry_ignore>{{ registry_key.key }}</registry_ignore>
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
{% if ansible_os_family == "Windows" %}
|
||||||
|
<!-- Frequency for ACL checking (seconds) -->
|
||||||
|
<windows_audit_interval>{{ wazuh_agent_config.syscheck.win_audit_interval }}</windows_audit_interval>
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
<!-- Nice value for Syscheck module -->
|
||||||
|
<process_priority>{{ wazuh_agent_config.syscheck.process_priority }}</process_priority>
|
||||||
|
|
||||||
|
<!-- Maximum output throughput -->
|
||||||
|
<max_eps>{{ wazuh_agent_config.syscheck.max_eps }}</max_eps>
|
||||||
|
|
||||||
|
<!-- Database synchronization settings -->
|
||||||
|
<synchronization>
|
||||||
|
<enabled>{{ wazuh_agent_config.syscheck.sync_enabled }}</enabled>
|
||||||
|
<interval>{{ wazuh_agent_config.syscheck.sync_interval }}</interval>
|
||||||
|
<max_interval>{{ wazuh_agent_config.syscheck.sync_max_interval }}</max_interval>
|
||||||
|
<max_eps>{{ wazuh_agent_config.syscheck.sync_max_eps }}</max_eps>
|
||||||
|
</synchronization>
|
||||||
|
</syscheck>
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
|
||||||
{% if ansible_system == "Linux" and wazuh_agent_config.vuls.disable == 'no' %}
|
{% if ansible_system == "Linux" and wazuh_agent_config.vuls.disable == 'no' %}
|
||||||
@ -284,68 +306,72 @@
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
<!-- Files to monitor (localfiles) -->
|
<!-- Files to monitor (localfiles) -->
|
||||||
{% if ansible_system == "Linux" %}
|
{% if ansible_system == "Linux" %}
|
||||||
{% for localfile in wazuh_agent_config.localfiles.linux %}
|
{% for localfile in wazuh_agent_config.localfiles.linux %}
|
||||||
<localfile>
|
|
||||||
<log_format>{{ localfile.format }}</log_format>
|
<localfile>
|
||||||
|
<log_format>{{ localfile.format }}</log_format>
|
||||||
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
||||||
<command>{{ localfile.command }}</command>
|
<command>{{ localfile.command }}</command>
|
||||||
<frequency>{{ localfile.frequency }}</frequency>
|
<frequency>{{ localfile.frequency }}</frequency>
|
||||||
{% if localfile.alias is defined %}
|
{% if localfile.alias is defined %}
|
||||||
<alias>{{ localfile.alias }}</alias>
|
<alias>{{ localfile.alias }}</alias>
|
||||||
{% endif %}
|
|
||||||
{% else %}
|
|
||||||
<location>{{ localfile.location }}</location>
|
|
||||||
{% endif %}
|
{% endif %}
|
||||||
</localfile>
|
{% else %}
|
||||||
|
<location>{{ localfile.location }}</location>
|
||||||
|
{% endif %}
|
||||||
|
</localfile>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
{% if ansible_os_family == "Debian" %}
|
{% if ansible_os_family == "Debian" %}
|
||||||
{% for localfile in wazuh_agent_config.localfiles.debian %}
|
{% for localfile in wazuh_agent_config.localfiles.debian %}
|
||||||
<localfile>
|
|
||||||
<log_format>{{ localfile.format }}</log_format>
|
<localfile>
|
||||||
|
<log_format>{{ localfile.format }}</log_format>
|
||||||
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
||||||
<command>{{ localfile.command }}</command>
|
<command>{{ localfile.command }}</command>
|
||||||
<frequency>{{ localfile.frequency }}</frequency>
|
<frequency>{{ localfile.frequency }}</frequency>
|
||||||
{% if localfile.alias is defined %}
|
{% if localfile.alias is defined %}
|
||||||
<alias>{{ localfile.alias }}</alias>
|
<alias>{{ localfile.alias }}</alias>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% else %}
|
{% else %}
|
||||||
<location>{{ localfile.location }}</location>
|
<location>{{ localfile.location }}</location>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
</localfile>
|
</localfile>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
{% if ansible_os_family == "RedHat" %}
|
{% if ansible_os_family == "RedHat" %}
|
||||||
{% for localfile in wazuh_agent_config.localfiles.centos %}
|
{% for localfile in wazuh_agent_config.localfiles.centos %}
|
||||||
<localfile>
|
|
||||||
<log_format>{{ localfile.format }}</log_format>
|
<localfile>
|
||||||
|
<log_format>{{ localfile.format }}</log_format>
|
||||||
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
||||||
<command>{{ localfile.command }}</command>
|
<command>{{ localfile.command }}</command>
|
||||||
<frequency>{{ localfile.frequency }}</frequency>
|
<frequency>{{ localfile.frequency }}</frequency>
|
||||||
{% if localfile.alias is defined %}
|
{% if localfile.alias is defined %}
|
||||||
<alias>{{ localfile.alias }}</alias>
|
<alias>{{ localfile.alias }}</alias>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% else %}
|
{% else %}
|
||||||
<location>{{ localfile.location }}</location>
|
<location>{{ localfile.location }}</location>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
</localfile>
|
</localfile>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
{% if ansible_os_family == "Windows" %}
|
{% if ansible_os_family == "Windows" %}
|
||||||
{% for localfile in wazuh_agent_config.localfiles.windows %}
|
{% for localfile in wazuh_agent_config.localfiles.windows %}
|
||||||
<localfile>
|
|
||||||
<log_format>{{ localfile.format }}</log_format>
|
<localfile>
|
||||||
{% if localfile.format == 'eventchannel' %}
|
<log_format>{{ localfile.format }}</log_format>
|
||||||
<location>{{ localfile.location }}</location>
|
{% if localfile.format == 'eventchannel' %}
|
||||||
<query>{{ localfile.query}}</query>
|
<location>{{ localfile.location }}</location>
|
||||||
{% else %}
|
<query>{{ localfile.query}}</query>
|
||||||
<location>{{ localfile.location }}</location>
|
{% else %}
|
||||||
{% endif %}
|
<location>{{ localfile.location }}</location>
|
||||||
</localfile>
|
{% endif %}
|
||||||
|
</localfile>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
@ -357,4 +383,14 @@
|
|||||||
</labels>
|
</labels>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
|
<active-response>
|
||||||
|
<disabled>{{ wazuh_agent_config.active_response.ar_disabled|default('no') }}</disabled>
|
||||||
|
<ca_store>{% if ansible_os_family == "Windows" %}{{ wazuh_agent_config.active_response.ca_store_win }}{% else %}{{ wazuh_agent_config.active_response.ca_store }}{% endif %}</ca_store>
|
||||||
|
<ca_verification>{{ wazuh_agent_config.active_response.ca_verification }}</ca_verification>
|
||||||
|
</active-response>
|
||||||
|
|
||||||
|
<logging>
|
||||||
|
<log_format>{{ wazuh_agent_config.log_format }}</log_format>
|
||||||
|
</logging>
|
||||||
|
|
||||||
</ossec_config>
|
</ossec_config>
|
||||||
|
|||||||
@ -20,7 +20,7 @@ This role has some variables which you can or need to override.
|
|||||||
```
|
```
|
||||||
wazuh_manager_fqdn: ~
|
wazuh_manager_fqdn: ~
|
||||||
wazuh_manager_config: []
|
wazuh_manager_config: []
|
||||||
wazuh_agent_configs: []
|
shared_agent_config: []
|
||||||
```
|
```
|
||||||
|
|
||||||
Vault variables
|
Vault variables
|
||||||
@ -157,7 +157,7 @@ wazuh_manager_config:
|
|||||||
level: 6
|
level: 6
|
||||||
timeout: 600
|
timeout: 600
|
||||||
|
|
||||||
wazuh_agent_configs:
|
shared_agent_config:
|
||||||
- type: os
|
- type: os
|
||||||
type_value: linux
|
type_value: linux
|
||||||
frequency_check: 79200
|
frequency_check: 79200
|
||||||
|
|||||||
@ -1,8 +1,70 @@
|
|||||||
---
|
---
|
||||||
|
wazuh_manager_version: 3.12.0-1
|
||||||
|
|
||||||
wazuh_manager_fqdn: "wazuh-server"
|
wazuh_manager_fqdn: "wazuh-server"
|
||||||
wazuh_manager_package_state: latest
|
wazuh_manager_package_state: present
|
||||||
|
|
||||||
|
# Custom packages installation
|
||||||
|
wazuh_custom_packages_installation_manager_enabled: false
|
||||||
|
wazuh_custom_packages_installation_manager_deb_url: "https://s3-us-west-1.amazonaws.com/packages-dev.wazuh.com/warehouse/branches/3.12/deb/var/wazuh-manager_3.12.0-0.3319fimreworksqlite_amd64.deb"
|
||||||
|
wazuh_custom_packages_installation_manager_rpm_url: "https://s3-us-west-1.amazonaws.com/packages-dev.wazuh.com/warehouse/branches/3.12/rpm/var/wazuh-manager-3.12.0-0.3319fimreworksqlite.x86_64.rpm"
|
||||||
|
wazuh_custom_packages_installation_api_enabled: false
|
||||||
|
wazuh_custom_packages_installation_api_deb_url: "https://s3-us-west-1.amazonaws.com/packages-dev.wazuh.com/warehouse/branches/3.12/deb/var/wazuh-api_3.12.0-0.3319fimreworksqlite_amd64.deb"
|
||||||
|
wazuh_custom_packages_installation_api_rpm_url: "https://s3-us-west-1.amazonaws.com/packages-dev.wazuh.com/warehouse/branches/3.12/rpm/var/wazuh-api-3.12.0-0.3319fimreworksqlite.x86_64.rpm"
|
||||||
|
|
||||||
|
# Sources installation
|
||||||
|
wazuh_manager_sources_installation:
|
||||||
|
enabled: false
|
||||||
|
branch: "v3.12.0"
|
||||||
|
user_language: "en"
|
||||||
|
user_no_stop: "y"
|
||||||
|
user_install_type: "server"
|
||||||
|
user_dir: "/var/ossec"
|
||||||
|
user_delete_dir: null
|
||||||
|
user_enable_active_response: null
|
||||||
|
user_enable_syscheck: "y"
|
||||||
|
user_enable_rootcheck: "y"
|
||||||
|
user_enable_openscap: "y"
|
||||||
|
user_enable_authd: "y"
|
||||||
|
user_generate_authd_cert: null
|
||||||
|
user_update: "y"
|
||||||
|
user_binaryinstall: null
|
||||||
|
user_enable_email: "n"
|
||||||
|
user_auto_start: "y"
|
||||||
|
user_email_address: null
|
||||||
|
user_email_smpt: null
|
||||||
|
user_enable_syslog: "n"
|
||||||
|
user_white_list: "n"
|
||||||
|
user_ca_store: null
|
||||||
|
threads: "2"
|
||||||
|
|
||||||
|
wazuh_api_sources_installation:
|
||||||
|
enabled: false
|
||||||
|
branch: "v3.12.0"
|
||||||
|
update: "y"
|
||||||
|
remove: "y"
|
||||||
|
directory: null
|
||||||
|
port: 55000
|
||||||
|
https: "n"
|
||||||
|
authd: null
|
||||||
|
proxy: null
|
||||||
|
country: null
|
||||||
|
state: null
|
||||||
|
locality: null
|
||||||
|
org_name: null
|
||||||
|
org_unit: null
|
||||||
|
common_name: null
|
||||||
|
password: null
|
||||||
|
|
||||||
|
wazuh_api_user:
|
||||||
|
- "foo:$apr1$/axqZYWQ$Xo/nz/IG3PdwV82EnfYKh/"
|
||||||
|
|
||||||
wazuh_manager_config:
|
wazuh_manager_config:
|
||||||
|
repo:
|
||||||
|
apt: 'deb https://packages.wazuh.com/3.x/apt/ stable main'
|
||||||
|
yum: 'https://packages.wazuh.com/3.x/yum/'
|
||||||
|
gpg: 'https://packages.wazuh.com/key/GPG-KEY-WAZUH'
|
||||||
|
key_id: '0DCFCA5547B19D2A6099506096B3EE5F29111145'
|
||||||
json_output: 'yes'
|
json_output: 'yes'
|
||||||
alerts_log: 'yes'
|
alerts_log: 'yes'
|
||||||
logall: 'no'
|
logall: 'no'
|
||||||
@ -33,9 +95,7 @@ wazuh_manager_config:
|
|||||||
port: '1516'
|
port: '1516'
|
||||||
bind_addr: '0.0.0.0'
|
bind_addr: '0.0.0.0'
|
||||||
nodes:
|
nodes:
|
||||||
- '172.17.0.2'
|
- 'manager'
|
||||||
- '172.17.0.3'
|
|
||||||
- '172.17.0.4'
|
|
||||||
hidden: 'no'
|
hidden: 'no'
|
||||||
connection:
|
connection:
|
||||||
- type: 'secure'
|
- type: 'secure'
|
||||||
@ -45,26 +105,29 @@ wazuh_manager_config:
|
|||||||
authd:
|
authd:
|
||||||
enable: true
|
enable: true
|
||||||
port: 1515
|
port: 1515
|
||||||
use_source_ip: 'yes'
|
use_source_ip: 'no'
|
||||||
force_insert: 'yes'
|
force_insert: 'yes'
|
||||||
force_time: 0
|
force_time: 0
|
||||||
purge: 'no'
|
purge: 'yes'
|
||||||
use_password: 'no'
|
use_password: 'no'
|
||||||
|
limit_maxagents: 'yes'
|
||||||
|
ciphers: 'HIGH:!ADH:!EXP:!MD5:!RC4:!3DES:!CAMELLIA:@STRENGTH'
|
||||||
ssl_agent_ca: null
|
ssl_agent_ca: null
|
||||||
ssl_verify_host: 'no'
|
ssl_verify_host: 'no'
|
||||||
ssl_manager_cert: '/var/ossec/etc/sslmanager.cert'
|
ssl_manager_cert: 'sslmanager.cert'
|
||||||
ssl_manager_key: '/var/ossec/etc/sslmanager.key'
|
ssl_manager_key: 'sslmanager.key'
|
||||||
ssl_auto_negotiate: 'no'
|
ssl_auto_negotiate: 'no'
|
||||||
email_notification: 'no'
|
email_notification: 'no'
|
||||||
mail_to:
|
mail_to:
|
||||||
- 'admin@example.net'
|
- 'admin@example.net'
|
||||||
mail_smtp_server: localhost
|
mail_smtp_server: smtp.example.wazuh.com
|
||||||
mail_from: wazuh-server@example.com
|
mail_from: ossecm@example.wazuh.com
|
||||||
mail_maxperhour: 12
|
mail_maxperhour: 12
|
||||||
mail_queue_size: 131072
|
mail_queue_size: 131072
|
||||||
|
email_log_source: 'alerts.log'
|
||||||
extra_emails:
|
extra_emails:
|
||||||
- enable: false
|
- enable: false
|
||||||
mail_to: 'admin@example.net'
|
mail_to: 'recipient@example.wazuh.com'
|
||||||
format: full
|
format: full
|
||||||
level: 7
|
level: 7
|
||||||
event_location: null
|
event_location: null
|
||||||
@ -76,7 +139,7 @@ wazuh_manager_config:
|
|||||||
- enable: false
|
- enable: false
|
||||||
category: 'syscheck'
|
category: 'syscheck'
|
||||||
title: 'Daily report: File changes'
|
title: 'Daily report: File changes'
|
||||||
email_to: 'admin@example.net'
|
email_to: 'recipient@example.wazuh.com'
|
||||||
location: null
|
location: null
|
||||||
group: null
|
group: null
|
||||||
rule: null
|
rule: null
|
||||||
@ -103,26 +166,33 @@ wazuh_manager_config:
|
|||||||
- /etc/cups/certs
|
- /etc/cups/certs
|
||||||
- /etc/dumpdates
|
- /etc/dumpdates
|
||||||
- /etc/svc/volatile
|
- /etc/svc/volatile
|
||||||
- /sys/kernel/security
|
ignore_linux_type:
|
||||||
- /sys/kernel/debug
|
- '.log$|.swp$'
|
||||||
no_diff:
|
no_diff:
|
||||||
- /etc/ssl/private.key
|
- /etc/ssl/private.key
|
||||||
directories:
|
directories:
|
||||||
- dirs: /etc,/usr/bin,/usr/sbin
|
- dirs: /etc,/usr/bin,/usr/sbin
|
||||||
checks: 'check_all="yes"'
|
checks: ''
|
||||||
- dirs: /bin,/sbin,/boot
|
- dirs: /bin,/sbin,/boot
|
||||||
checks: 'check_all="yes"'
|
checks: ''
|
||||||
auto_ignore_frequency:
|
auto_ignore_frequency:
|
||||||
frequency: 'frequency="10"'
|
frequency: 'frequency="10"'
|
||||||
timeframe: 'timeframe="3600"'
|
timeframe: 'timeframe="3600"'
|
||||||
value: 'no'
|
value: 'no'
|
||||||
skip_nfs: 'yes'
|
skip_nfs: 'yes'
|
||||||
remove_old_diff: 'yes'
|
skip_dev: 'yes'
|
||||||
restart_audit: 'yes'
|
skip_proc: 'yes'
|
||||||
|
skip_sys: 'yes'
|
||||||
|
process_priority: 10
|
||||||
|
max_eps: 100
|
||||||
|
sync_enabled: 'yes'
|
||||||
|
sync_interval: '5m'
|
||||||
|
sync_max_interval: '1h'
|
||||||
|
sync_max_eps: 10
|
||||||
rootcheck:
|
rootcheck:
|
||||||
frequency: 43200
|
frequency: 43200
|
||||||
openscap:
|
openscap:
|
||||||
disable: 'no'
|
disable: 'yes'
|
||||||
timeout: 1800
|
timeout: 1800
|
||||||
interval: '1d'
|
interval: '1d'
|
||||||
scan_on_start: 'yes'
|
scan_on_start: 'yes'
|
||||||
@ -134,10 +204,6 @@ wazuh_manager_config:
|
|||||||
scan_on_start: 'yes'
|
scan_on_start: 'yes'
|
||||||
java_path: '/usr/lib/jvm/java-1.8.0-openjdk-amd64/jre/bin'
|
java_path: '/usr/lib/jvm/java-1.8.0-openjdk-amd64/jre/bin'
|
||||||
ciscat_path: 'wodles/ciscat'
|
ciscat_path: 'wodles/ciscat'
|
||||||
content:
|
|
||||||
- type: 'xccdf'
|
|
||||||
path: 'benchmarks/CIS_Ubuntu_Linux_16.04_LTS_Benchmark_v1.0.0-xccdf.xml'
|
|
||||||
profile: 'xccdf_org.cisecurity.benchmarks_profile_Level_1_-_Server'
|
|
||||||
osquery:
|
osquery:
|
||||||
disable: 'yes'
|
disable: 'yes'
|
||||||
run_daemon: 'yes'
|
run_daemon: 'yes'
|
||||||
@ -154,20 +220,44 @@ wazuh_manager_config:
|
|||||||
packages: 'yes'
|
packages: 'yes'
|
||||||
ports_no: 'yes'
|
ports_no: 'yes'
|
||||||
processes: 'yes'
|
processes: 'yes'
|
||||||
vul_detector:
|
sca:
|
||||||
disable: 'yes'
|
enabled: 'yes'
|
||||||
|
scan_on_start: 'yes'
|
||||||
|
interval: '12h'
|
||||||
|
skip_nfs: 'yes'
|
||||||
|
day: ''
|
||||||
|
wday: ''
|
||||||
|
time: ''
|
||||||
|
vulnerability_detector:
|
||||||
|
enabled: 'no'
|
||||||
interval: '5m'
|
interval: '5m'
|
||||||
ignore_time: '6h'
|
ignore_time: '6h'
|
||||||
run_on_start: 'yes'
|
run_on_start: 'yes'
|
||||||
ubuntu:
|
providers:
|
||||||
disable: 'yes'
|
- enabled: 'no'
|
||||||
update_interval: '1h'
|
os:
|
||||||
redhat:
|
- 'precise'
|
||||||
disable: 'yes'
|
- 'trusty'
|
||||||
update_interval: '1h'
|
- 'xenial'
|
||||||
debian:
|
- 'bionic'
|
||||||
disable: 'yes'
|
update_interval: '1h'
|
||||||
update_interval: '1h'
|
name: '"canonical"'
|
||||||
|
- enabled: 'no'
|
||||||
|
os:
|
||||||
|
- 'wheezy'
|
||||||
|
- 'stretch'
|
||||||
|
- 'jessie'
|
||||||
|
- 'buster'
|
||||||
|
update_interval: '1h'
|
||||||
|
name: '"debian"'
|
||||||
|
- enabled: 'no'
|
||||||
|
update_from_year: '2010'
|
||||||
|
update_interval: '1h'
|
||||||
|
name: '"redhat"'
|
||||||
|
- enabled: 'no'
|
||||||
|
update_from_year: '2010'
|
||||||
|
update_interval: '1h'
|
||||||
|
name: '"nvd"'
|
||||||
vuls:
|
vuls:
|
||||||
disable: 'yes'
|
disable: 'yes'
|
||||||
interval: '1d'
|
interval: '1d'
|
||||||
@ -178,19 +268,20 @@ wazuh_manager_config:
|
|||||||
- 'updatenvd'
|
- 'updatenvd'
|
||||||
- 'nvd-year 2016'
|
- 'nvd-year 2016'
|
||||||
- 'autoupdate'
|
- 'autoupdate'
|
||||||
log_level: 1
|
log_level: 3
|
||||||
email_level: 12
|
email_level: 12
|
||||||
localfiles:
|
localfiles:
|
||||||
common:
|
common:
|
||||||
- format: 'command'
|
- format: 'command'
|
||||||
command: df -P -x squashfs -x tmpfs -x devtmpfs
|
command: df -P
|
||||||
frequency: '360'
|
frequency: '360'
|
||||||
- format: 'full_command'
|
- format: 'full_command'
|
||||||
command: ss -nutal | awk '{print $1,$5,$6;}' | sort -b | column -t
|
command: netstat -tulpn | sed 's/\([[:alnum:]]\+\)\ \+[[:digit:]]\+\ \+[[:digit:]]\+\ \+\(.*\):\([[:digit:]]*\)\ \+\([0-9\.\:\*]\+\).\+\ \([[:digit:]]*\/[[:alnum:]\-]*\).*/\1 \2 == \3 == \4 \5/' | sort -k 4 -g | sed 's/ == \(.*\) ==/:\1/' | sed 1,2d
|
||||||
alias: 'netstat listening ports'
|
alias: 'netstat listening ports'
|
||||||
frequency: '360'
|
frequency: '360'
|
||||||
- format: 'full_command'
|
- format: 'full_command'
|
||||||
command: 'last -n 20'
|
command: 'last -n 20'
|
||||||
|
frequency: '360'
|
||||||
- format: 'syslog'
|
- format: 'syslog'
|
||||||
location: '/var/ossec/logs/active-responses.log'
|
location: '/var/ossec/logs/active-responses.log'
|
||||||
debian:
|
debian:
|
||||||
@ -213,20 +304,16 @@ wazuh_manager_config:
|
|||||||
location: '/var/log/audit/audit.log'
|
location: '/var/log/audit/audit.log'
|
||||||
globals:
|
globals:
|
||||||
- '127.0.0.1'
|
- '127.0.0.1'
|
||||||
- '192.168.2.1'
|
- '^localhost.localdomain$'
|
||||||
|
- '127.0.0.53'
|
||||||
commands:
|
commands:
|
||||||
- name: 'disable-account'
|
- name: 'disable-account'
|
||||||
executable: 'disable-account.sh'
|
executable: 'disable-account.sh'
|
||||||
expect: 'user'
|
expect: 'user'
|
||||||
timeout_allowed: 'yes'
|
timeout_allowed: 'yes'
|
||||||
# - name: 'restart-ossec'
|
- name: 'restart-ossec'
|
||||||
# executable: 'restart-ossec.sh'
|
executable: 'restart-ossec.sh'
|
||||||
# expect: ''
|
|
||||||
# timeout_allowed: 'no'
|
|
||||||
- name: 'win_restart-ossec'
|
|
||||||
executable: 'restart-ossec.cmd'
|
|
||||||
expect: ''
|
expect: ''
|
||||||
timeout_allowed: 'no'
|
|
||||||
- name: 'firewall-drop'
|
- name: 'firewall-drop'
|
||||||
executable: 'firewall-drop.sh'
|
executable: 'firewall-drop.sh'
|
||||||
expect: 'srcip'
|
expect: 'srcip'
|
||||||
@ -243,6 +330,10 @@ wazuh_manager_config:
|
|||||||
executable: 'route-null.cmd'
|
executable: 'route-null.cmd'
|
||||||
expect: 'srcip'
|
expect: 'srcip'
|
||||||
timeout_allowed: 'yes'
|
timeout_allowed: 'yes'
|
||||||
|
- name: 'win_route-null-2012'
|
||||||
|
executable: 'route-null-2012.cmd'
|
||||||
|
expect: 'srcip'
|
||||||
|
timeout_allowed: 'yes'
|
||||||
- name: 'netsh'
|
- name: 'netsh'
|
||||||
executable: 'netsh.cmd'
|
executable: 'netsh.cmd'
|
||||||
expect: 'srcip'
|
expect: 'srcip'
|
||||||
@ -254,6 +345,10 @@ wazuh_manager_config:
|
|||||||
ruleset:
|
ruleset:
|
||||||
rules_path: 'custom_ruleset/rules/'
|
rules_path: 'custom_ruleset/rules/'
|
||||||
decoders_path: 'custom_ruleset/decoders/'
|
decoders_path: 'custom_ruleset/decoders/'
|
||||||
|
cdb_lists:
|
||||||
|
- 'audit-keys'
|
||||||
|
- 'security-eventchannel'
|
||||||
|
- 'amazon/aws-eventnames'
|
||||||
rule_exclude:
|
rule_exclude:
|
||||||
- '0215-policy_rules.xml'
|
- '0215-policy_rules.xml'
|
||||||
syslog_outputs:
|
syslog_outputs:
|
||||||
@ -266,51 +361,58 @@ wazuh_manager_config:
|
|||||||
- key: Env
|
- key: Env
|
||||||
value: Production
|
value: Production
|
||||||
|
|
||||||
wazuh_agent_configs:
|
# shared_agent_config:
|
||||||
- type: os
|
# - type: os
|
||||||
type_value: Linux
|
# type_value: Linux
|
||||||
syscheck:
|
# syscheck:
|
||||||
frequency: 43200
|
# frequency: 43200
|
||||||
scan_on_start: 'yes'
|
# scan_on_start: 'yes'
|
||||||
auto_ignore: 'no'
|
# alert_new_files: 'yes'
|
||||||
alert_new_files: 'yes'
|
# ignore:
|
||||||
ignore:
|
# - /etc/mtab
|
||||||
- /etc/mtab
|
# - /etc/mnttab
|
||||||
- /etc/mnttab
|
# - /etc/hosts.deny
|
||||||
- /etc/hosts.deny
|
# - /etc/mail/statistics
|
||||||
- /etc/mail/statistics
|
# - /etc/svc/volatile
|
||||||
- /etc/svc/volatile
|
# no_diff:
|
||||||
no_diff:
|
# - /etc/ssl/private.key
|
||||||
- /etc/ssl/private.key
|
# rootcheck:
|
||||||
rootcheck:
|
# frequency: 43200
|
||||||
frequency: 43200
|
# cis_distribution_filename: null
|
||||||
cis_distribution_filename: null
|
# localfiles:
|
||||||
localfiles:
|
# - format: 'syslog'
|
||||||
- format: 'syslog'
|
# location: '/var/log/messages'
|
||||||
location: '/var/log/messages'
|
# - format: 'syslog'
|
||||||
- format: 'syslog'
|
# location: '/var/log/secure'
|
||||||
location: '/var/log/secure'
|
# - format: 'syslog'
|
||||||
- format: 'syslog'
|
# location: '/var/log/maillog'
|
||||||
location: '/var/log/maillog'
|
# - format: 'apache'
|
||||||
- format: 'apache'
|
# location: '/var/log/httpd/error_log'
|
||||||
location: '/var/log/httpd/error_log'
|
# - format: 'apache'
|
||||||
- format: 'apache'
|
# location: '/var/log/httpd/access_log'
|
||||||
location: '/var/log/httpd/access_log'
|
# - format: 'apache'
|
||||||
- format: 'apache'
|
# location: '/var/ossec/logs/active-responses.log'
|
||||||
location: '/var/ossec/logs/active-responses.log'
|
# - type: os
|
||||||
- type: os
|
# type_value: Windows
|
||||||
type_value: Windows
|
# syscheck:
|
||||||
syscheck:
|
# frequency: 43200
|
||||||
frequency: 43200
|
# scan_on_start: 'yes'
|
||||||
scan_on_start: 'yes'
|
# auto_ignore: 'no'
|
||||||
auto_ignore: 'no'
|
# alert_new_files: 'yes'
|
||||||
alert_new_files: 'yes'
|
# windows_registry:
|
||||||
windows_registry:
|
# - key: 'HKEY_LOCAL_MACHINE\Software\Classes\batfile'
|
||||||
- key: 'HKEY_LOCAL_MACHINE\Software\Classes\batfile'
|
# arch: 'both'
|
||||||
arch: 'both'
|
# - key: 'HKEY_LOCAL_MACHINE\Software\Classes\Folder'
|
||||||
- key: 'HKEY_LOCAL_MACHINE\Software\Classes\Folder'
|
# localfiles:
|
||||||
localfiles:
|
# - location: 'Security'
|
||||||
- location: 'Security'
|
# format: 'eventchannel'
|
||||||
format: 'eventchannel'
|
# - location: 'System'
|
||||||
- location: 'System'
|
# format: 'eventlog'
|
||||||
format: 'eventlog'
|
|
||||||
|
nodejs:
|
||||||
|
repo_dict:
|
||||||
|
debian: "deb"
|
||||||
|
redhat: "rpm"
|
||||||
|
repo_url_ext: "nodesource.com/setup_10.x"
|
||||||
|
|
||||||
|
agent_groups: [] # groups to create
|
||||||
|
|||||||
@ -1,7 +1,4 @@
|
|||||||
---
|
---
|
||||||
- name: rebuild cdb_lists
|
|
||||||
command: /var/ossec/bin/ossec-makelists
|
|
||||||
|
|
||||||
- name: restart wazuh-manager
|
- name: restart wazuh-manager
|
||||||
service:
|
service:
|
||||||
name: wazuh-manager
|
name: wazuh-manager
|
||||||
@ -12,6 +9,4 @@
|
|||||||
service:
|
service:
|
||||||
name: wazuh-api
|
name: wazuh-api
|
||||||
state: restarted
|
state: restarted
|
||||||
enabled: true
|
enabled: true
|
||||||
when:
|
|
||||||
- not (ansible_distribution == 'CentOS' or ansible_distribution == 'RedHat' and ansible_distribution_major_version|int < 6)
|
|
||||||
@ -7,6 +7,7 @@
|
|||||||
- gnupg
|
- gnupg
|
||||||
state: present
|
state: present
|
||||||
cache_valid_time: 3600
|
cache_valid_time: 3600
|
||||||
|
install_recommends: false
|
||||||
register: wazuh_manager_https_packages_installed
|
register: wazuh_manager_https_packages_installed
|
||||||
until: wazuh_manager_https_packages_installed is succeeded
|
until: wazuh_manager_https_packages_installed is succeeded
|
||||||
|
|
||||||
@ -22,43 +23,28 @@
|
|||||||
when:
|
when:
|
||||||
- ansible_distribution == "Ubuntu"
|
- ansible_distribution == "Ubuntu"
|
||||||
- ansible_distribution_major_version | int == 14
|
- ansible_distribution_major_version | int == 14
|
||||||
|
- not wazuh_manager_sources_installation.enabled or not wazuh_api_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_manager_enabled or not wazuh_custom_packages_installation_api_enabled
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Installing Wazuh repository key
|
- name: Debian/Ubuntu | Installing Wazuh repository key
|
||||||
apt_key: url=https://packages.wazuh.com/key/GPG-KEY-WAZUH
|
apt_key:
|
||||||
|
url: "{{ wazuh_manager_config.repo.gpg }}"
|
||||||
|
id: "{{ wazuh_manager_config.repo.key_id }}"
|
||||||
when:
|
when:
|
||||||
- not (ansible_distribution == "Ubuntu" and ansible_distribution_major_version | int == 14)
|
- not (ansible_distribution == "Ubuntu" and ansible_distribution_major_version | int == 14)
|
||||||
|
- not wazuh_manager_sources_installation.enabled or not wazuh_api_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_manager_enabled or not wazuh_custom_packages_installation_api_enabled
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Add Wazuh repositories
|
- name: Debian/Ubuntu | Add Wazuh repositories
|
||||||
apt_repository:
|
apt_repository:
|
||||||
repo: 'deb https://packages.wazuh.com/3.x/apt/ stable main'
|
filename: wazuh_repo
|
||||||
|
repo: "{{ wazuh_manager_config.repo.apt }}"
|
||||||
state: present
|
state: present
|
||||||
update_cache: true
|
update_cache: true
|
||||||
changed_when: false
|
changed_when: false
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Installing NodeJS repository key (Ubuntu 14)
|
|
||||||
become: true
|
|
||||||
shell: |
|
|
||||||
set -o pipefail
|
|
||||||
curl -s https://deb.nodesource.com/gpgkey/nodesource.gpg.key | apt-key add -
|
|
||||||
args:
|
|
||||||
warn: false
|
|
||||||
executable: /bin/bash
|
|
||||||
changed_when: false
|
|
||||||
when:
|
when:
|
||||||
- ansible_distribution == "Ubuntu"
|
- not wazuh_manager_sources_installation.enabled or not wazuh_api_sources_installation.enabled
|
||||||
- ansible_distribution_major_version | int == 14
|
- not wazuh_custom_packages_installation_manager_enabled or not wazuh_custom_packages_installation_api_enabled
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Installing NodeJS repository key
|
|
||||||
apt_key: url=https://deb.nodesource.com/gpgkey/nodesource.gpg.key
|
|
||||||
when:
|
|
||||||
- not (ansible_distribution == "Ubuntu" and ansible_distribution_major_version | int == 14)
|
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Add NodeSource repositories for Node.js
|
|
||||||
apt_repository:
|
|
||||||
repo: "deb https://deb.nodesource.com/node_6.x {{ ansible_distribution_release }} main"
|
|
||||||
state: present
|
|
||||||
update_cache: true
|
|
||||||
changed_when: false
|
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Set Distribution CIS filename for Debian/Ubuntu
|
- name: Debian/Ubuntu | Set Distribution CIS filename for Debian/Ubuntu
|
||||||
set_fact:
|
set_fact:
|
||||||
@ -82,16 +68,16 @@
|
|||||||
- init
|
- init
|
||||||
|
|
||||||
- name: Debian/Ubuntu | Install OpenScap
|
- name: Debian/Ubuntu | Install OpenScap
|
||||||
package:
|
apt:
|
||||||
name: "{{ item }}"
|
name:
|
||||||
|
- libopenscap8
|
||||||
|
- xsltproc
|
||||||
state: present
|
state: present
|
||||||
cache_valid_time: 3600
|
cache_valid_time: 3600
|
||||||
|
install_recommends: false
|
||||||
register: wazuh_manager_openscap_installed
|
register: wazuh_manager_openscap_installed
|
||||||
until: wazuh_manager_openscap_installed is succeeded
|
until: wazuh_manager_openscap_installed is succeeded
|
||||||
when: wazuh_manager_config.openscap.disable == 'no'
|
when: wazuh_manager_config.openscap.disable == 'no'
|
||||||
with_items:
|
|
||||||
- libopenscap8
|
|
||||||
- xsltproc
|
|
||||||
tags:
|
tags:
|
||||||
- init
|
- init
|
||||||
|
|
||||||
@ -110,3 +96,40 @@
|
|||||||
changed_when: false
|
changed_when: false
|
||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
|
- name: Debian/Ubuntu | Install wazuh-manager
|
||||||
|
apt:
|
||||||
|
name:
|
||||||
|
- "wazuh-manager={{ wazuh_manager_version }}"
|
||||||
|
state: present
|
||||||
|
cache_valid_time: 3600
|
||||||
|
install_recommends: false
|
||||||
|
register: wazuh_manager_main_packages_installed
|
||||||
|
until: wazuh_manager_main_packages_installed is succeeded
|
||||||
|
tags: init
|
||||||
|
when:
|
||||||
|
- not wazuh_manager_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_manager_enabled
|
||||||
|
|
||||||
|
- include_tasks: "installation_from_sources.yml"
|
||||||
|
when:
|
||||||
|
- wazuh_manager_sources_installation.enabled or wazuh_api_sources_installation.enabled
|
||||||
|
|
||||||
|
- include_tasks: "installation_from_custom_packages.yml"
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_manager_enabled or wazuh_custom_packages_installation_api_enabled
|
||||||
|
|
||||||
|
- name: Debian/Ubuntu | Install wazuh-api
|
||||||
|
apt:
|
||||||
|
name:
|
||||||
|
- "wazuh-api={{ wazuh_manager_version }}"
|
||||||
|
state: present
|
||||||
|
cache_valid_time: 3600
|
||||||
|
install_recommends: false
|
||||||
|
register: wazuh_manager_main_packages_installed
|
||||||
|
until: wazuh_manager_main_packages_installed is succeeded
|
||||||
|
tags: init
|
||||||
|
when:
|
||||||
|
- not wazuh_api_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_manager_enabled
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
@ -1,69 +1,36 @@
|
|||||||
---
|
---
|
||||||
- name: RedHat/CentOS | Install Nodejs repo
|
- name: RedHat/CentOS 5 | Install Wazuh repo
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: NodeJS
|
name: wazuh_repo
|
||||||
description: NodeJS-$releasever
|
description: Wazuh repository
|
||||||
baseurl: https://rpm.nodesource.com/pub_6.x/el/{{ ansible_distribution_major_version }}/x86_64
|
baseurl: "{{ wazuh_manager_config.repo.yum }}5/"
|
||||||
gpgkey: https://rpm.nodesource.com/pub/el/NODESOURCE-GPG-SIGNING-KEY-EL
|
gpgkey: "{{ wazuh_manager_config.repo.gpg }}-5"
|
||||||
gpgcheck: true
|
gpgcheck: true
|
||||||
changed_when: false
|
changed_when: false
|
||||||
when:
|
when:
|
||||||
- ansible_distribution_major_version|int > 5
|
- (ansible_os_family|lower == 'redhat') and (ansible_distribution|lower != 'amazon')
|
||||||
|
- (ansible_distribution_major_version|int <= 5)
|
||||||
- name: Fedora | Install Nodejs repo
|
- not wazuh_manager_sources_installation.enabled or not wazuh_api_sources_installation.enabled
|
||||||
yum_repository:
|
- not wazuh_custom_packages_installation_manager_enabled or not wazuh_custom_packages_installation_api_enabled
|
||||||
name: NodeJS
|
register: repo_v5_manager_installed
|
||||||
description: NodeJS-$releasever
|
|
||||||
baseurl: https://rpm.nodesource.com/pub_6.x/fc/$releasever/x86_64
|
|
||||||
gpgkey: https://rpm.nodesource.com/pub/el/NODESOURCE-GPG-SIGNING-KEY-EL
|
|
||||||
gpgcheck: true
|
|
||||||
when: ansible_distribution == 'Fedora'
|
|
||||||
|
|
||||||
- name: AmazonLinux | Get Nodejs
|
|
||||||
shell: |
|
|
||||||
set -o pipefail
|
|
||||||
curl --silent --location https://rpm.nodesource.com/setup_8.x | bash -
|
|
||||||
args:
|
|
||||||
warn: false
|
|
||||||
executable: /bin/bash
|
|
||||||
when:
|
|
||||||
- ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA"
|
|
||||||
|
|
||||||
- name: AmazonLinux | Install Nodejs repo
|
|
||||||
yum:
|
|
||||||
name: nodejs
|
|
||||||
state: present
|
|
||||||
register: wazuh_manager_amz_node_packages_installed
|
|
||||||
until: wazuh_manager_amz_node_packages_installed is succeeded
|
|
||||||
when:
|
|
||||||
- ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA"
|
|
||||||
|
|
||||||
- name: RedHat/CentOS/Fedora | Install Wazuh repo
|
- name: RedHat/CentOS/Fedora | Install Wazuh repo
|
||||||
yum_repository:
|
yum_repository:
|
||||||
name: wazuh_repo
|
name: wazuh_repo
|
||||||
description: Wazuh repository
|
description: Wazuh repository
|
||||||
baseurl: https://packages.wazuh.com/3.x/yum/
|
baseurl: "{{ wazuh_manager_config.repo.yum }}"
|
||||||
gpgkey: https://packages.wazuh.com/key/GPG-KEY-WAZUH
|
gpgkey: "{{ wazuh_manager_config.repo.gpg }}"
|
||||||
gpgcheck: true
|
gpgcheck: true
|
||||||
changed_when: false
|
changed_when: false
|
||||||
when:
|
when:
|
||||||
- (ansible_distribution_major_version|int > 5) or (ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA")
|
- repo_v5_manager_installed is skipped
|
||||||
|
- not wazuh_manager_sources_installation.enabled or not wazuh_api_sources_installation.enabled
|
||||||
- name: RedHat/CentOS 5 | Install Wazuh repo
|
- not wazuh_custom_packages_installation_manager_enabled or not wazuh_custom_packages_installation_api_enabled
|
||||||
yum_repository:
|
|
||||||
name: wazuh_repo
|
|
||||||
description: Wazuh repository
|
|
||||||
baseurl: https://packages.wazuh.com/3.x/yum/5/
|
|
||||||
gpgkey: https://packages.wazuh.com/key/GPG-KEY-WAZUH
|
|
||||||
gpgcheck: true
|
|
||||||
when:
|
|
||||||
- ansible_distribution_major_version|int == 5
|
|
||||||
|
|
||||||
- name: RedHat/CentOS/Fedora | Install openscap
|
- name: RedHat/CentOS/Fedora | Install openscap
|
||||||
package: name={{ item }} state=present
|
package: name={{ item }} state=present
|
||||||
with_items:
|
with_items:
|
||||||
- openscap-scanner
|
- openscap-scanner
|
||||||
- openssl
|
|
||||||
register: wazuh_manager_openscp_packages_installed
|
register: wazuh_manager_openscp_packages_installed
|
||||||
until: wazuh_manager_openscp_packages_installed is succeeded
|
until: wazuh_manager_openscp_packages_installed is succeeded
|
||||||
tags:
|
tags:
|
||||||
@ -143,3 +110,62 @@
|
|||||||
cis_distribution_filename: cis_rhel7_linux_rcl.txt
|
cis_distribution_filename: cis_rhel7_linux_rcl.txt
|
||||||
when:
|
when:
|
||||||
- ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA"
|
- ansible_distribution == "Amazon" and ansible_distribution_major_version == "NA"
|
||||||
|
|
||||||
|
- name: CentOS/RedHat/Amazon | Install wazuh-manager
|
||||||
|
package:
|
||||||
|
name: "wazuh-manager-{{ wazuh_manager_version }}"
|
||||||
|
state: "{{ wazuh_manager_package_state }}"
|
||||||
|
register: wazuh_manager_main_packages_installed
|
||||||
|
until: wazuh_manager_main_packages_installed is succeeded
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "redhat"
|
||||||
|
- not wazuh_manager_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_manager_enabled
|
||||||
|
tags:
|
||||||
|
- init
|
||||||
|
|
||||||
|
- include_tasks: "../tasks/installation_from_sources.yml"
|
||||||
|
when:
|
||||||
|
- wazuh_manager_sources_installation.enabled or wazuh_api_sources_installation.enabled
|
||||||
|
|
||||||
|
- include_tasks: "../tasks/installation_from_custom_packages.yml"
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_manager_enabled or wazuh_custom_packages_installation_api_enabled
|
||||||
|
|
||||||
|
- name: CentOS/RedHat/Amazon | Install wazuh-api
|
||||||
|
package:
|
||||||
|
name: "wazuh-api-{{ wazuh_manager_version }}"
|
||||||
|
state: "{{ wazuh_manager_package_state }}"
|
||||||
|
register: wazuh_api_main_packages_installed
|
||||||
|
until: wazuh_api_main_packages_installed is succeeded
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "redhat"
|
||||||
|
- not wazuh_api_sources_installation.enabled
|
||||||
|
- not wazuh_custom_packages_installation_api_enabled
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
tags:
|
||||||
|
- init
|
||||||
|
|
||||||
|
- name: CentOS/RedHat 6 | Enabling python2.7 and sqlite3
|
||||||
|
replace:
|
||||||
|
path: /etc/init.d/wazuh-manager
|
||||||
|
regexp: 'echo -n "Starting Wazuh-manager: "'
|
||||||
|
replace: 'echo -n "Starting Wazuh-manager (EL6): "; source /opt/rh/python27/enable; export LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/var/ossec/framework/lib'
|
||||||
|
when:
|
||||||
|
- ansible_distribution in ['CentOS', 'RedHat', 'Amazon'] and ansible_distribution_major_version|int == 6
|
||||||
|
- wazuh_manager_config.cluster.disable != 'yes'
|
||||||
|
|
||||||
|
- name: Install expect (EL5)
|
||||||
|
package:
|
||||||
|
name: "{{ item }}"
|
||||||
|
state: "{{ wazuh_manager_package_state }}"
|
||||||
|
with_items:
|
||||||
|
- expect
|
||||||
|
register: wazuh_manager_main_packages_installed
|
||||||
|
until: wazuh_manager_main_packages_installed is succeeded
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "RedHat"
|
||||||
|
- ansible_distribution_major_version|int < 6
|
||||||
|
tags:
|
||||||
|
- init
|
||||||
|
|
||||||
|
|||||||
@ -0,0 +1,61 @@
|
|||||||
|
---
|
||||||
|
- block:
|
||||||
|
- name: Install Wazuh Manager from .deb packages
|
||||||
|
apt:
|
||||||
|
deb: "{{ wazuh_custom_packages_installation_manager_deb_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_manager_enabled
|
||||||
|
|
||||||
|
- name: Install Wazuh API from .deb packages
|
||||||
|
apt:
|
||||||
|
deb: "{{ wazuh_custom_packages_installation_api_deb_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_api_enabled
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "debian"
|
||||||
|
|
||||||
|
- block:
|
||||||
|
- name: Install Wazuh Manager from .rpm packages | yum
|
||||||
|
yum:
|
||||||
|
name: "{{ wazuh_custom_packages_installation_manager_rpm_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_manager_enabled
|
||||||
|
- not (ansible_distribution|lower == "centos" and ansible_distribution_major_version >= "8")
|
||||||
|
- not (ansible_distribution|lower == "redhat" and ansible_distribution_major_version >= "8")
|
||||||
|
|
||||||
|
- name: Install Wazuh Manager from .rpm packages | dnf
|
||||||
|
dnf:
|
||||||
|
name: "{{ wazuh_custom_packages_installation_manager_rpm_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_manager_enabled
|
||||||
|
- (ansible_distribution|lower == "centos" and ansible_distribution_major_version >= "8") or
|
||||||
|
(ansible_distribution|lower == "redhat" and ansible_distribution_major_version >= "8")
|
||||||
|
|
||||||
|
- name: Install Wazuh API from .rpm packages | yum
|
||||||
|
yum:
|
||||||
|
name: "{{ wazuh_custom_packages_installation_api_rpm_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_api_enabled
|
||||||
|
- not (ansible_distribution|lower == "centos" and ansible_distribution_major_version >= "8")
|
||||||
|
- not (ansible_distribution|lower == "redhat" and ansible_distribution_major_version >= "8")
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
|
||||||
|
- name: Install Wazuh API from .rpm packages | dnf
|
||||||
|
dnf:
|
||||||
|
name: "{{ wazuh_custom_packages_installation_api_rpm_url }}"
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- wazuh_custom_packages_installation_api_enabled
|
||||||
|
- (ansible_distribution|lower == "centos" and ansible_distribution_major_version >= "8") or
|
||||||
|
(ansible_distribution|lower == "redhat" and ansible_distribution_major_version >= "8")
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "redhat"
|
||||||
@ -0,0 +1,185 @@
|
|||||||
|
---
|
||||||
|
# Wazuh Manager
|
||||||
|
- name: Check if Wazuh Manager is already installed
|
||||||
|
stat:
|
||||||
|
path: /var/ossec/bin/ossec-control
|
||||||
|
register: wazuh_ossec_control
|
||||||
|
|
||||||
|
- name: Installing Wazuh Manager from sources
|
||||||
|
block:
|
||||||
|
- name: Install dependencies to build Wazuh packages
|
||||||
|
package:
|
||||||
|
name:
|
||||||
|
- make
|
||||||
|
- gcc
|
||||||
|
- automake
|
||||||
|
- autoconf
|
||||||
|
- libtool
|
||||||
|
- tar
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Removing old files
|
||||||
|
file:
|
||||||
|
path: "/tmp/{{ wazuh_manager_sources_installation.branch }}.tar.gz"
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- name: Removing old folders
|
||||||
|
file:
|
||||||
|
path: "/tmp/wazuh-{{ wazuh_manager_sources_installation.branch }}"
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- name: Installing policycoreutils-python (RedHat families)
|
||||||
|
package:
|
||||||
|
name:
|
||||||
|
- policycoreutils-python
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "redhat"
|
||||||
|
|
||||||
|
- name: Installing policycoreutils-python-utils (Debian families)
|
||||||
|
package:
|
||||||
|
name:
|
||||||
|
- libc6-dev
|
||||||
|
- curl
|
||||||
|
- policycoreutils
|
||||||
|
when:
|
||||||
|
- ansible_os_family|lower == "debian"
|
||||||
|
|
||||||
|
- name: Remove old repository folder
|
||||||
|
file:
|
||||||
|
path: /tmp/wazuh-{{ wazuh_manager_sources_installation.branch }}
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- name: Download required packages from github.com/wazuh/wazuh
|
||||||
|
get_url:
|
||||||
|
url: "https://github.com/wazuh/wazuh/archive/{{ wazuh_manager_sources_installation.branch }}.tar.gz"
|
||||||
|
dest: "/tmp/{{ wazuh_manager_sources_installation.branch }}.tar.gz"
|
||||||
|
delegate_to: "{{ inventory_hostname }}"
|
||||||
|
|
||||||
|
- name: Create folder to extract Wazuh branch
|
||||||
|
file:
|
||||||
|
path: "/tmp/wazuh-{{ wazuh_manager_sources_installation.branch }}"
|
||||||
|
state: directory
|
||||||
|
|
||||||
|
# When downloading "v3.11.0" extracted folder name is 3.11.0.
|
||||||
|
|
||||||
|
# Explicitly creating the folder with proper naming and striping first level in .tar.gz file
|
||||||
|
|
||||||
|
- name: Extract downloaded Wazuh branch from Github # Using shell instead of unarchive due to that module not working properlyh with --strip
|
||||||
|
command: >-
|
||||||
|
tar -xzvf /tmp/{{ wazuh_manager_sources_installation.branch }}.tar.gz
|
||||||
|
--strip 1
|
||||||
|
--directory /tmp/wazuh-{{ wazuh_manager_sources_installation.branch }}
|
||||||
|
register: wazuh_untar
|
||||||
|
changed_when: wazuh_untar.rc ==0
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
|
||||||
|
- name: Clean remaining files from others builds
|
||||||
|
command: "make -C src {{ item }}"
|
||||||
|
args:
|
||||||
|
chdir: "/tmp/wazuh-{{ wazuh_manager_sources_installation.branch }}/src/"
|
||||||
|
with_items:
|
||||||
|
- "clean"
|
||||||
|
- "clean-deps"
|
||||||
|
register: clean_result
|
||||||
|
changed_when: clean_result.rc == 0
|
||||||
|
failed_when: false
|
||||||
|
|
||||||
|
- name: Render the "preloaded-vars.conf" file
|
||||||
|
template:
|
||||||
|
src: "templates/preloaded_vars_manager.conf.j2"
|
||||||
|
dest: "/tmp/wazuh-{{ wazuh_manager_sources_installation.branch }}/etc/preloaded-vars.conf"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: 0644
|
||||||
|
|
||||||
|
- name: Executing "install.sh" script to build and install the Wazuh Manager
|
||||||
|
shell: ./install.sh > /tmp/build_wazuh_manager_log.txt
|
||||||
|
register: installation_result
|
||||||
|
changed_when: installation_result == 0
|
||||||
|
args:
|
||||||
|
chdir: "/tmp/wazuh-{{ wazuh_manager_sources_installation.branch }}"
|
||||||
|
|
||||||
|
- name: Cleanup downloaded files
|
||||||
|
file:
|
||||||
|
path: "/tmp/{{ wazuh_manager_sources_installation.branch }}.tar.gz"
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- name: Cleanup created folders
|
||||||
|
file:
|
||||||
|
path: "/tmp/wazuh-{{ wazuh_manager_sources_installation.branch }}"
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
when:
|
||||||
|
- not wazuh_ossec_control.stat.exists
|
||||||
|
- wazuh_manager_sources_installation.enabled
|
||||||
|
tags:
|
||||||
|
- manager
|
||||||
|
|
||||||
|
# Wazuh API
|
||||||
|
|
||||||
|
- name: Check if Wazuh API is already installed
|
||||||
|
stat:
|
||||||
|
path: /var/ossec/api/app.js
|
||||||
|
register: wazuh_api
|
||||||
|
when:
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
|
||||||
|
- name: Install Wazuh API from sources
|
||||||
|
block:
|
||||||
|
- name: Install dependencies to build Wazuh packages
|
||||||
|
package:
|
||||||
|
name:
|
||||||
|
- make
|
||||||
|
- gcc
|
||||||
|
- automake
|
||||||
|
- autoconf
|
||||||
|
- libtool
|
||||||
|
- tar
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Explicitly installing npm for Debian hosts
|
||||||
|
package:
|
||||||
|
name: npm
|
||||||
|
state: present
|
||||||
|
when:
|
||||||
|
- ansible_distribution == "Debian"
|
||||||
|
|
||||||
|
- name: Ensure Git is present in the host
|
||||||
|
package:
|
||||||
|
name: git
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Remove old repository folder
|
||||||
|
file:
|
||||||
|
path: /tmp/wazuh-api
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- name: Download the Wazuh API repository
|
||||||
|
git:
|
||||||
|
repo: 'https://github.com/wazuh/wazuh-api.git'
|
||||||
|
version: "{{ wazuh_api_sources_installation.branch }}"
|
||||||
|
dest: /tmp/wazuh-api
|
||||||
|
|
||||||
|
- name: Configure Wazuh API installation
|
||||||
|
template:
|
||||||
|
src: "templates/preloaded_vars_api.conf.j2"
|
||||||
|
dest: "/tmp/wazuh-api/configuration/preloaded_vars.conf"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: 0644
|
||||||
|
|
||||||
|
- name: Execute Wazuh API installation script
|
||||||
|
shell: ./install_api.sh > /tmp/build_wazuh_api_log.txt
|
||||||
|
register: install_api
|
||||||
|
changed_when: install_api.rc == 0
|
||||||
|
args:
|
||||||
|
chdir: "/tmp/wazuh-api"
|
||||||
|
notify:
|
||||||
|
- restart wazuh-api
|
||||||
|
when:
|
||||||
|
- not wazuh_api.stat.exists
|
||||||
|
- wazuh_api_sources_installation.enabled
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
tags:
|
||||||
|
- api
|
||||||
@ -1,43 +1,58 @@
|
|||||||
---
|
---
|
||||||
- import_tasks: "RedHat.yml"
|
- name: "Install dependencies"
|
||||||
|
package:
|
||||||
|
name:
|
||||||
|
- unzip
|
||||||
|
- openssl
|
||||||
|
- tar
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Check if NodeJS service exists
|
||||||
|
stat:
|
||||||
|
path: /usr/bin/node
|
||||||
|
register: node_service_status
|
||||||
|
|
||||||
|
- name: Install NodeJS repository
|
||||||
|
block:
|
||||||
|
- name: Download NodeJS repository script
|
||||||
|
get_url:
|
||||||
|
url: "https://{{ nodejs['repo_dict'][ansible_os_family|lower] }}.{{ nodejs['repo_url_ext'] }}"
|
||||||
|
dest: /etc/nodejs.sh
|
||||||
|
mode: 0775
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Run NodeJS bash script
|
||||||
|
command: sh /etc/nodejs.sh
|
||||||
|
register: nodejs_script
|
||||||
|
changed_when: nodejs_script.rc == 0
|
||||||
|
when:
|
||||||
|
- not node_service_status.stat.exists
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
|
||||||
|
- name: Installing NodeJS
|
||||||
|
package:
|
||||||
|
name: nodejs
|
||||||
|
state: present
|
||||||
|
register: nodejs_service_is_installed
|
||||||
|
until: nodejs_service_is_installed is succeeded
|
||||||
|
when:
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
|
||||||
|
tags: init
|
||||||
|
|
||||||
|
- include_tasks: "RedHat.yml"
|
||||||
when: (ansible_os_family == "RedHat" and ansible_distribution_major_version|int > 5) or (ansible_os_family == "RedHat" and ansible_distribution == "Amazon")
|
when: (ansible_os_family == "RedHat" and ansible_distribution_major_version|int > 5) or (ansible_os_family == "RedHat" and ansible_distribution == "Amazon")
|
||||||
|
|
||||||
- import_tasks: "Debian.yml"
|
- include_tasks: "Debian.yml"
|
||||||
when: ansible_os_family == "Debian"
|
when: ansible_os_family == "Debian"
|
||||||
|
|
||||||
- name: Install wazuh-manager, wazuh-api and expect
|
- name: Install expect
|
||||||
package: pkg={{ item }} state={{ wazuh_manager_package_state }}
|
package:
|
||||||
with_items:
|
name: expect
|
||||||
- wazuh-manager
|
state: "{{ wazuh_manager_package_state }}"
|
||||||
- wazuh-api
|
|
||||||
- expect
|
|
||||||
register: wazuh_manager_main_packages_installed
|
|
||||||
until: wazuh_manager_main_packages_installed is succeeded
|
|
||||||
when:
|
when:
|
||||||
- not (ansible_distribution in ['CentOS','RedHat'] and ansible_distribution_major_version|int < 6)
|
- not (ansible_os_family|lower == "redhat" and ansible_distribution_major_version|int < 6)
|
||||||
tags:
|
tags: init
|
||||||
- init
|
|
||||||
|
|
||||||
- name: CentOS/RedHat 6 | Enabling python2.7 and sqlite3
|
|
||||||
replace:
|
|
||||||
path: /etc/init.d/wazuh-manager
|
|
||||||
regexp: 'echo -n "Starting Wazuh-manager: "'
|
|
||||||
replace: 'echo -n "Starting Wazuh-manager (EL6): "; source /opt/rh/python27/enable; export LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/var/ossec/framework/lib'
|
|
||||||
when:
|
|
||||||
- ansible_distribution in ['CentOS', 'RedHat'] and ansible_distribution_major_version|int == 6
|
|
||||||
- wazuh_manager_config.cluster.disable != 'yes'
|
|
||||||
|
|
||||||
- name: Install wazuh-manager and expect (EL5)
|
|
||||||
package: pkg={{ item }} state={{ wazuh_manager_package_state }}
|
|
||||||
with_items:
|
|
||||||
- wazuh-manager
|
|
||||||
- expect
|
|
||||||
register: wazuh_manager_main_packages_installed
|
|
||||||
until: wazuh_manager_main_packages_installed is succeeded
|
|
||||||
when:
|
|
||||||
- ansible_distribution in ['CentOS','RedHat'] and ansible_distribution_major_version|int < 6
|
|
||||||
tags:
|
|
||||||
- init
|
|
||||||
|
|
||||||
- name: Generate SSL files for authd
|
- name: Generate SSL files for authd
|
||||||
command: "openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:1825 -keyout sslmanager.key -out sslmanager.cert -subj /CN={{ wazuh_manager_fqdn }}/"
|
command: "openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:1825 -keyout sslmanager.key -out sslmanager.cert -subj /CN={{ wazuh_manager_fqdn }}/"
|
||||||
@ -46,12 +61,12 @@
|
|||||||
chdir: /var/ossec/etc/
|
chdir: /var/ossec/etc/
|
||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
when: not wazuh_manager_config.authd.ssl_agent_ca is not none
|
when: wazuh_manager_config.authd.ssl_agent_ca is not none
|
||||||
|
|
||||||
- name: Copy CA, SSL key and cert for authd
|
- name: Copy CA, SSL key and cert for authd
|
||||||
copy:
|
copy:
|
||||||
src: "{{ item }}"
|
src: "{{ item }}"
|
||||||
dest: "/var/ossec/etc/{{ item | basename }}"
|
dest: "/var/ossec/etc/{{ item }}"
|
||||||
mode: 0644
|
mode: 0644
|
||||||
with_items:
|
with_items:
|
||||||
- "{{ wazuh_manager_config.authd.ssl_agent_ca }}"
|
- "{{ wazuh_manager_config.authd.ssl_agent_ca }}"
|
||||||
@ -148,6 +163,8 @@
|
|||||||
tags:
|
tags:
|
||||||
- init
|
- init
|
||||||
- config
|
- config
|
||||||
|
when:
|
||||||
|
- shared_agent_config is defined
|
||||||
|
|
||||||
- name: Installing the config.js (api configuration)
|
- name: Installing the config.js (api configuration)
|
||||||
template: src=var-ossec-api-configuration-config.js.j2
|
template: src=var-ossec-api-configuration-config.js.j2
|
||||||
@ -156,6 +173,9 @@
|
|||||||
group=ossec
|
group=ossec
|
||||||
mode=0740
|
mode=0740
|
||||||
notify: restart wazuh-api
|
notify: restart wazuh-api
|
||||||
|
when:
|
||||||
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
|
||||||
tags:
|
tags:
|
||||||
- init
|
- init
|
||||||
- config
|
- config
|
||||||
@ -181,17 +201,6 @@
|
|||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
- name: Retrieving Wazuh-API User Credentials
|
|
||||||
include_vars: wazuh_api_creds.yml
|
|
||||||
when:
|
|
||||||
- not (ansible_distribution in ['CentOS','RedHat'] and ansible_distribution_major_version|int < 6)
|
|
||||||
tags:
|
|
||||||
- config
|
|
||||||
|
|
||||||
- name: Retrieving CDB lists
|
|
||||||
include_vars: cdb_lists.yml
|
|
||||||
tags:
|
|
||||||
- config
|
|
||||||
|
|
||||||
- name: Check if syslog output is enabled
|
- name: Check if syslog output is enabled
|
||||||
set_fact: syslog_output=true
|
set_fact: syslog_output=true
|
||||||
@ -262,7 +271,7 @@
|
|||||||
poll: 0
|
poll: 0
|
||||||
when:
|
when:
|
||||||
- wazuh_manager_config.vuls.disable != 'yes'
|
- wazuh_manager_config.vuls.disable != 'yes'
|
||||||
- ansible_distribution in ['Redhat', 'CentOS', 'Ubuntu', 'Debian', 'Oracle']
|
- ansible_distribution in ['Redhat', 'CentOS', 'Ubuntu', 'Debian', 'Oracle', 'Amazon']
|
||||||
- not ansible_check_mode
|
- not ansible_check_mode
|
||||||
tags:
|
tags:
|
||||||
- init
|
- init
|
||||||
@ -304,7 +313,7 @@
|
|||||||
notify: restart wazuh-api
|
notify: restart wazuh-api
|
||||||
when:
|
when:
|
||||||
- wazuh_api_user is defined
|
- wazuh_api_user is defined
|
||||||
- not (ansible_distribution == 'CentOS' or ansible_distribution == 'RedHat' and ansible_distribution_major_version|int < 6)
|
- wazuh_manager_config.cluster.node_type == "master"
|
||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
@ -326,54 +335,37 @@
|
|||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
- name: CDB Lists
|
- name: Ensure Wazuh Manager service is started and enabled.
|
||||||
template:
|
|
||||||
src: cdb_lists.j2
|
|
||||||
dest: "/var/ossec/etc/lists/{{ item.name }}"
|
|
||||||
owner: root
|
|
||||||
group: ossec
|
|
||||||
mode: 0640
|
|
||||||
no_log: true
|
|
||||||
register: wazuh_manager_cdb_lists
|
|
||||||
until: wazuh_manager_cdb_lists is succeeded
|
|
||||||
notify:
|
|
||||||
- rebuild cdb_lists
|
|
||||||
- restart wazuh-manager
|
|
||||||
with_items:
|
|
||||||
- "{{ cdb_lists }}"
|
|
||||||
when:
|
|
||||||
- cdb_lists is defined
|
|
||||||
- cdb_lists is iterable
|
|
||||||
tags:
|
|
||||||
- config
|
|
||||||
|
|
||||||
- name: Ensure Wazuh Manager, wazuh API service is started and enabled
|
|
||||||
service:
|
service:
|
||||||
name: "{{ item }}"
|
name: "wazuh-manager"
|
||||||
enabled: true
|
|
||||||
state: started
|
|
||||||
with_items:
|
|
||||||
- wazuh-manager
|
|
||||||
- wazuh-api
|
|
||||||
tags:
|
|
||||||
- config
|
|
||||||
environment:
|
|
||||||
LD_LIBRARY_PATH: "$LD_LIBRARY_PATH:/var/ossec/framework/lib"
|
|
||||||
when:
|
|
||||||
- not (ansible_distribution == 'CentOS' or ansible_distribution == 'RedHat' and ansible_distribution_major_version|int < 6)
|
|
||||||
|
|
||||||
- name: Ensure Wazuh Manager is started and enabled (EL5)
|
|
||||||
service:
|
|
||||||
name: wazuh-manager
|
|
||||||
enabled: true
|
enabled: true
|
||||||
state: started
|
state: started
|
||||||
tags:
|
tags:
|
||||||
- config
|
- config
|
||||||
|
|
||||||
|
- name: Ensure Wazuh API service is started and enabled.
|
||||||
|
service:
|
||||||
|
name: "wazuh-api"
|
||||||
|
enabled: true
|
||||||
|
state: started
|
||||||
|
when: wazuh_manager_config.cluster.node_type == "master"
|
||||||
|
tags:
|
||||||
|
- config
|
||||||
|
|
||||||
|
- name: Create agent groups
|
||||||
|
command: "/var/ossec/bin/agent_groups -a -g {{ item }} -q"
|
||||||
|
with_items:
|
||||||
|
- "{{ agent_groups }}"
|
||||||
when:
|
when:
|
||||||
- ansible_distribution in ['CentOS', 'RedHat'] and ansible_distribution_major_version|int < 6
|
- ( agent_groups is defined) and ( agent_groups|length > 0)
|
||||||
|
tags: molecule-idempotence-notest
|
||||||
|
|
||||||
- import_tasks: "RMRedHat.yml"
|
- include_tasks: "RMRedHat.yml"
|
||||||
when: ansible_os_family == "RedHat"
|
when:
|
||||||
|
- ansible_os_family == "RedHat" or ansible_os_family == "Amazon"
|
||||||
|
- not wazuh_manager_sources_installation.enabled
|
||||||
|
|
||||||
- import_tasks: "RMDebian.yml"
|
- include_tasks: "RMDebian.yml"
|
||||||
when: ansible_os_family == "Debian"
|
when:
|
||||||
|
- ansible_os_family == "Debian"
|
||||||
|
- not wazuh_manager_sources_installation.enabled
|
||||||
|
|||||||
@ -0,0 +1,7 @@
|
|||||||
|
{% for key, value in wazuh_api_sources_installation.items() %}
|
||||||
|
{% if "enabled" not in key and "branch" not in key %}
|
||||||
|
{% if value is defined and value is not none %}
|
||||||
|
{{ key|upper }}="{{ value }}"
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
@ -0,0 +1,7 @@
|
|||||||
|
{% for key, value in wazuh_manager_sources_installation.items() %}
|
||||||
|
{% if "user_" in key %}
|
||||||
|
{% if value is defined and value is not none %}
|
||||||
|
{{ key|upper }}="{{ value }}"
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
@ -1,4 +1,4 @@
|
|||||||
#jinja2: trim_blocks: False
|
#jinja2: lstrip_blocks: True
|
||||||
<!--
|
<!--
|
||||||
Wazuh - Manager - Default configuration
|
Wazuh - Manager - Default configuration
|
||||||
More info at: https://documentation.wazuh.com
|
More info at: https://documentation.wazuh.com
|
||||||
@ -18,7 +18,7 @@
|
|||||||
<smtp_server>{{ wazuh_manager_config.mail_smtp_server }}</smtp_server>
|
<smtp_server>{{ wazuh_manager_config.mail_smtp_server }}</smtp_server>
|
||||||
<email_from>{{ wazuh_manager_config.mail_from }}</email_from>
|
<email_from>{{ wazuh_manager_config.mail_from }}</email_from>
|
||||||
<email_maxperhour>{{ wazuh_manager_config.mail_maxperhour }}</email_maxperhour>
|
<email_maxperhour>{{ wazuh_manager_config.mail_maxperhour }}</email_maxperhour>
|
||||||
<queue_size>{{ wazuh_manager_config.mail_queue_size }}</queue_size>
|
<email_log_source>{{ wazuh_manager_config.email_log_source }}</email_log_source>
|
||||||
</global>
|
</global>
|
||||||
|
|
||||||
<alerts>
|
<alerts>
|
||||||
@ -26,6 +26,11 @@
|
|||||||
<email_alert_level>{{ wazuh_manager_config.email_level }}</email_alert_level>
|
<email_alert_level>{{ wazuh_manager_config.email_level }}</email_alert_level>
|
||||||
</alerts>
|
</alerts>
|
||||||
|
|
||||||
|
<!-- Choose between "plain", "json", or "plain,json" for the format of internal logs -->
|
||||||
|
<logging>
|
||||||
|
<log_format>{{ wazuh_manager_config.log_format }}</log_format>
|
||||||
|
</logging>
|
||||||
|
|
||||||
{% if wazuh_manager_config.extra_emails is defined %}
|
{% if wazuh_manager_config.extra_emails is defined %}
|
||||||
{% for mail in wazuh_manager_config.extra_emails %}
|
{% for mail in wazuh_manager_config.extra_emails %}
|
||||||
{% if mail.enable == true %}
|
{% if mail.enable == true %}
|
||||||
@ -57,16 +62,17 @@
|
|||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
<!-- Choose between "plain", "json", or "plain,json" for the format of internal logs -->
|
|
||||||
<logging>
|
|
||||||
<log_format>{{ wazuh_manager_config.log_format }}</log_format>
|
|
||||||
</logging>
|
|
||||||
|
|
||||||
{% for connection in wazuh_manager_config.connection %}
|
|
||||||
<remote>
|
{% for connection in wazuh_manager_config.connection %}
|
||||||
|
<remote>
|
||||||
<connection>{{ connection.type }}</connection>
|
<connection>{{ connection.type }}</connection>
|
||||||
{% if connection.port is defined %}<port>{{ connection.port }}</port>{% endif %}
|
{% if connection.port is defined %}
|
||||||
{% if connection.protocol is defined %}<protocol>{{ connection.protocol }}</protocol>{% endif %}
|
<port>{{ connection.port }}</port>
|
||||||
|
{% endif %}
|
||||||
|
{% if connection.protocol is defined %}
|
||||||
|
<protocol>{{ connection.protocol }}</protocol>
|
||||||
|
{% endif %}
|
||||||
{% if connection.allowed_ips is defined %}
|
{% if connection.allowed_ips is defined %}
|
||||||
{% for allowed_ip in connection.allowed_ips %}
|
{% for allowed_ip in connection.allowed_ips %}
|
||||||
<allowed-ips>{{ allowed_ip }}</allowed-ips>
|
<allowed-ips>{{ allowed_ip }}</allowed-ips>
|
||||||
@ -77,11 +83,17 @@
|
|||||||
<denied-ips>{{ denied_ip }}</denied-ips>
|
<denied-ips>{{ denied_ip }}</denied-ips>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if connection.local_ip is defined %}<local_ip>{{ connection.local_ip }}</local_ip>{% endif %}
|
{% if connection.local_ip is defined %}
|
||||||
{% if connection.ipv6 is defined %}<ipv6>{{ connection.ipv6 }}</ipv6>{% endif %}
|
<local_ip>{{ connection.local_ip }}</local_ip>
|
||||||
{% if connection.queue_size is defined %}<queue_size>{{connection.queue_size}}</queue_size>{% endif %}
|
{% endif %}
|
||||||
|
{% if connection.ipv6 is defined %}
|
||||||
|
<ipv6>{{ connection.ipv6 }}</ipv6>
|
||||||
|
{% endif %}
|
||||||
|
{% if connection.queue_size is defined %}
|
||||||
|
<queue_size>{{connection.queue_size}}</queue_size>
|
||||||
|
{% endif %}
|
||||||
</remote>
|
</remote>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
|
||||||
{% if wazuh_manager_config.reports is defined %}
|
{% if wazuh_manager_config.reports is defined %}
|
||||||
{% for report in wazuh_manager_config.reports %}
|
{% for report in wazuh_manager_config.reports %}
|
||||||
@ -102,11 +114,9 @@
|
|||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
|
|
||||||
<!-- Policy monitoring -->
|
<!-- Policy monitoring -->
|
||||||
<rootcheck>
|
<rootcheck>
|
||||||
<disabled>no</disabled>
|
<disabled>no</disabled>
|
||||||
<check_unixaudit>yes</check_unixaudit>
|
|
||||||
<check_files>yes</check_files>
|
<check_files>yes</check_files>
|
||||||
<check_trojans>yes</check_trojans>
|
<check_trojans>yes</check_trojans>
|
||||||
<check_dev>yes</check_dev>
|
<check_dev>yes</check_dev>
|
||||||
@ -118,13 +128,8 @@
|
|||||||
<!-- Frequency that rootcheck is executed - every 12 hours -->
|
<!-- Frequency that rootcheck is executed - every 12 hours -->
|
||||||
<frequency>{{ wazuh_manager_config.rootcheck.frequency }}</frequency>
|
<frequency>{{ wazuh_manager_config.rootcheck.frequency }}</frequency>
|
||||||
|
|
||||||
<rootkit_files>/var/ossec/etc/shared/default/rootkit_files.txt</rootkit_files>
|
<rootkit_files>/var/ossec/etc/rootcheck/rootkit_files.txt</rootkit_files>
|
||||||
<rootkit_trojans>/var/ossec/etc/shared/default/rootkit_trojans.txt</rootkit_trojans>
|
<rootkit_trojans>/var/ossec/etc/rootcheck/rootkit_trojans.txt</rootkit_trojans>
|
||||||
<system_audit>/var/ossec/etc/shared/default/system_audit_rcl.txt</system_audit>
|
|
||||||
<system_audit>/var/ossec/etc/shared/default/system_audit_ssh.txt</system_audit>
|
|
||||||
{% if cis_distribution_filename is defined %}
|
|
||||||
<system_audit>/var/ossec/etc/shared/default/{{ cis_distribution_filename }}</system_audit>
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
<skip_nfs>yes</skip_nfs>
|
<skip_nfs>yes</skip_nfs>
|
||||||
</rootcheck>
|
</rootcheck>
|
||||||
@ -151,23 +156,33 @@
|
|||||||
<content type="oval" path="cve-debian-9-oval.xml"/>
|
<content type="oval" path="cve-debian-9-oval.xml"/>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% elif ansible_distribution == 'CentOS' %}
|
{% elif ansible_distribution == 'CentOS' %}
|
||||||
{% if ansible_distribution_major_version == '7' %}
|
{% if ansible_distribution_major_version == '8' %}
|
||||||
|
{# Policy not available #}
|
||||||
|
{% elif ansible_distribution_major_version == '7' %}
|
||||||
<content type="xccdf" path="ssg-centos-7-ds.xml">
|
<content type="xccdf" path="ssg-centos-7-ds.xml">
|
||||||
|
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
||||||
|
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
||||||
|
</content>
|
||||||
{% elif ansible_distribution_major_version == '6' %}
|
{% elif ansible_distribution_major_version == '6' %}
|
||||||
<content type="xccdf" path="ssg-centos-6-ds.xml">
|
<content type="xccdf" path="ssg-centos-6-ds.xml">
|
||||||
{% endif %}
|
|
||||||
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
||||||
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
||||||
</content>
|
</content>
|
||||||
|
{% endif %}
|
||||||
{% elif ansible_distribution == 'RedHat' %}
|
{% elif ansible_distribution == 'RedHat' %}
|
||||||
{% if ansible_distribution_major_version == '7' %}
|
{% if ansible_distribution_major_version == '8' %}
|
||||||
|
{# Policy not available #}
|
||||||
|
{% elif ansible_distribution_major_version == '7' %}
|
||||||
<content type="xccdf" path="ssg-rhel-7-ds.xml">
|
<content type="xccdf" path="ssg-rhel-7-ds.xml">
|
||||||
|
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
||||||
|
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
||||||
|
</content>
|
||||||
{% elif ansible_distribution_major_version == '6' %}
|
{% elif ansible_distribution_major_version == '6' %}
|
||||||
<content type="xccdf" path="ssg-rhel-6-ds.xml">
|
<content type="xccdf" path="ssg-rhel-6-ds.xml">
|
||||||
{% endif %}
|
|
||||||
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
<profile>xccdf_org.ssgproject.content_profile_pci-dss</profile>
|
||||||
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
<profile>xccdf_org.ssgproject.content_profile_common</profile>
|
||||||
</content>
|
</content>
|
||||||
|
{% endif %}
|
||||||
{% if ansible_distribution_major_version == '7' %}
|
{% if ansible_distribution_major_version == '7' %}
|
||||||
<content type="oval" path="cve-redhat-7-ds.xml"/>
|
<content type="oval" path="cve-redhat-7-ds.xml"/>
|
||||||
{% elif ansible_distribution_major_version == '6' %}
|
{% elif ansible_distribution_major_version == '6' %}
|
||||||
@ -193,11 +208,6 @@
|
|||||||
<java_path>{{ wazuh_manager_config.cis_cat.java_path }}</java_path>
|
<java_path>{{ wazuh_manager_config.cis_cat.java_path }}</java_path>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
<ciscat_path>{{ wazuh_manager_config.cis_cat.ciscat_path }}</ciscat_path>
|
<ciscat_path>{{ wazuh_manager_config.cis_cat.ciscat_path }}</ciscat_path>
|
||||||
{% for benchmark in wazuh_manager_config.cis_cat.content %}
|
|
||||||
<content type="{{ benchmark.type }}" path="{{ benchmark.path }}">
|
|
||||||
<profile>{{ benchmark.profile }}</profile>
|
|
||||||
</content>
|
|
||||||
{% endfor %}
|
|
||||||
</wodle>
|
</wodle>
|
||||||
|
|
||||||
<!-- Osquery integration -->
|
<!-- Osquery integration -->
|
||||||
@ -222,35 +232,73 @@
|
|||||||
<processes>{{ wazuh_manager_config.syscollector.processes }}</processes>
|
<processes>{{ wazuh_manager_config.syscollector.processes }}</processes>
|
||||||
</wodle>
|
</wodle>
|
||||||
|
|
||||||
<wodle name="vulnerability-detector">
|
<sca>
|
||||||
<disabled>{{ wazuh_manager_config.vul_detector.disable }}</disabled>
|
{% if wazuh_manager_config.sca.enabled | length > 0 %}
|
||||||
<interval>{{ wazuh_manager_config.vul_detector.interval }}</interval>
|
<enabled>{{ wazuh_manager_config.sca.enabled }}</enabled>
|
||||||
<ignore_time>{{ wazuh_manager_config.vul_detector.ignore_time }}</ignore_time>
|
{% endif %}
|
||||||
<run_on_start>{{ wazuh_manager_config.vul_detector.run_on_start }}</run_on_start>
|
{% if wazuh_manager_config.sca.scan_on_start | length > 0 %}
|
||||||
<feed name="ubuntu-18">
|
<scan_on_start>{{ wazuh_manager_config.sca.scan_on_start }}</scan_on_start>
|
||||||
<disabled>{{ wazuh_manager_config.vul_detector.ubuntu.disable }}</disabled>
|
{% endif %}
|
||||||
<update_interval>{{ wazuh_manager_config.vul_detector.ubuntu.update_interval }}</update_interval>
|
{% if wazuh_manager_config.sca.interval | length > 0 %}
|
||||||
</feed>
|
<interval>{{ wazuh_manager_config.sca.interval }}</interval>
|
||||||
<feed name="redhat">
|
{% endif %}
|
||||||
<disabled>{{ wazuh_manager_config.vul_detector.redhat.disable }}</disabled>
|
{% if wazuh_manager_config.sca.skip_nfs | length > 0 %}
|
||||||
<update_interval>{{ wazuh_manager_config.vul_detector.redhat.update_interval }}</update_interval>
|
<skip_nfs>yes</skip_nfs>
|
||||||
</feed>
|
{% endif %}
|
||||||
<feed name="debian-9">
|
{% if wazuh_manager_config.sca.day | length > 0 %}
|
||||||
<disabled>{{ wazuh_manager_config.vul_detector.debian.disable }}</disabled>
|
<day>yes</day>
|
||||||
<update_interval>{{ wazuh_manager_config.vul_detector.debian.update_interval }}</update_interval>
|
{% endif %}
|
||||||
</feed>
|
{% if wazuh_manager_config.sca.wday | length > 0 %}
|
||||||
</wodle>
|
<wday>yes</wday>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.sca.time | length > 0 %}
|
||||||
|
<time>yes</time>
|
||||||
|
{% endif %}
|
||||||
|
</sca>
|
||||||
|
|
||||||
|
<vulnerability-detector>
|
||||||
|
{% if wazuh_manager_config.vulnerability_detector.enabled is defined %}
|
||||||
|
<enabled>{{ wazuh_manager_config.vulnerability_detector.enabled }}</enabled>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.vulnerability_detector.interval is defined %}
|
||||||
|
<interval>{{ wazuh_manager_config.vulnerability_detector.interval }}</interval>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.vulnerability_detector.ignore_time is defined %}
|
||||||
|
<ignore_time>{{ wazuh_manager_config.vulnerability_detector.ignore_time }}</ignore_time>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.vulnerability_detector.run_on_start is defined %}
|
||||||
|
<run_on_start>{{ wazuh_manager_config.vulnerability_detector.run_on_start }}</run_on_start>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.vulnerability_detector.providers is defined %}
|
||||||
|
{% for provider_ in wazuh_manager_config.vulnerability_detector.providers %}
|
||||||
|
<provider name={{ provider_.name }}>
|
||||||
|
{% if provider_.enabled is defined %}
|
||||||
|
<enabled>{{ provider_.enabled }}</enabled>
|
||||||
|
{% endif %}
|
||||||
|
{% if provider_.os is defined %}
|
||||||
|
{% for os_ in provider_.os %}
|
||||||
|
<os>{{ os_ }}</os>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
{% if provider_.update_from_year is defined %}
|
||||||
|
<update_from_year>{{ provider_.update_from_year }}</update_from_year>
|
||||||
|
{% endif %}
|
||||||
|
{% if provider_.update_interval is defined %}
|
||||||
|
<update_interval>{{ provider_.update_interval }}</update_interval>
|
||||||
|
{% endif %}
|
||||||
|
</provider>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
</vulnerability-detector>
|
||||||
|
|
||||||
<!-- File integrity monitoring -->
|
<!-- File integrity monitoring -->
|
||||||
<syscheck>
|
<syscheck>
|
||||||
<disabled>{{ wazuh_manager_config.syscheck.disable }}</disabled>
|
<disabled>{{ wazuh_manager_config.syscheck.disable }}</disabled>
|
||||||
<auto_ignore>{{ wazuh_manager_config.syscheck.auto_ignore }}</auto_ignore>
|
|
||||||
<alert_new_files>{{ wazuh_manager_config.syscheck.alert_new_files }}</alert_new_files>
|
<alert_new_files>{{ wazuh_manager_config.syscheck.alert_new_files }}</alert_new_files>
|
||||||
<!-- Frequency that syscheck is executed -- default every 20 hours -->
|
|
||||||
<frequency>{{ wazuh_manager_config.syscheck.frequency }}</frequency>
|
<frequency>{{ wazuh_manager_config.syscheck.frequency }}</frequency>
|
||||||
<scan_on_start>{{ wazuh_manager_config.syscheck.scan_on_start }}</scan_on_start>
|
<scan_on_start>{{ wazuh_manager_config.syscheck.scan_on_start }}</scan_on_start>
|
||||||
|
|
||||||
<!-- Don't ignore files that change more than 'frequency' times -->
|
<!-- Do not ignore files that change more than 'frequency' times -->
|
||||||
{% if wazuh_manager_config.syscheck.auto_ignore_frequency is defined %}
|
{% if wazuh_manager_config.syscheck.auto_ignore_frequency is defined %}
|
||||||
<auto_ignore {{ wazuh_manager_config.syscheck.auto_ignore_frequency.frequency }} {{ wazuh_manager_config.syscheck.auto_ignore_frequency.timeframe }}>{{wazuh_manager_config.syscheck.auto_ignore_frequency.value }}</auto_ignore>
|
<auto_ignore {{ wazuh_manager_config.syscheck.auto_ignore_frequency.frequency }} {{ wazuh_manager_config.syscheck.auto_ignore_frequency.timeframe }}>{{wazuh_manager_config.syscheck.auto_ignore_frequency.value }}</auto_ignore>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
@ -269,24 +317,44 @@
|
|||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
|
<!-- File types to ignore -->
|
||||||
|
{% if wazuh_manager_config.syscheck.ignore_linux_type is defined %}
|
||||||
|
{% for ignore in wazuh_manager_config.syscheck.ignore_linux_type %}
|
||||||
|
<ignore type="sregex">{{ ignore }}</ignore>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
|
||||||
<!-- Files no diff -->
|
<!-- Files no diff -->
|
||||||
{% for no_diff in wazuh_manager_config.syscheck.no_diff %}
|
{% for no_diff in wazuh_manager_config.syscheck.no_diff %}
|
||||||
<nodiff>{{ no_diff }}</nodiff>
|
<nodiff>{{ no_diff }}</nodiff>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
|
||||||
{% if wazuh_manager_config.syscheck.skip_nfs is defined %}
|
{% if wazuh_manager_config.syscheck.skip_nfs is defined %}
|
||||||
<skip_nfs>{{ wazuh_manager_config.syscheck.skip_nfs }}</skip_nfs>
|
<skip_nfs>{{ wazuh_manager_config.syscheck.skip_nfs }}</skip_nfs>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.syscheck.skip_dev is defined %}
|
||||||
<!-- Remove not monitored files -->
|
<skip_dev>{{ wazuh_manager_config.syscheck.skip_dev }}</skip_dev>
|
||||||
{% if wazuh_manager_config.syscheck.remove_old_diff is defined %}
|
{% endif %}
|
||||||
<remove_old_diff>{{ wazuh_manager_config.syscheck.remove_old_diff }}</remove_old_diff>
|
{% if wazuh_manager_config.syscheck.skip_proc is defined %}
|
||||||
|
<skip_proc>{{ wazuh_manager_config.syscheck.skip_proc }}</skip_proc>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.syscheck.skip_sys is defined %}
|
||||||
|
<skip_sys>{{ wazuh_manager_config.syscheck.skip_sys }}</skip_sys>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
<!-- Allow the system to restart Auditd after installing the plugin -->
|
<!-- Nice value for Syscheck module -->
|
||||||
{% if wazuh_manager_config.syscheck.restart_audit is defined %}
|
<process_priority>{{ wazuh_manager_config.syscheck.process_priority }}</process_priority>
|
||||||
<restart_audit>{{ wazuh_manager_config.syscheck.restart_audit }}</restart_audit>
|
|
||||||
{% endif %}
|
<!-- Maximum output throughput -->
|
||||||
|
<max_eps>{{ wazuh_manager_config.syscheck.max_eps }}</max_eps>
|
||||||
|
|
||||||
|
<!-- Database synchronization settings -->
|
||||||
|
<synchronization>
|
||||||
|
<enabled>{{ wazuh_manager_config.syscheck.sync_enabled }}</enabled>
|
||||||
|
<interval>{{ wazuh_manager_config.syscheck.sync_interval }}</interval>
|
||||||
|
<max_interval>{{ wazuh_manager_config.syscheck.sync_max_interval }}</max_interval>
|
||||||
|
<max_eps>{{ wazuh_manager_config.syscheck.sync_max_eps }}</max_eps>
|
||||||
|
</synchronization>
|
||||||
</syscheck>
|
</syscheck>
|
||||||
|
|
||||||
<global>
|
<global>
|
||||||
@ -295,73 +363,19 @@
|
|||||||
{% endfor %}
|
{% endfor %}
|
||||||
</global>
|
</global>
|
||||||
|
|
||||||
{% for command in wazuh_manager_config.commands %}
|
{% for command in wazuh_manager_config.commands %}
|
||||||
<command>
|
|
||||||
<name>{{ command.name }}</name>
|
|
||||||
<executable>{{ command.executable }}</executable>
|
|
||||||
<expect>{{ command.expect }}</expect>
|
|
||||||
<timeout_allowed>{{ command.timeout_allowed }}</timeout_allowed>
|
|
||||||
</command>
|
|
||||||
{% endfor %}
|
|
||||||
|
|
||||||
<ruleset>
|
<command>
|
||||||
<!-- Default ruleset -->
|
<name>{{ command.name }}</name>
|
||||||
<decoder_dir>ruleset/decoders</decoder_dir>
|
<executable>{{ command.executable }}</executable>
|
||||||
<rule_dir>ruleset/rules</rule_dir>
|
<expect>{{ command.expect }}</expect>
|
||||||
{% if wazuh_manager_config.rule_exclude is defined %}
|
{% if command.timeout_allowed is defined %}
|
||||||
{% for rule in wazuh_manager_config.rule_exclude %}
|
<timeout_allowed>{{ command.timeout_allowed }}</timeout_allowed>
|
||||||
<rule_exclude>{{ rule }}</rule_exclude>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
{% if cdb_lists is defined %}
|
|
||||||
{% for list in cdb_lists %}
|
|
||||||
<list>etc/lists/{{ list.name }}</list>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
</command>
|
||||||
|
{% endfor %}
|
||||||
|
|
||||||
<!-- User-defined ruleset -->
|
{% if ansible_system == "Linux" and wazuh_manager_config.vuls.disable == 'no' %}
|
||||||
<decoder_dir>etc/decoders</decoder_dir>
|
|
||||||
<rule_dir>etc/rules</rule_dir>
|
|
||||||
</ruleset>
|
|
||||||
|
|
||||||
{% if wazuh_manager_config.authd.enable == true %}
|
|
||||||
<auth>
|
|
||||||
<disabled>no</disabled>
|
|
||||||
{% if wazuh_manager_config.authd.port is not none %}<port>{{wazuh_manager_config.authd.port}}</port>{% else %}<port>1515</port>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.use_source_ip is not none %}<use_source_ip>{{wazuh_manager_config.authd.use_source_ip}}</use_source_ip>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.force_insert is not none %}<force_insert>{{wazuh_manager_config.authd.force_insert}}</force_insert>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.force_time is not none %}<force_time>{{wazuh_manager_config.authd.force_time}}</force_time>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.purge is not none %}<purge>{{wazuh_manager_config.authd.purge}}</purge>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.use_password is not none %}<use_password>{{wazuh_manager_config.authd.use_password}}</use_password>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.ssl_agent_ca is not none %}<ssl_agent_ca>/var/ossec/etc/{{wazuh_manager_config.authd.ssl_agent_ca | basename}}</ssl_agent_ca>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.ssl_verify_host is not none %}<ssl_verify_host>{{wazuh_manager_config.authd.ssl_verify_host}}</ssl_verify_host>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.ssl_manager_cert is not none %}<ssl_manager_cert>/var/ossec/etc/{{wazuh_manager_config.authd.ssl_manager_cert | basename}}</ssl_manager_cert>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.ssl_manager_key is not none %}<ssl_manager_key>/var/ossec/etc/{{wazuh_manager_config.authd.ssl_manager_key | basename}}</ssl_manager_key>{% endif %}
|
|
||||||
{% if wazuh_manager_config.authd.ssl_auto_negotiate is not none %}<ssl_auto_negotiate>{{wazuh_manager_config.authd.ssl_auto_negotiate}}</ssl_auto_negotiate>{% endif %}
|
|
||||||
</auth>
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
|
|
||||||
<cluster>
|
|
||||||
<disabled>{{ wazuh_manager_config.cluster.disable }}</disabled>
|
|
||||||
<name>{{ wazuh_manager_config.cluster.name }}</name>
|
|
||||||
<node_name>{{ wazuh_manager_config.cluster.node_name }}</node_name>
|
|
||||||
<node_type>{{ wazuh_manager_config.cluster.node_type }}</node_type>
|
|
||||||
<key>{{ wazuh_manager_config.cluster.key }}</key>
|
|
||||||
{% if wazuh_manager_config.cluster.interval is defined %}
|
|
||||||
<interval>{{ wazuh_manager_config.cluster.interval }}</interval>
|
|
||||||
{% endif %}
|
|
||||||
<port>{{ wazuh_manager_config.cluster.port }}</port>
|
|
||||||
<bind_addr>{{ wazuh_manager_config.cluster.bind_addr }}</bind_addr>
|
|
||||||
<nodes>
|
|
||||||
{% for node in wazuh_manager_config.cluster.nodes %}
|
|
||||||
<node>{{ node }}</node>
|
|
||||||
{% endfor %}
|
|
||||||
</nodes>
|
|
||||||
<hidden>{{ wazuh_manager_config.cluster.hidden }}</hidden>
|
|
||||||
</cluster>
|
|
||||||
|
|
||||||
{% if ansible_system == "Linux" and wazuh_manager_config.vuls.disable == 'no' %}
|
|
||||||
<wodle name="command">
|
<wodle name="command">
|
||||||
<disabled>no</disabled>
|
<disabled>no</disabled>
|
||||||
<tag>Wazuh-VULS</tag>
|
<tag>Wazuh-VULS</tag>
|
||||||
@ -370,7 +384,7 @@
|
|||||||
<ignore_output>yes</ignore_output>
|
<ignore_output>yes</ignore_output>
|
||||||
<run_on_start>{{ wazuh_manager_config.vuls.run_on_start }}</run_on_start>
|
<run_on_start>{{ wazuh_manager_config.vuls.run_on_start }}</run_on_start>
|
||||||
</wodle>
|
</wodle>
|
||||||
{% endif %}
|
{% endif -%}
|
||||||
|
|
||||||
{% if agentless_creds is defined %}
|
{% if agentless_creds is defined %}
|
||||||
{% for agentless in agentless_creds %}
|
{% for agentless in agentless_creds %}
|
||||||
@ -383,11 +397,8 @@
|
|||||||
<arguments>{{ agentless.arguments }}</arguments>
|
<arguments>{{ agentless.arguments }}</arguments>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
</agentless>
|
</agentless>
|
||||||
|
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif -%}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
{% if wazuh_manager_config.active_responses is defined %}
|
{% if wazuh_manager_config.active_responses is defined %}
|
||||||
{% for response in wazuh_manager_config.active_responses %}
|
{% for response in wazuh_manager_config.active_responses %}
|
||||||
@ -403,10 +414,11 @@
|
|||||||
{%if response.repeated_offenders is defined %}<repeated_offenders>{{ response.repeated_offenders }}</repeated_offenders>{% endif %}
|
{%if response.repeated_offenders is defined %}<repeated_offenders>{{ response.repeated_offenders }}</repeated_offenders>{% endif %}
|
||||||
</active-response>
|
</active-response>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif -%}
|
||||||
|
|
||||||
<!-- Files to monitor (localfiles) -->
|
<!-- Files to monitor (localfiles) -->
|
||||||
{% for localfile in wazuh_manager_config.localfiles.common %}
|
{% for localfile in wazuh_manager_config.localfiles.common %}
|
||||||
|
|
||||||
<localfile>
|
<localfile>
|
||||||
<log_format>{{ localfile.format }}</log_format>
|
<log_format>{{ localfile.format }}</log_format>
|
||||||
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
||||||
@ -429,7 +441,7 @@
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if localfile.format == 'json' and localfile.labels is defined %}
|
{% if localfile.format == 'json' and localfile.labels is defined %}
|
||||||
{% for key, value in localfile.labels.iteritems() %}
|
{% for key, value in localfile.labels.items() %}
|
||||||
<label key="{{ key }}">{{ value }}</label>
|
<label key="{{ key }}">{{ value }}</label>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
@ -444,44 +456,7 @@
|
|||||||
|
|
||||||
{% if ansible_os_family == "Debian" %}
|
{% if ansible_os_family == "Debian" %}
|
||||||
{% for localfile in wazuh_manager_config.localfiles.debian %}
|
{% for localfile in wazuh_manager_config.localfiles.debian %}
|
||||||
<localfile>
|
|
||||||
<log_format>{{ localfile.format }}</log_format>
|
|
||||||
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
|
||||||
<command>{{ localfile.command }}</command>
|
|
||||||
{% if localfile.alias is defined %}
|
|
||||||
<alias>{{ localfile.alias }}</alias>
|
|
||||||
{% endif %}
|
|
||||||
{% if localfile.frequency is defined %}
|
|
||||||
<frequency>{{ localfile.frequency }}</frequency>
|
|
||||||
{% endif %}
|
|
||||||
{% else %}
|
|
||||||
<location>{{ localfile.location }}</location>
|
|
||||||
{% if localfile.format == 'eventchannel' %}
|
|
||||||
{% if localfile.only_future_events is defined %}
|
|
||||||
<only-future-events>{{ localfile.only_future_events }}</only_future_events>
|
|
||||||
{% endif %}
|
|
||||||
{% if localfile.query is defined %}
|
|
||||||
<query>{{ localfile.query }}</query>
|
|
||||||
{% endif %}
|
|
||||||
{% endif %}
|
|
||||||
{% endif %}
|
|
||||||
{% if localfile.format == 'json' and localfile.labels is defined %}
|
|
||||||
{% for key, value in localfile.labels.iteritems() %}
|
|
||||||
<label key="{{ key }}">{{ value }}</label>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
{% if localfile.target is defined %}
|
|
||||||
<target>{{ localfile.target }}</target>
|
|
||||||
{% endif %}
|
|
||||||
{% if localfile.out_format is defined %}
|
|
||||||
<out_format>{{ localfile.out_format }}</out_format>
|
|
||||||
{% endif %}
|
|
||||||
</localfile>
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if ansible_os_family == "RedHat" %}
|
|
||||||
{% for localfile in wazuh_manager_config.localfiles.centos %}
|
|
||||||
<localfile>
|
<localfile>
|
||||||
<log_format>{{ localfile.format }}</log_format>
|
<log_format>{{ localfile.format }}</log_format>
|
||||||
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
||||||
@ -504,7 +479,7 @@
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if localfile.format == 'json' and localfile.labels is defined %}
|
{% if localfile.format == 'json' and localfile.labels is defined %}
|
||||||
{% for key, value in localfile.labels.iteritems() %}
|
{% for key, value in localfile.labels.items() %}
|
||||||
<label key="{{ key }}">{{ value }}</label>
|
<label key="{{ key }}">{{ value }}</label>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
@ -516,7 +491,46 @@
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
</localfile>
|
</localfile>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif -%}
|
||||||
|
|
||||||
|
{% if ansible_os_family == "RedHat" %}
|
||||||
|
{% for localfile in wazuh_manager_config.localfiles.centos %}
|
||||||
|
|
||||||
|
<localfile>
|
||||||
|
<log_format>{{ localfile.format }}</log_format>
|
||||||
|
{% if localfile.format == 'command' or localfile.format == 'full_command' %}
|
||||||
|
<command>{{ localfile.command }}</command>
|
||||||
|
{% if localfile.alias is defined %}
|
||||||
|
<alias>{{ localfile.alias }}</alias>
|
||||||
|
{% endif %}
|
||||||
|
{% if localfile.frequency is defined %}
|
||||||
|
<frequency>{{ localfile.frequency }}</frequency>
|
||||||
|
{% endif %}
|
||||||
|
{% else %}
|
||||||
|
<location>{{ localfile.location }}</location>
|
||||||
|
{% if localfile.format == 'eventchannel' %}
|
||||||
|
{% if localfile.only_future_events is defined %}
|
||||||
|
<only-future-events>{{ localfile.only_future_events }}</only_future_events>
|
||||||
|
{% endif %}
|
||||||
|
{% if localfile.query is defined %}
|
||||||
|
<query>{{ localfile.query }}</query>
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
|
{% if localfile.format == 'json' and localfile.labels is defined %}
|
||||||
|
{% for key, value in localfile.labels.items() %}
|
||||||
|
<label key="{{ key }}">{{ value }}</label>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
{% if localfile.target is defined %}
|
||||||
|
<target>{{ localfile.target }}</target>
|
||||||
|
{% endif %}
|
||||||
|
{% if localfile.out_format is defined %}
|
||||||
|
<out_format>{{ localfile.out_format }}</out_format>
|
||||||
|
{% endif %}
|
||||||
|
</localfile>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif -%}
|
||||||
|
|
||||||
{% if wazuh_manager_config.syslog_outputs is defined %}
|
{% if wazuh_manager_config.syslog_outputs is defined %}
|
||||||
{% for syslog_output in wazuh_manager_config.syslog_outputs %}
|
{% for syslog_output in wazuh_manager_config.syslog_outputs %}
|
||||||
@ -538,4 +552,91 @@
|
|||||||
</labels>
|
</labels>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
|
|
||||||
|
<ruleset>
|
||||||
|
<!-- Default ruleset -->
|
||||||
|
<decoder_dir>ruleset/decoders</decoder_dir>
|
||||||
|
<rule_dir>ruleset/rules</rule_dir>
|
||||||
|
{% if wazuh_manager_config.rule_exclude is defined %}
|
||||||
|
{% for rule in wazuh_manager_config.rule_exclude %}
|
||||||
|
<rule_exclude>{{ rule }}</rule_exclude>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.ruleset.cdb_lists is defined %}
|
||||||
|
{% for list in wazuh_manager_config.ruleset.cdb_lists %}
|
||||||
|
<list>etc/lists/{{ list }}</list>
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
<!-- User-defined ruleset -->
|
||||||
|
<decoder_dir>etc/decoders</decoder_dir>
|
||||||
|
<rule_dir>etc/rules</rule_dir>
|
||||||
|
</ruleset>
|
||||||
|
|
||||||
|
{% if wazuh_manager_config.authd.enable == true %}
|
||||||
|
<auth>
|
||||||
|
<disabled>no</disabled>
|
||||||
|
{% if wazuh_manager_config.authd.port is not none %}
|
||||||
|
<port>{{wazuh_manager_config.authd.port}}</port>
|
||||||
|
{% else %}
|
||||||
|
<port>1515</port>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.use_source_ip is not none %}
|
||||||
|
<use_source_ip>{{wazuh_manager_config.authd.use_source_ip}}</use_source_ip>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.force_insert is not none %}
|
||||||
|
<force_insert>{{wazuh_manager_config.authd.force_insert}}</force_insert>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.force_time is not none %}
|
||||||
|
<force_time>{{wazuh_manager_config.authd.force_time}}</force_time>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.purge is not none %}
|
||||||
|
<purge>{{wazuh_manager_config.authd.purge}}</purge>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.use_password is not none %}
|
||||||
|
<use_password>{{wazuh_manager_config.authd.use_password}}</use_password>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.limit_maxagents is not none %}
|
||||||
|
<limit_maxagents>{{wazuh_manager_config.authd.limit_maxagents}}</limit_maxagents>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.ciphers is not none %}
|
||||||
|
<ciphers>{{wazuh_manager_config.authd.ciphers}}</ciphers>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.ssl_agent_ca is not none %}
|
||||||
|
<ssl_agent_ca>/var/ossec/etc/{{wazuh_manager_config.authd.ssl_agent_ca | basename}}</ssl_agent_ca>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.ssl_verify_host is not none %}
|
||||||
|
<ssl_verify_host>{{wazuh_manager_config.authd.ssl_verify_host}}</ssl_verify_host>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.ssl_manager_cert is not none %}
|
||||||
|
<ssl_manager_cert>/var/ossec/etc/{{wazuh_manager_config.authd.ssl_manager_cert | basename}}</ssl_manager_cert>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.ssl_manager_key is not none %}
|
||||||
|
<ssl_manager_key>/var/ossec/etc/{{wazuh_manager_config.authd.ssl_manager_key | basename}}</ssl_manager_key>
|
||||||
|
{% endif %}
|
||||||
|
{% if wazuh_manager_config.authd.ssl_auto_negotiate is not none %}
|
||||||
|
<ssl_auto_negotiate>{{wazuh_manager_config.authd.ssl_auto_negotiate}}</ssl_auto_negotiate>
|
||||||
|
{% endif %}
|
||||||
|
</auth>
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
<cluster>
|
||||||
|
<disabled>{{ wazuh_manager_config.cluster.disable }}</disabled>
|
||||||
|
<name>{{ wazuh_manager_config.cluster.name }}</name>
|
||||||
|
<node_name>{{ wazuh_manager_config.cluster.node_name }}</node_name>
|
||||||
|
<node_type>{{ wazuh_manager_config.cluster.node_type }}</node_type>
|
||||||
|
<key>{{ wazuh_manager_config.cluster.key }}</key>
|
||||||
|
{% if wazuh_manager_config.cluster.interval is defined %}
|
||||||
|
<interval>{{ wazuh_manager_config.cluster.interval }}</interval>
|
||||||
|
{% endif %}
|
||||||
|
<port>{{ wazuh_manager_config.cluster.port }}</port>
|
||||||
|
<bind_addr>{{ wazuh_manager_config.cluster.bind_addr }}</bind_addr>
|
||||||
|
<nodes>
|
||||||
|
{% for node in wazuh_manager_config.cluster.nodes %}
|
||||||
|
<node>{{ node }}</node>
|
||||||
|
{% endfor %}
|
||||||
|
</nodes>
|
||||||
|
<hidden>{{ wazuh_manager_config.cluster.hidden }}</hidden>
|
||||||
|
</cluster>
|
||||||
|
|
||||||
</ossec_config>
|
</ossec_config>
|
||||||
|
|||||||
@ -1,12 +1,13 @@
|
|||||||
#jinja2: trim_blocks: False
|
#jinja2: trim_blocks: False
|
||||||
{% if wazuh_agent_configs is defined %}
|
{% if shared_agent_config is defined %}
|
||||||
{% for agent_config in wazuh_agent_configs %}
|
{% for agent_config in shared_agent_config %}
|
||||||
<agent_config {{ agent_config.type }}="{{ agent_config.type_value }}">
|
<agent_config {{ agent_config.type }}="{{ agent_config.type_value }}">
|
||||||
{% if agent_config.syscheck is defined %}
|
{% if agent_config.syscheck is defined %}
|
||||||
<syscheck>
|
<syscheck>
|
||||||
|
{% if agent_config.syscheck.auto_ignore is defined %}
|
||||||
<auto_ignore>{{ agent_config.syscheck.auto_ignore }}</auto_ignore>
|
<auto_ignore>{{ agent_config.syscheck.auto_ignore }}</auto_ignore>
|
||||||
|
{% endif %}
|
||||||
<alert_new_files>{{ agent_config.syscheck.alert_new_files }}</alert_new_files>
|
<alert_new_files>{{ agent_config.syscheck.alert_new_files }}</alert_new_files>
|
||||||
<!-- Frequency that syscheck is executed -- default every 20 hours -->
|
|
||||||
<frequency>{{ agent_config.syscheck.frequency }}</frequency>
|
<frequency>{{ agent_config.syscheck.frequency }}</frequency>
|
||||||
<scan_on_start>{{ agent_config.syscheck.scan_on_start }}</scan_on_start>
|
<scan_on_start>{{ agent_config.syscheck.scan_on_start }}</scan_on_start>
|
||||||
|
|
||||||
@ -66,7 +67,7 @@
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if localfile.format == 'json' and localfile.labels is defined %}
|
{% if localfile.format == 'json' and localfile.labels is defined %}
|
||||||
{% for key, value in localfile.labels.iteritems() %}
|
{% for key, value in localfile.labels.items() %}
|
||||||
<label key="{{ key }}">{{ value }}</label>
|
<label key="{{ key }}">{{ value }}</label>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
@ -1,87 +0,0 @@
|
|||||||
---
|
|
||||||
cdb_lists:
|
|
||||||
- name: 'audit-keys'
|
|
||||||
content: |
|
|
||||||
audit-wazuh-w:write
|
|
||||||
audit-wazuh-r:read
|
|
||||||
audit-wazuh-a:attribute
|
|
||||||
audit-wazuh-x:execute
|
|
||||||
audit-wazuh-c:command
|
|
||||||
- name: 'aws-source'
|
|
||||||
content: |
|
|
||||||
ec2.amazonaws.com:
|
|
||||||
elasticloadbalancing.amazonaws.com:
|
|
||||||
iam.amazonaws.com:
|
|
||||||
signin.amazonaws.com:
|
|
||||||
kms.amazonaws.com:
|
|
||||||
s3.amazonaws.com:
|
|
||||||
- name: 'aws-eventnames'
|
|
||||||
content: |
|
|
||||||
AddUserToGroup:
|
|
||||||
AllocateAddress:
|
|
||||||
AssociateAddress:
|
|
||||||
AssociateDhcpOptions:
|
|
||||||
AssociateRouteTable:
|
|
||||||
AttachGroupPolicy:
|
|
||||||
AttachNetworkInterface:
|
|
||||||
AttachRolePolicy:
|
|
||||||
AttachUserPolicy:
|
|
||||||
AttachVolume:
|
|
||||||
AuthorizeSecurityGroupIngress:
|
|
||||||
ConsoleLogin:
|
|
||||||
CopySnapshot:
|
|
||||||
CreateAccountAlias:
|
|
||||||
CreateGroup:
|
|
||||||
CreateImage:
|
|
||||||
CreateLoadBalancer:
|
|
||||||
CreatePlacementGroup:
|
|
||||||
CreatePolicy:
|
|
||||||
CreateRole:
|
|
||||||
CreateRouteTable:
|
|
||||||
CreateSecurityGroup:
|
|
||||||
CreateSnapshot:
|
|
||||||
CreateSubnet:
|
|
||||||
CreateTags:
|
|
||||||
CreateUser:
|
|
||||||
CreateVolume:
|
|
||||||
CreateVpc:
|
|
||||||
DeleteAccountAlias:
|
|
||||||
DeleteLoadBalancer:
|
|
||||||
DeletePlacementGroup:
|
|
||||||
DeleteSecurityGroup:
|
|
||||||
DeleteSnapshot:
|
|
||||||
DeleteTags:
|
|
||||||
DeleteUser:
|
|
||||||
DeleteVolume:
|
|
||||||
DeregisterImage:
|
|
||||||
DetachGroupPolicy:
|
|
||||||
DetachNetworkInterface:
|
|
||||||
DetachRolePolicy:
|
|
||||||
DetachVolume:
|
|
||||||
DisableKey:
|
|
||||||
DisassociateAddress:
|
|
||||||
DisassociateAddress:
|
|
||||||
DisassociateRouteTable:
|
|
||||||
GetGroup:
|
|
||||||
ListAliases:
|
|
||||||
ListGroups:
|
|
||||||
ListUsers:
|
|
||||||
ModifyImageAttribute:
|
|
||||||
ModifyInstanceAttribute:
|
|
||||||
ModifyNetworkInterfaceAttribute:
|
|
||||||
ModifySnapshotAttribute:
|
|
||||||
ModifySubnetAttribute:
|
|
||||||
ModifyVolumeAttribute:
|
|
||||||
MonitorInstances:
|
|
||||||
RebootInstances:
|
|
||||||
RegisterImage:
|
|
||||||
RemoveUserFromGroup:
|
|
||||||
RevokeSecurityGroupIngress:
|
|
||||||
RunInstances:
|
|
||||||
StartInstances:
|
|
||||||
StopInstances:
|
|
||||||
TerminateInstances:
|
|
||||||
UnmonitorInstances:
|
|
||||||
UpdateAccessKey:
|
|
||||||
UpdateAccountPasswordPolicy:
|
|
||||||
UpdateInstanceAlias:
|
|
||||||
@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
wazuh_api_user:
|
|
||||||
- "foo:$apr1$/axqZYWQ$Xo/nz/IG3PdwV82EnfYKh/"
|
|
||||||
Loading…
Reference in New Issue
Block a user