mirror of
				https://github.com/wazuh/wazuh-docker.git
				synced 2025-11-03 05:23:14 +00:00 
			
		
		
		
	Compare commits
	
		
			48 Commits
		
	
	
		
			6.8.2_6.6.
			...
			3.8.2_6.6.
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 
						 | 
					b47f723285 | ||
| 
						 | 
					b99d54eb25 | ||
| 
						 | 
					2b0f2955d0 | ||
| 
						 | 
					38644d380c | ||
| 
						 | 
					86bc43a494 | ||
| 
						 | 
					8e5ad87619 | ||
| 
						 | 
					2bd0138d6f | ||
| 
						 | 
					92b2814fb1 | ||
| 
						 | 
					91e70da2b8 | ||
| 
						 | 
					260762968d | ||
| 
						 | 
					beb9bee27b | ||
| 
						 | 
					49f6f673c6 | ||
| 
						 | 
					1bc6ecca67 | ||
| 
						 | 
					ebca6b3696 | ||
| 
						 | 
					b15d61cda7 | ||
| 
						 | 
					7aeb6b2050 | ||
| 
						 | 
					11108631c0 | ||
| 
						 | 
					62af977067 | ||
| 
						 | 
					be9c278a18 | ||
| 
						 | 
					92d957730c | ||
| 
						 | 
					8823405dd9 | ||
| 
						 | 
					73e5b99983 | ||
| 
						 | 
					e563df4093 | ||
| 
						 | 
					f3674ff9d9 | ||
| 
						 | 
					12b40b48ee | ||
| 
						 | 
					715fb4fdec | ||
| 
						 | 
					fdca63f592 | ||
| 
						 | 
					6a82a36711 | ||
| 
						 | 
					18e955090a | ||
| 
						 | 
					fc97c3623b | ||
| 
						 | 
					283ca42d57 | ||
| 
						 | 
					c6793657e7 | ||
| 
						 | 
					b3114e7293 | ||
| 
						 | 
					727858f74c | ||
| 
						 | 
					48e0c75a26 | ||
| 
						 | 
					580251104c | ||
| 
						 | 
					3fdba44bfa | ||
| 
						 | 
					6ce25e00c9 | ||
| 
						 | 
					699f2bb82e | ||
| 
						 | 
					b7537453e3 | ||
| 
						 | 
					9b0602766f | ||
| 
						 | 
					e6062f28f3 | ||
| 
						 | 
					e182e0d4f8 | ||
| 
						 | 
					666708c47f | ||
| 
						 | 
					d0df9a06e1 | ||
| 
						 | 
					c1a33b7185 | ||
| 
						 | 
					b06e4c4a5e | ||
| 
						 | 
					3ef08ccf66 | 
							
								
								
									
										19
									
								
								CHANGELOG.md
									
									
									
									
									
								
							
							
						
						
									
										19
									
								
								CHANGELOG.md
									
									
									
									
									
								
							@@ -1,6 +1,18 @@
 | 
			
		||||
# Change Log
 | 
			
		||||
All notable changes to this project will be documented in this file.
 | 
			
		||||
 | 
			
		||||
## Wazuh Docker v3.8.2_6.6.2
 | 
			
		||||
 | 
			
		||||
### Changed
 | 
			
		||||
 | 
			
		||||
- Update Elastic Stack version to 6.6.2. ([#130](https://github.com/wazuh/wazuh-docker/pull/130))
 | 
			
		||||
 | 
			
		||||
## Wazuh Docker v3.8.2_6.6.2
 | 
			
		||||
 | 
			
		||||
### Changed
 | 
			
		||||
 | 
			
		||||
- Update Elastic Stack version to 6.6.2. ([#129](https://github.com/wazuh/wazuh-docker/pull/129))
 | 
			
		||||
 | 
			
		||||
## Wazuh Docker v3.8.2_6.5.4
 | 
			
		||||
 | 
			
		||||
### Added
 | 
			
		||||
@@ -10,11 +22,18 @@ All notable changes to this project will be documented in this file.
 | 
			
		||||
- Adding the option to disable some xpack features. ([#111](https://github.com/wazuh/wazuh-docker/pull/111))
 | 
			
		||||
- Wazuh-Kibana customizable at plugin level. ([#117](https://github.com/wazuh/wazuh-docker/pull/117))
 | 
			
		||||
- Adding env variables for alerts data flow. ([#118](https://github.com/wazuh/wazuh-docker/pull/118))
 | 
			
		||||
- New Logstash entrypoint added. ([#135](https://github.com/wazuh/wazuh-docker/pull/135/files))
 | 
			
		||||
- Welcome screen management. ([#133](https://github.com/wazuh/wazuh-docker/pull/133))
 | 
			
		||||
 | 
			
		||||
### Changed
 | 
			
		||||
 | 
			
		||||
- Update to Wazuh version 3.8.2. ([#105](https://github.com/wazuh/wazuh-docker/pull/105))
 | 
			
		||||
 | 
			
		||||
### Removed
 | 
			
		||||
 | 
			
		||||
- Remove alerts created in build time. ([#137](https://github.com/wazuh/wazuh-docker/pull/137))
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
## Wazuh Docker v3.8.1_6.5.4
 | 
			
		||||
 | 
			
		||||
### Changed
 | 
			
		||||
 
 | 
			
		||||
@@ -11,8 +11,9 @@ In this repository you will find the containers to run:
 | 
			
		||||
* wazuh-logstash: It is used to receive alerts generated by the manager and feed Elasticsearch using an alerts template
 | 
			
		||||
* wazuh-kibana: Provides a web user interface to browse through alerts data. It includes Wazuh plugin for Kibana, that allows you to visualize agents configuration and status.
 | 
			
		||||
* wazuh-nginx: Proxies the Kibana container, adding HTTPS (via self-signed SSL certificate) and [Basic authentication](https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#Basic_authentication_scheme).
 | 
			
		||||
* wazuh-elasticsearch: An Elasticsearch container (working as a single-node cluster) using Elastic Stack Docker images. **Be aware to increase the `vm.max_map_count` setting, as it's detailed in the [Wazuh documentation](https://documentation.wazuh.com/current/docker/wazuh-container.html#increase-max-map-count-on-your-host-linux).** 
 | 
			
		||||
 | 
			
		||||
In addition, a docker-compose file is provided to launch the containers mentioned above. It also launches an Elasticsearch container (working as a single-node cluster) using Elastic Stack Docker images.
 | 
			
		||||
In addition, a docker-compose file is provided to launch the containers mentioned above. 
 | 
			
		||||
 | 
			
		||||
## Documentation
 | 
			
		||||
 | 
			
		||||
@@ -58,9 +59,9 @@ In addition, a docker-compose file is provided to launch the containers mentione
 | 
			
		||||
 | 
			
		||||
## Branches
 | 
			
		||||
 | 
			
		||||
* `stable` branch on correspond to the last Wazuh-Docker stable version.
 | 
			
		||||
* `stable` branch on correspond to the latest Wazuh-Docker stable version.
 | 
			
		||||
* `master` branch contains the latest code, be aware of possible bugs on this branch.
 | 
			
		||||
* `Wazuh.Version_ElasticStack.Version` (for example 3.7.0_6.4.3) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch.
 | 
			
		||||
* `Wazuh.Version_ElasticStack.Version` (for example 3.8.2_6.6.2) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch.
 | 
			
		||||
 | 
			
		||||
## Credits and Thank you
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										2
									
								
								VERSION
									
									
									
									
									
								
							
							
						
						
									
										2
									
								
								VERSION
									
									
									
									
									
								
							@@ -1,2 +1,2 @@
 | 
			
		||||
WAZUH-DOCKER_VERSION="3.8.2_6.5.4"
 | 
			
		||||
WAZUH-DOCKER_VERSION="3.8.2_6.6.2"
 | 
			
		||||
REVISION="3802"
 | 
			
		||||
 
 | 
			
		||||
@@ -3,7 +3,7 @@ version: '2'
 | 
			
		||||
 | 
			
		||||
services:
 | 
			
		||||
  wazuh:
 | 
			
		||||
    image: wazuh/wazuh:3.8.2_6.5.4
 | 
			
		||||
    image: wazuh/wazuh:3.8.2_6.6.2
 | 
			
		||||
    hostname: wazuh-manager
 | 
			
		||||
    restart: always
 | 
			
		||||
    ports:
 | 
			
		||||
@@ -14,7 +14,7 @@ services:
 | 
			
		||||
    depends_on:
 | 
			
		||||
      - logstash
 | 
			
		||||
  logstash:
 | 
			
		||||
    image: wazuh/wazuh-logstash:3.8.2_6.5.4
 | 
			
		||||
    image: wazuh/wazuh-logstash:3.8.2_6.6.2
 | 
			
		||||
    hostname: logstash
 | 
			
		||||
    restart: always
 | 
			
		||||
    links:
 | 
			
		||||
@@ -26,7 +26,7 @@ services:
 | 
			
		||||
    environment:
 | 
			
		||||
      - LS_HEAP_SIZE=2048m
 | 
			
		||||
  elasticsearch:
 | 
			
		||||
    image: wazuh/wazuh-elasticsearch:3.8.2_6.5.4
 | 
			
		||||
    image: wazuh/wazuh-elasticsearch:3.8.2_6.6.2
 | 
			
		||||
    hostname: elasticsearch
 | 
			
		||||
    restart: always
 | 
			
		||||
    ports:
 | 
			
		||||
@@ -43,7 +43,7 @@ services:
 | 
			
		||||
        hard: -1
 | 
			
		||||
    mem_limit: 2g
 | 
			
		||||
  kibana:
 | 
			
		||||
    image: wazuh/wazuh-kibana:3.8.2_6.5.4
 | 
			
		||||
    image: wazuh/wazuh-kibana:3.8.2_6.6.2
 | 
			
		||||
    hostname: kibana
 | 
			
		||||
    restart: always
 | 
			
		||||
    depends_on:
 | 
			
		||||
@@ -52,11 +52,12 @@ services:
 | 
			
		||||
      - elasticsearch:elasticsearch
 | 
			
		||||
      - wazuh:wazuh
 | 
			
		||||
  nginx:
 | 
			
		||||
    image: wazuh/wazuh-nginx:3.8.2_6.5.4
 | 
			
		||||
    image: wazuh/wazuh-nginx:3.8.2_6.6.2
 | 
			
		||||
    hostname: nginx
 | 
			
		||||
    restart: always
 | 
			
		||||
    environment:
 | 
			
		||||
      - NGINX_PORT=443
 | 
			
		||||
      - NGINX_CREDENTIALS
 | 
			
		||||
    ports:
 | 
			
		||||
      - "80:80"
 | 
			
		||||
      - "443:443"
 | 
			
		||||
 
 | 
			
		||||
@@ -1,5 +1,5 @@
 | 
			
		||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
FROM docker.elastic.co/elasticsearch/elasticsearch:6.5.4
 | 
			
		||||
FROM docker.elastic.co/elasticsearch/elasticsearch:6.6.2
 | 
			
		||||
 | 
			
		||||
ENV ALERTS_SHARDS="1" \
 | 
			
		||||
    ALERTS_REPLICAS="0"
 | 
			
		||||
@@ -9,6 +9,8 @@ ENV API_USER="foo" \
 | 
			
		||||
 | 
			
		||||
ENV XPACK_ML="true" 
 | 
			
		||||
 | 
			
		||||
ENV ENABLE_CONFIGURE_S3="false"
 | 
			
		||||
 | 
			
		||||
ENV TEMPLATE_VERSION=v3.8.2
 | 
			
		||||
 | 
			
		||||
ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/wazuh-elastic6-template-alerts.json /usr/share/elasticsearch/config
 | 
			
		||||
@@ -21,5 +23,10 @@ COPY --chown=elasticsearch:elasticsearch ./config/load_settings.sh ./
 | 
			
		||||
 | 
			
		||||
RUN chmod +x ./load_settings.sh
 | 
			
		||||
 | 
			
		||||
RUN elasticsearch-plugin install --batch repository-s3
 | 
			
		||||
 | 
			
		||||
COPY config/configure_s3.sh ./config/configure_s3.sh
 | 
			
		||||
RUN chmod 755 ./config/configure_s3.sh
 | 
			
		||||
 | 
			
		||||
ENTRYPOINT ["/entrypoint.sh"]
 | 
			
		||||
CMD ["elasticsearch"]
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										76
									
								
								elasticsearch/config/configure_s3.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										76
									
								
								elasticsearch/config/configure_s3.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,76 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
 | 
			
		||||
set -e
 | 
			
		||||
 | 
			
		||||
# Check number of arguments passed to configure_s3.sh. If it is different from 4 or 5, the process will finish with error.
 | 
			
		||||
# param 1: number of arguments passed to configure_s3.sh
 | 
			
		||||
 | 
			
		||||
function CheckArgs()
 | 
			
		||||
{
 | 
			
		||||
    if [ $1 != 4 ] && [ $1 != 5 ];then
 | 
			
		||||
        echo "Use: configure_s3.sh <Elastic_Server_IP:Port> <Bucket> <Path> <RepositoryName> (By default <current_elasticsearch_major_version> is added to the path and the repository name)"
 | 
			
		||||
        echo "or use: configure_s3.sh <Elastic_Server_IP:Port> <Bucket> <Path> <RepositoryName> <Elasticsearch major version>" 
 | 
			
		||||
        exit 1
 | 
			
		||||
 | 
			
		||||
    fi
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Create S3 repository from base_path <path>/<elasticsearch_major_version> (if there is no <Elasticsearch major version> argument, current version is added)
 | 
			
		||||
# Repository name would be <RepositoryName>-<elasticsearch_major_version> (if there is no <Elasticsearch major version> argument, current version is added)
 | 
			
		||||
# param 1: <Elastic_Server_IP:Port>
 | 
			
		||||
# param 2: <Bucket>
 | 
			
		||||
# param 3: <Path>
 | 
			
		||||
# param 4: <RepositoryName>
 | 
			
		||||
# param 5: Optional <Elasticsearch major version>
 | 
			
		||||
# output: It will show "acknowledged" if the repository has been successfully created
 | 
			
		||||
 | 
			
		||||
function CreateRepo()
 | 
			
		||||
{
 | 
			
		||||
 | 
			
		||||
    elastic_ip_port="$2"
 | 
			
		||||
    bucket_name="$3"
 | 
			
		||||
    path="$4"
 | 
			
		||||
    repository_name="$5"
 | 
			
		||||
 | 
			
		||||
    if [ $1 == 5 ];then
 | 
			
		||||
        version="$6"
 | 
			
		||||
    else
 | 
			
		||||
        version=`curl -s $elastic_ip_port | grep number | cut -d"\"" -f4 | cut -c1`
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    if ! [[ "$version" =~ ^[0-9]+$ ]];then
 | 
			
		||||
        echo "Elasticsearch major version must be an integer"
 | 
			
		||||
        exit 1
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    repository="$repository_name-$version"
 | 
			
		||||
    s3_path="$path/$version"
 | 
			
		||||
 | 
			
		||||
    curl -X PUT "$elastic_ip_port/_snapshot/$repository" -H 'Content-Type: application/json' -d'
 | 
			
		||||
        {
 | 
			
		||||
            "type": "s3",
 | 
			
		||||
            "settings": {
 | 
			
		||||
            "bucket": "'$bucket_name'",
 | 
			
		||||
            "base_path": "'$s3_path'"
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    '
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# Run functions CheckArgs and CreateRepo
 | 
			
		||||
# param 1: number of arguments passed to configure_s3.sh
 | 
			
		||||
# param 2: <Elastic_Server_IP:Port>
 | 
			
		||||
# param 3: <Bucket>
 | 
			
		||||
# param 4: <Path>
 | 
			
		||||
# param 5: <RepositoryName>
 | 
			
		||||
# param 6: Optional <Elasticsearch major version>
 | 
			
		||||
 | 
			
		||||
function Main()
 | 
			
		||||
{
 | 
			
		||||
    CheckArgs $1
 | 
			
		||||
 | 
			
		||||
    CreateRepo $1 $2 $3 $4 $5 $6
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
Main $# $1 $2 $3 $4 $5
 | 
			
		||||
@@ -23,6 +23,25 @@ done
 | 
			
		||||
 | 
			
		||||
>&2 echo "Elastic is up - executing command"
 | 
			
		||||
 | 
			
		||||
if [ $ENABLE_CONFIGURE_S3 ]; then
 | 
			
		||||
  #Wait for Elasticsearch to be ready to create the repository
 | 
			
		||||
  sleep 10
 | 
			
		||||
  IP_PORT="${ELASTICSEARCH_IP}:${ELASTICSEARCH_PORT}"
 | 
			
		||||
 | 
			
		||||
  if [ "x$S3_PATH" != "x" ]; then 
 | 
			
		||||
 | 
			
		||||
    if [ "x$S3_ELASTIC_MAJOR" != "x" ]; then 
 | 
			
		||||
      ./config/configure_s3.sh $IP_PORT $S3_BUCKET_NAME $S3_PATH $S3_REPOSITORY_NAME $S3_ELASTIC_MAJOR 
 | 
			
		||||
 | 
			
		||||
    else
 | 
			
		||||
      ./config/configure_s3.sh $IP_PORT $S3_BUCKET_NAME $S3_PATH $S3_REPOSITORY_NAME 
 | 
			
		||||
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
  fi
 | 
			
		||||
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
#Insert default templates
 | 
			
		||||
 | 
			
		||||
sed -i 's|    "index.refresh_interval": "5s"|    "index.refresh_interval": "5s",    "number_of_shards" :   '"${ALERTS_SHARDS}"',    "number_of_replicas" : '"${ALERTS_REPLICAS}"'|' /usr/share/elasticsearch/config/wazuh-elastic6-template-alerts.json
 | 
			
		||||
 
 | 
			
		||||
@@ -1,6 +1,6 @@
 | 
			
		||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
FROM docker.elastic.co/kibana/kibana:6.5.4
 | 
			
		||||
ARG WAZUH_APP_VERSION=3.8.2_6.5.4
 | 
			
		||||
FROM docker.elastic.co/kibana/kibana:6.6.2
 | 
			
		||||
ARG WAZUH_APP_VERSION=3.8.2_6.6.2
 | 
			
		||||
USER root
 | 
			
		||||
 | 
			
		||||
ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp
 | 
			
		||||
@@ -49,6 +49,7 @@ ARG XPACK_DEVTOOLS="true"
 | 
			
		||||
ARG XPACK_MONITORING="true"
 | 
			
		||||
ARG XPACK_APM="true"
 | 
			
		||||
 | 
			
		||||
ARG CHANGE_WELCOME="false"
 | 
			
		||||
 | 
			
		||||
COPY --chown=kibana:kibana ./config/wazuh_app_config.sh ./
 | 
			
		||||
 | 
			
		||||
@@ -64,6 +65,12 @@ RUN chmod +x ./xpack_config.sh
 | 
			
		||||
 | 
			
		||||
RUN ./xpack_config.sh
 | 
			
		||||
 | 
			
		||||
COPY --chown=kibana:kibana ./config/welcome_wazuh.sh ./
 | 
			
		||||
 | 
			
		||||
RUN chmod +x ./welcome_wazuh.sh
 | 
			
		||||
 | 
			
		||||
RUN ./welcome_wazuh.sh
 | 
			
		||||
 | 
			
		||||
RUN /usr/local/bin/kibana-docker --optimize
 | 
			
		||||
 | 
			
		||||
ENTRYPOINT /entrypoint.sh
 | 
			
		||||
 
 | 
			
		||||
@@ -3,6 +3,10 @@
 | 
			
		||||
 | 
			
		||||
set -e
 | 
			
		||||
 | 
			
		||||
##############################################################################
 | 
			
		||||
# Waiting for elasticsearch
 | 
			
		||||
##############################################################################
 | 
			
		||||
 | 
			
		||||
if [ "x${ELASTICSEARCH_URL}" = "x" ]; then
 | 
			
		||||
  el_url="http://elasticsearch:9200"
 | 
			
		||||
else
 | 
			
		||||
@@ -10,11 +14,32 @@ else
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
until curl -XGET $el_url; do
 | 
			
		||||
  >&2 echo "Elastic is unavailable - sleeping"
 | 
			
		||||
  >&2 echo "Elastic is unavailable - sleeping."
 | 
			
		||||
  sleep 5
 | 
			
		||||
done
 | 
			
		||||
 | 
			
		||||
>&2 echo "Elastic is up - executing command"
 | 
			
		||||
sleep 2
 | 
			
		||||
 | 
			
		||||
>&2 echo "Elasticsearch is up."
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
##############################################################################
 | 
			
		||||
# Waiting for wazuh alerts template
 | 
			
		||||
##############################################################################
 | 
			
		||||
 | 
			
		||||
strlen=0
 | 
			
		||||
 | 
			
		||||
while [[ $strlen -eq 0 ]]
 | 
			
		||||
do
 | 
			
		||||
  template=$(curl $el_url/_cat/templates/wazuh -s)
 | 
			
		||||
  strlen=${#template}
 | 
			
		||||
  >&2 echo "Wazuh alerts template not loaded - sleeping."
 | 
			
		||||
  sleep 2
 | 
			
		||||
done
 | 
			
		||||
 | 
			
		||||
sleep 2
 | 
			
		||||
 | 
			
		||||
>&2 echo "Wazuh alerts template is loaded."
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
./wazuh_app_config.sh
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										23
									
								
								kibana/config/welcome_wazuh.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										23
									
								
								kibana/config/welcome_wazuh.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,23 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
 | 
			
		||||
if [[ $CHANGE_WELCOME == "true" ]]
 | 
			
		||||
then
 | 
			
		||||
 | 
			
		||||
    rm -rf ./optimize/bundles
 | 
			
		||||
 | 
			
		||||
    kibana_path="/usr/share/kibana"
 | 
			
		||||
    # Set Wazuh app as the default landing page
 | 
			
		||||
    echo "Set Wazuh app as the default landing page"
 | 
			
		||||
    echo "server.defaultRoute: /app/wazuh" >> /usr/share/kibana/config/kibana.yml
 | 
			
		||||
 | 
			
		||||
    # Redirect Kibana welcome screen to Discover
 | 
			
		||||
    echo "Redirect Kibana welcome screen to Discover"
 | 
			
		||||
    sed -i "s:'/app/kibana#/home':'/app/wazuh':g" $kibana_path/src/ui/public/chrome/directives/global_nav/global_nav.html
 | 
			
		||||
    sed -i "s:'/app/kibana#/home':'/app/wazuh':g" $kibana_path/src/ui/public/chrome/directives/header_global_nav/header_global_nav.js
 | 
			
		||||
 | 
			
		||||
    # Redirect Kibana welcome screen to Discover
 | 
			
		||||
    echo "Hide undesired links"
 | 
			
		||||
    sed -i 's#visible: true#visible: false#g' $kibana_path/node_modules/x-pack/plugins/rollup/public/crud_app/index.js
 | 
			
		||||
    sed -i 's#visible: true#visible: false#g' $kibana_path/node_modules/x-pack/plugins/license_management/public/management_section.js
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
@@ -1,12 +1,12 @@
 | 
			
		||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
FROM docker.elastic.co/logstash/logstash:6.5.4
 | 
			
		||||
FROM docker.elastic.co/logstash/logstash:6.6.2
 | 
			
		||||
 | 
			
		||||
COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh
 | 
			
		||||
 | 
			
		||||
RUN chmod 755 /entrypoint.sh
 | 
			
		||||
 | 
			
		||||
RUN rm -f /usr/share/logstash/pipeline/logstash.conf
 | 
			
		||||
 | 
			
		||||
COPY config/01-wazuh.conf /usr/share/logstash/pipeline/01-wazuh.conf
 | 
			
		||||
 | 
			
		||||
USER root
 | 
			
		||||
COPY config/run.sh /run.sh
 | 
			
		||||
RUN chmod +x /run.sh
 | 
			
		||||
 | 
			
		||||
ENTRYPOINT ["/run.sh"]
 | 
			
		||||
ENTRYPOINT /entrypoint.sh
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										72
									
								
								logstash/config/entrypoint.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										72
									
								
								logstash/config/entrypoint.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,72 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
#
 | 
			
		||||
# OSSEC container bootstrap. See the README for information of the environment
 | 
			
		||||
# variables expected by this script.
 | 
			
		||||
#
 | 
			
		||||
 | 
			
		||||
set -e
 | 
			
		||||
 | 
			
		||||
##############################################################################
 | 
			
		||||
# Waiting for elasticsearch
 | 
			
		||||
##############################################################################
 | 
			
		||||
 | 
			
		||||
if [ "x${ELASTICSEARCH_URL}" = "x" ]; then
 | 
			
		||||
  el_url="http://elasticsearch:9200"
 | 
			
		||||
else
 | 
			
		||||
  el_url="${ELASTICSEARCH_URL}"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
until curl -XGET $el_url; do
 | 
			
		||||
  >&2 echo "Elastic is unavailable - sleeping."
 | 
			
		||||
  sleep 5
 | 
			
		||||
done
 | 
			
		||||
 | 
			
		||||
sleep 2
 | 
			
		||||
 | 
			
		||||
>&2 echo "Elasticsearch is up."
 | 
			
		||||
 | 
			
		||||
##############################################################################
 | 
			
		||||
# Waiting for wazuh alerts template
 | 
			
		||||
##############################################################################
 | 
			
		||||
 | 
			
		||||
strlen=0
 | 
			
		||||
 | 
			
		||||
while [[ $strlen -eq 0 ]]
 | 
			
		||||
do
 | 
			
		||||
  template=$(curl $el_url/_cat/templates/wazuh -s)
 | 
			
		||||
  strlen=${#template}
 | 
			
		||||
  >&2 echo "Wazuh alerts template not loaded - sleeping."
 | 
			
		||||
  sleep 2
 | 
			
		||||
done
 | 
			
		||||
 | 
			
		||||
sleep 2
 | 
			
		||||
 | 
			
		||||
>&2 echo "Wazuh alerts template is loaded."
 | 
			
		||||
 | 
			
		||||
##############################################################################
 | 
			
		||||
# Customize logstash output ip
 | 
			
		||||
##############################################################################
 | 
			
		||||
 | 
			
		||||
if [ "$LOGSTASH_OUTPUT" != "" ]; then
 | 
			
		||||
  >&2 echo "Customize Logstash ouput ip."
 | 
			
		||||
  sed -i "s/elasticsearch:9200/$LOGSTASH_OUTPUT:9200/" /usr/share/logstash/pipeline/01-wazuh.conf
 | 
			
		||||
  sed -i "s/elasticsearch:9200/$LOGSTASH_OUTPUT:9200/" /usr/share/logstash/config/logstash.yml 
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
##############################################################################
 | 
			
		||||
# Map environment variables to entries in logstash.yml.
 | 
			
		||||
# Note that this will mutate logstash.yml in place if any such settings are found.
 | 
			
		||||
# This may be undesirable, especially if logstash.yml is bind-mounted from the
 | 
			
		||||
# host system.
 | 
			
		||||
##############################################################################
 | 
			
		||||
 | 
			
		||||
env2yaml /usr/share/logstash/config/logstash.yml
 | 
			
		||||
 | 
			
		||||
export LS_JAVA_OPTS="-Dls.cgroup.cpuacct.path.override=/ -Dls.cgroup.cpu.path.override=/ $LS_JAVA_OPTS"
 | 
			
		||||
 | 
			
		||||
if [[ -z $1 ]] || [[ ${1:0:1} == '-' ]] ; then
 | 
			
		||||
  exec logstash "$@"
 | 
			
		||||
else
 | 
			
		||||
  exec "$@"
 | 
			
		||||
fi
 | 
			
		||||
@@ -1,16 +0,0 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
#
 | 
			
		||||
# OSSEC container bootstrap. See the README for information of the environment
 | 
			
		||||
# variables expected by this script.
 | 
			
		||||
#
 | 
			
		||||
 | 
			
		||||
##############################################################################
 | 
			
		||||
# Customize logstash output ip
 | 
			
		||||
##############################################################################
 | 
			
		||||
if [ "$LOGSTASH_OUTPUT" != "" ]; then
 | 
			
		||||
  sed -i "s/elasticsearch:9200/$LOGSTASH_OUTPUT:9200/" /usr/share/logstash/pipeline/01-wazuh.conf
 | 
			
		||||
  sed -i "s/elasticsearch:9200/$LOGSTASH_OUTPUT:9200/" /usr/share/logstash/config/logstash.yml 
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
/usr/local/bin/docker-entrypoint
 | 
			
		||||
@@ -1,4 +1,4 @@
 | 
			
		||||
#!/bin/sh
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
 | 
			
		||||
set -e
 | 
			
		||||
@@ -12,15 +12,37 @@ else
 | 
			
		||||
  echo "SSL certificates already present"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
# Configuring default credentiales.
 | 
			
		||||
# Setting users credentials.
 | 
			
		||||
# In order to set NGINX_CREDENTIALS, before "docker-compose up -d" run (a or b):
 | 
			
		||||
#
 | 
			
		||||
# a) export NGINX_CREDENTIALS="user1:pass1;user2:pass2;" or
 | 
			
		||||
#    export NGINX_CREDENTIALS="user1:pass1;user2:pass2"
 | 
			
		||||
#
 | 
			
		||||
# b) Set NGINX_CREDENTIALS in docker-compose.yml:
 | 
			
		||||
#    NGINX_CREDENTIALS=user1:pass1;user2:pass2; or
 | 
			
		||||
#    NGINX_CREDENTIALS=user1:pass1;user2:pass2
 | 
			
		||||
#
 | 
			
		||||
if [ ! -f /etc/nginx/conf.d/kibana.htpasswd ]; then
 | 
			
		||||
  echo "Setting Nginx credentials"
 | 
			
		||||
  echo "Setting users credentials"
 | 
			
		||||
  if [ ! -z "$NGINX_CREDENTIALS" ]; then
 | 
			
		||||
    IFS=';' read -r -a users <<< "$NGINX_CREDENTIALS"
 | 
			
		||||
    for index in "${!users[@]}"
 | 
			
		||||
    do
 | 
			
		||||
      IFS=':' read -r -a credentials <<< "${users[index]}"
 | 
			
		||||
      if [ $index -eq 0 ]; then
 | 
			
		||||
        echo ${credentials[1]}|htpasswd -i -c /etc/nginx/conf.d/kibana.htpasswd ${credentials[0]} >/dev/null
 | 
			
		||||
      else
 | 
			
		||||
        echo ${credentials[1]}|htpasswd -i /etc/nginx/conf.d/kibana.htpasswd  ${credentials[0]} >/dev/null
 | 
			
		||||
      fi
 | 
			
		||||
    done
 | 
			
		||||
  else
 | 
			
		||||
    # NGINX_PWD and NGINX_NAME are declared in nginx/Dockerfile 
 | 
			
		||||
    echo $NGINX_PWD|htpasswd -i -c /etc/nginx/conf.d/kibana.htpasswd $NGINX_NAME >/dev/null
 | 
			
		||||
  fi
 | 
			
		||||
else
 | 
			
		||||
  echo "Kibana credentials already configured"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
if [ "x${NGINX_PORT}" = "x" ]; then
 | 
			
		||||
  NGINX_PORT=443
 | 
			
		||||
fi
 | 
			
		||||
 
 | 
			
		||||
@@ -1,6 +1,6 @@
 | 
			
		||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
FROM phusion/baseimage:latest
 | 
			
		||||
ARG FILEBEAT_VERSION=6.5.4
 | 
			
		||||
ARG FILEBEAT_VERSION=6.6.2
 | 
			
		||||
ARG WAZUH_VERSION=3.8.2-1
 | 
			
		||||
 | 
			
		||||
ENV API_USER="foo" \
 | 
			
		||||
@@ -17,7 +17,8 @@ RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /
 | 
			
		||||
RUN add-apt-repository universe && apt-get update && apt-get upgrade -y -o Dpkg::Options::="--force-confold" && \
 | 
			
		||||
   apt-get --no-install-recommends --no-install-suggests -y install openssl postfix bsd-mailx python-boto python-pip  \
 | 
			
		||||
   apt-transport-https vim expect nodejs python-cryptography mailutils libsasl2-modules wazuh-manager=${WAZUH_VERSION} \
 | 
			
		||||
   wazuh-api=${WAZUH_VERSION} && apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
 | 
			
		||||
   wazuh-api=${WAZUH_VERSION} && apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* && rm -f \
 | 
			
		||||
   /var/ossec/logs/alerts/*/*/*.log && rm -f /var/ossec/logs/alerts/*/*/*.json
 | 
			
		||||
 | 
			
		||||
# Adding first run script and entrypoint
 | 
			
		||||
COPY config/data_dirs.env /data_dirs.env
 | 
			
		||||
 
 | 
			
		||||
@@ -8,6 +8,7 @@ filebeat:
 | 
			
		||||
    json.message_key: log
 | 
			
		||||
    json.keys_under_root: true
 | 
			
		||||
    json.overwrite_keys: true
 | 
			
		||||
    tail_files: true
 | 
			
		||||
 | 
			
		||||
output:
 | 
			
		||||
 logstash:
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user