mirror of
https://github.com/wazuh/wazuh-docker.git
synced 2025-11-03 21:43:15 +00:00
Compare commits
33 Commits
v3.7.0_6.5
...
3.7.2_6.5.
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8913df6284 | ||
|
|
b8294dba69 | ||
|
|
5123f92551 | ||
|
|
81035c39db | ||
|
|
70e491fa6f | ||
|
|
57fd4d8859 | ||
|
|
7c9ee9b256 | ||
|
|
f3655b1360 | ||
|
|
0cc8be2142 | ||
|
|
dff13dfc7a | ||
|
|
ab90a9a95b | ||
|
|
7a9b32fbd9 | ||
|
|
ef5fbe15a5 | ||
|
|
a8e1661aa6 | ||
|
|
c7abb4239f | ||
|
|
68b4703f7a | ||
|
|
2e66d5f3ee | ||
|
|
020047aa8f | ||
|
|
2a03d08a5b | ||
|
|
40a74df00d | ||
|
|
05fa996ffd | ||
|
|
edd2e250e8 | ||
|
|
5e3b25aa95 | ||
|
|
49663b71bb | ||
|
|
77f123460e | ||
|
|
458bfcde09 | ||
|
|
12bb0cba4a | ||
|
|
608b25df4c | ||
|
|
7cce0d9c9e | ||
|
|
cd0d180c93 | ||
|
|
16335e1f70 | ||
|
|
e3e81a4671 | ||
|
|
6fbae577dd |
27
CHANGELOG.md
27
CHANGELOG.md
@@ -1,6 +1,33 @@
|
|||||||
# Change Log
|
# Change Log
|
||||||
All notable changes to this project will be documented in this file.
|
All notable changes to this project will be documented in this file.
|
||||||
|
|
||||||
|
## Wazuh Docker v3.7.2_6.5.4
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Add Kibana environmental variables for Wazuh APP config.yml. ([#89](https://github.com/wazuh/wazuh-docker/pull/89))
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Update Elastic Stack version to 6.5.4. ([#82](https://github.com/wazuh/wazuh-docker/pull/82))
|
||||||
|
- Add env credentials for nginx. ([#86](https://github.com/wazuh/wazuh-docker/pull/86))
|
||||||
|
- Improve filebeat configuration ([#88](https://github.com/wazuh/wazuh-docker/pull/88))
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Temporary fix for Wazuh cluster master node in Kubernetes. ([#84](https://github.com/wazuh/wazuh-docker/pull/84))
|
||||||
|
|
||||||
|
## Wazuh Docker v3.7.2_6.5.3
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Erasing temporary fix for AWS integration. ([#81](https://github.com/wazuh/wazuh-docker/pull/81))
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Upgrading errors due to wrong files. ([#80](https://github.com/wazuh/wazuh-docker/pull/80))
|
||||||
|
|
||||||
|
|
||||||
## Wazuh Docker v3.7.0_6.5.0
|
## Wazuh Docker v3.7.0_6.5.0
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ In addition, a docker-compose file is provided to launch the containers mentione
|
|||||||
|
|
||||||
## Current release
|
## Current release
|
||||||
|
|
||||||
Containers are currently tested on Wazuh version 3.7.0 and Elastic Stack version 6.4.3. We will do our best to keep this repository updated to latest versions of both Wazuh and Elastic Stack.
|
Containers are currently tested on Wazuh version 3.7.2 and Elastic Stack version 6.5.4. We will do our best to keep this repository updated to latest versions of both Wazuh and Elastic Stack.
|
||||||
|
|
||||||
## Directory structure
|
## Directory structure
|
||||||
|
|
||||||
|
|||||||
4
VERSION
4
VERSION
@@ -1,2 +1,2 @@
|
|||||||
WAZUH-DOCKER_VERSION="3.7.0_6.5.0"
|
WAZUH-DOCKER_VERSION="3.7.2_6.5.4"
|
||||||
REVISION="3701"
|
REVISION="3732"
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ version: '2'
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
wazuh:
|
wazuh:
|
||||||
image: wazuh/wazuh:3.7.0_6.5.0
|
image: wazuh/wazuh:3.7.2_6.5.4
|
||||||
hostname: wazuh-manager
|
hostname: wazuh-manager
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
@@ -23,7 +23,7 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
- logstash
|
- logstash
|
||||||
logstash:
|
logstash:
|
||||||
image: wazuh/wazuh-logstash:3.7.0_6.5.0
|
image: wazuh/wazuh-logstash:3.7.2_6.5.4
|
||||||
hostname: logstash
|
hostname: logstash
|
||||||
restart: always
|
restart: always
|
||||||
# volumes:
|
# volumes:
|
||||||
@@ -39,7 +39,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- LS_HEAP_SIZE=2048m
|
- LS_HEAP_SIZE=2048m
|
||||||
elasticsearch:
|
elasticsearch:
|
||||||
image: docker.elastic.co/elasticsearch/elasticsearch:6.5.0
|
image: docker.elastic.co/elasticsearch/elasticsearch:6.5.4
|
||||||
hostname: elasticsearch
|
hostname: elasticsearch
|
||||||
restart: always
|
restart: always
|
||||||
ports:
|
ports:
|
||||||
@@ -61,7 +61,7 @@ services:
|
|||||||
networks:
|
networks:
|
||||||
- docker_elk
|
- docker_elk
|
||||||
kibana:
|
kibana:
|
||||||
image: wazuh/wazuh-kibana:3.7.0_6.5.0
|
image: wazuh/wazuh-kibana:3.7.2_6.5.4
|
||||||
hostname: kibana
|
hostname: kibana
|
||||||
restart: always
|
restart: always
|
||||||
# ports:
|
# ports:
|
||||||
@@ -76,7 +76,7 @@ services:
|
|||||||
- elasticsearch:elasticsearch
|
- elasticsearch:elasticsearch
|
||||||
- wazuh:wazuh
|
- wazuh:wazuh
|
||||||
nginx:
|
nginx:
|
||||||
image: wazuh/wazuh-nginx:3.7.0_6.5.0
|
image: wazuh/wazuh-nginx:3.7.2_6.5.4
|
||||||
hostname: nginx
|
hostname: nginx
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
||||||
FROM docker.elastic.co/kibana/kibana:6.5.0
|
FROM docker.elastic.co/kibana/kibana:6.5.4
|
||||||
ARG WAZUH_APP_VERSION=3.7.0_6.5.0
|
ARG WAZUH_APP_VERSION=3.7.2_6.5.4
|
||||||
USER root
|
USER root
|
||||||
|
|
||||||
ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp
|
ADD https://packages.wazuh.com/wazuhapp/wazuhapp-${WAZUH_APP_VERSION}.zip /tmp
|
||||||
@@ -16,4 +16,37 @@ RUN chmod 755 /entrypoint.sh
|
|||||||
|
|
||||||
USER kibana
|
USER kibana
|
||||||
|
|
||||||
|
ENV PATTERN="" \
|
||||||
|
CHECKS_PATTERN="" \
|
||||||
|
CHECKS_TEMPLATE="" \
|
||||||
|
CHECKS_API="" \
|
||||||
|
CHECKS_SETUP="" \
|
||||||
|
EXTENSIONS_PCI="" \
|
||||||
|
EXTENSIONS_GDPR="" \
|
||||||
|
EXTENSIONS_AUDIT="" \
|
||||||
|
EXTENSIONS_OSCAP="" \
|
||||||
|
EXTENSIONS_CISCAT="" \
|
||||||
|
EXTENSIONS_AWS="" \
|
||||||
|
EXTENSIONS_VIRUSTOTAL="" \
|
||||||
|
EXTENSIONS_OSQUERY="" \
|
||||||
|
APP_TIMEOUT="" \
|
||||||
|
WAZUH_SHARDS="" \
|
||||||
|
WAZUH_REPLICAS="" \
|
||||||
|
WAZUH_VERSION_SHARDS="" \
|
||||||
|
WAZUH_VERSION_REPLICAS="" \
|
||||||
|
IP_SELECTOR="" \
|
||||||
|
IP_IGNORE="" \
|
||||||
|
XPACK_RBAC_ENABLED="" \
|
||||||
|
WAZUH_MONITORING_ENABLED="" \
|
||||||
|
WAZUH_MONITORING_FREQUENCY="" \
|
||||||
|
WAZUH_MONITORING_SHARDS="" \
|
||||||
|
WAZUH_MONITORING_REPLICAS="" \
|
||||||
|
ADMIN_PRIVILEGES=""
|
||||||
|
|
||||||
|
|
||||||
|
COPY --chown=kibana:kibana ./config/wazuh_app_config.sh ./
|
||||||
|
|
||||||
|
RUN chmod +x ./wazuh_app_config.sh
|
||||||
|
|
||||||
ENTRYPOINT /entrypoint.sh
|
ENTRYPOINT /entrypoint.sh
|
||||||
|
|
||||||
|
|||||||
@@ -50,6 +50,9 @@ if [ "x$CONFIG_CODE" = "x404" ]; then
|
|||||||
else
|
else
|
||||||
echo "Wazuh APP already configured"
|
echo "Wazuh APP already configured"
|
||||||
fi
|
fi
|
||||||
|
sleep 5
|
||||||
|
|
||||||
|
./wazuh_app_config.sh
|
||||||
|
|
||||||
sleep 5
|
sleep 5
|
||||||
|
|
||||||
|
|||||||
40
kibana/config/wazuh_app_config.sh
Normal file
40
kibana/config/wazuh_app_config.sh
Normal file
@@ -0,0 +1,40 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
||||||
|
|
||||||
|
kibana_config_file="/usr/share/kibana/plugins/wazuh/config.yml"
|
||||||
|
|
||||||
|
declare -A CONFIG_MAP=(
|
||||||
|
[pattern]=$PATTERN
|
||||||
|
[checks.pattern]=$CHECKS_PATTERN
|
||||||
|
[checks.template]=$CHECKS_TEMPLATE
|
||||||
|
[checks.api]=$CHECKS_API
|
||||||
|
[checks.setup]=$CHECKS_SETUP
|
||||||
|
[extensions.pci]=$EXTENSIONS_PCI
|
||||||
|
[extensions.gdpr]=$EXTENSIONS_GDPR
|
||||||
|
[extensions.audit]=$EXTENSIONS_AUDIT
|
||||||
|
[extensions.oscap]=$EXTENSIONS_OSCAP
|
||||||
|
[extensions.ciscat]=$EXTENSIONS_CISCAT
|
||||||
|
[extensions.aws]=$EXTENSIONS_AWS
|
||||||
|
[extensions.virustotal]=$EXTENSIONS_VIRUSTOTAL
|
||||||
|
[extensions.osquery]=$EXTENSIONS_OSQUERY
|
||||||
|
[timeout]=$APP_TIMEOUT
|
||||||
|
[wazuh.shards]=$WAZUH_SHARDS
|
||||||
|
[wazuh.replicas]=$WAZUH_REPLICAS
|
||||||
|
[wazuh-version.shards]=$WAZUH_VERSION_SHARDS
|
||||||
|
[wazuh-version.replicas]=$WAZUH_VERSION_REPLICAS
|
||||||
|
[ip.selector]=$IP_SELECTOR
|
||||||
|
[ip.ignore]=$IP_IGNORE
|
||||||
|
[xpack.rbac.enabled]=$XPACK_RBAC_ENABLED
|
||||||
|
[wazuh.monitoring.enabled]=$WAZUH_MONITORING_ENABLED
|
||||||
|
[wazuh.monitoring.frequency]=$WAZUH_MONITORING_FREQUENCY
|
||||||
|
[wazuh.monitoring.shards]=$WAZUH_MONITORING_SHARDS
|
||||||
|
[wazuh.monitoring.replicas]=$WAZUH_MONITORING_REPLICAS
|
||||||
|
[admin]=$ADMIN_PRIVILEGES
|
||||||
|
)
|
||||||
|
|
||||||
|
for i in "${!CONFIG_MAP[@]}"
|
||||||
|
do
|
||||||
|
if [ "${CONFIG_MAP[$i]}" != "" ]; then
|
||||||
|
sed -i 's/.*#'"$i"'.*/'"$i"': '"${CONFIG_MAP[$i]}"'/' $kibana_config_file
|
||||||
|
fi
|
||||||
|
done
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
||||||
FROM docker.elastic.co/logstash/logstash:6.5.0
|
FROM docker.elastic.co/logstash/logstash:6.5.4
|
||||||
|
|
||||||
RUN rm -f /usr/share/logstash/pipeline/logstash.conf
|
RUN rm -f /usr/share/logstash/pipeline/logstash.conf
|
||||||
|
|
||||||
|
|||||||
@@ -13,4 +13,7 @@ RUN apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
|
|||||||
|
|
||||||
VOLUME ["/etc/nginx/conf.d"]
|
VOLUME ["/etc/nginx/conf.d"]
|
||||||
|
|
||||||
|
ENV NGINX_NAME="foo" \
|
||||||
|
NGINX_PWD="bar"
|
||||||
|
|
||||||
ENTRYPOINT /entrypoint.sh
|
ENTRYPOINT /entrypoint.sh
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ fi
|
|||||||
# Configuring default credentiales.
|
# Configuring default credentiales.
|
||||||
if [ ! -f /etc/nginx/conf.d/kibana.htpasswd ]; then
|
if [ ! -f /etc/nginx/conf.d/kibana.htpasswd ]; then
|
||||||
echo "Setting Nginx credentials"
|
echo "Setting Nginx credentials"
|
||||||
echo bar|htpasswd -i -c /etc/nginx/conf.d/kibana.htpasswd foo >/dev/null
|
echo $NGINX_PWD|htpasswd -i -c /etc/nginx/conf.d/kibana.htpasswd $NGINX_NAME >/dev/null
|
||||||
else
|
else
|
||||||
echo "Kibana credentials already configured"
|
echo "Kibana credentials already configured"
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
||||||
FROM phusion/baseimage:latest
|
FROM phusion/baseimage:latest
|
||||||
ARG FILEBEAT_VERSION=6.5.0
|
ARG FILEBEAT_VERSION=6.5.4
|
||||||
ARG WAZUH_VERSION=3.7.0-1
|
ARG WAZUH_VERSION=3.7.2-1
|
||||||
|
|
||||||
# Updating image
|
# Updating image
|
||||||
RUN apt-get update && apt-get upgrade -y -o Dpkg::Options::="--force-confold"
|
RUN apt-get update && apt-get upgrade -y -o Dpkg::Options::="--force-confold"
|
||||||
@@ -76,11 +76,8 @@ RUN mkdir /etc/service/filebeat
|
|||||||
COPY config/filebeat.runit.service /etc/service/filebeat/run
|
COPY config/filebeat.runit.service /etc/service/filebeat/run
|
||||||
RUN chmod +x /etc/service/filebeat/run
|
RUN chmod +x /etc/service/filebeat/run
|
||||||
|
|
||||||
# Temporary fix for AWS integration
|
# Temporary fix for Wazuh cluster master node in Kubernetes
|
||||||
RUN sed -i 's/.*with open*/#wiht open/' /var/ossec/wodles/aws/aws-s3
|
RUN sed -i '87d;88d' /var/ossec/framework/wazuh/cluster/cluster.py
|
||||||
RUN sed -i 's/.*max_queue_buffer = int(kernel_param.read().strip())*/#max_queue_buffer/' /var/ossec/wodles/aws/aws-s3
|
|
||||||
RUN sed -i '784imax_queue_buffer = 0' /var/ossec/wodles/aws/aws-s3
|
|
||||||
RUN sed -i '784s/^/ /' /var/ossec/wodles/aws/aws-s3
|
|
||||||
|
|
||||||
# Run all services
|
# Run all services
|
||||||
ENTRYPOINT ["/entrypoint.sh"]
|
ENTRYPOINT ["/entrypoint.sh"]
|
||||||
|
|||||||
@@ -1,16 +1,6 @@
|
|||||||
i=0
|
i=0
|
||||||
DATA_DIRS[((i++))]="api/configuration"
|
DATA_DIRS[((i++))]="api/configuration"
|
||||||
DATA_DIRS[((i++))]="etc/client.keys"
|
DATA_DIRS[((i++))]="etc"
|
||||||
DATA_DIRS[((i++))]="etc/decoders"
|
|
||||||
DATA_DIRS[((i++))]="etc/lists"
|
|
||||||
DATA_DIRS[((i++))]="etc/local_internal_options.conf"
|
|
||||||
DATA_DIRS[((i++))]="etc/localtime"
|
|
||||||
DATA_DIRS[((i++))]="etc/ossec.conf"
|
|
||||||
DATA_DIRS[((i++))]="etc/rootcheck"
|
|
||||||
DATA_DIRS[((i++))]="etc/rules"
|
|
||||||
DATA_DIRS[((i++))]="etc/shared"
|
|
||||||
DATA_DIRS[((i++))]="etc/sslmanager.cert"
|
|
||||||
DATA_DIRS[((i++))]="etc/sslmanager.key"
|
|
||||||
DATA_DIRS[((i++))]="logs"
|
DATA_DIRS[((i++))]="logs"
|
||||||
DATA_DIRS[((i++))]="queue/db"
|
DATA_DIRS[((i++))]="queue/db"
|
||||||
DATA_DIRS[((i++))]="queue/rootcheck"
|
DATA_DIRS[((i++))]="queue/rootcheck"
|
||||||
|
|||||||
@@ -53,6 +53,12 @@ for ossecdir in "${DATA_DIRS[@]}"; do
|
|||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|
||||||
|
if [ -e ${WAZUH_INSTALL_PATH}/etc-template ]
|
||||||
|
then
|
||||||
|
cp -p /var/ossec/etc-template/internal_options.conf /var/ossec/etc/internal_options.conf
|
||||||
|
fi
|
||||||
|
rm /var/ossec/queue/db/.template.db
|
||||||
|
|
||||||
touch ${DATA_PATH}/process_list
|
touch ${DATA_PATH}/process_list
|
||||||
chgrp ossec ${DATA_PATH}/process_list
|
chgrp ossec ${DATA_PATH}/process_list
|
||||||
chmod g+rw ${DATA_PATH}/process_list
|
chmod g+rw ${DATA_PATH}/process_list
|
||||||
|
|||||||
@@ -1,11 +1,10 @@
|
|||||||
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
# Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2)
|
||||||
filebeat:
|
filebeat:
|
||||||
inputs:
|
prospectors:
|
||||||
- type: log
|
- type: log
|
||||||
paths:
|
paths:
|
||||||
- "/var/ossec/data/logs/alerts/alerts.json"
|
- "/var/ossec/logs/alerts/alerts.json"
|
||||||
fields:
|
document_type: json
|
||||||
document_type: wazuh-alerts
|
|
||||||
json.message_key: log
|
json.message_key: log
|
||||||
json.keys_under_root: true
|
json.keys_under_root: true
|
||||||
json.overwrite_keys: true
|
json.overwrite_keys: true
|
||||||
|
|||||||
Reference in New Issue
Block a user