mirror of
				https://github.com/wazuh/wazuh-docker.git
				synced 2025-11-04 05:53:19 +00:00 
			
		
		
		
	Compare commits
	
		
			1 Commits
		
	
	
		
			v3.10.0_7.
			...
			v3.9.5_7.2
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 
						 | 
					eb34bc3d0d | 
@@ -1,12 +1,6 @@
 | 
			
		||||
# Change Log
 | 
			
		||||
All notable changes to this project will be documented in this file.
 | 
			
		||||
 | 
			
		||||
## Wazuh Docker v3.10.0_7.3.2
 | 
			
		||||
 | 
			
		||||
### Added
 | 
			
		||||
 | 
			
		||||
- Update to Wazuh version 3.10.0_7.3.2
 | 
			
		||||
 | 
			
		||||
## Wazuh Docker v3.9.5_7.2.1
 | 
			
		||||
 | 
			
		||||
### Added
 | 
			
		||||
 
 | 
			
		||||
@@ -57,7 +57,7 @@ In addition, a docker-compose file is provided to launch the containers mentione
 | 
			
		||||
 | 
			
		||||
* `stable` branch on correspond to the latest Wazuh-Docker stable version.
 | 
			
		||||
* `master` branch contains the latest code, be aware of possible bugs on this branch.
 | 
			
		||||
* `Wazuh.Version_ElasticStack.Version` (for example 3.10.0_7.3.2) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch.
 | 
			
		||||
* `Wazuh.Version_ElasticStack.Version` (for example 3.9.5_7.2.1) branch. This branch contains the current release referenced in Docker Hub. The container images are installed under the current version of this branch.
 | 
			
		||||
 | 
			
		||||
## Credits and Thank you
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										4
									
								
								VERSION
									
									
									
									
									
								
							
							
						
						
									
										4
									
								
								VERSION
									
									
									
									
									
								
							@@ -1,2 +1,2 @@
 | 
			
		||||
WAZUH-DOCKER_VERSION="3.10.0_7.3.2"
 | 
			
		||||
REVISION="31000"
 | 
			
		||||
WAZUH-DOCKER_VERSION="3.9.5_7.2.1"
 | 
			
		||||
REVISION="3950"
 | 
			
		||||
@@ -3,7 +3,7 @@ version: '2'
 | 
			
		||||
 | 
			
		||||
services:
 | 
			
		||||
  wazuh:
 | 
			
		||||
    image: wazuh/wazuh:3.10.0_7.3.2
 | 
			
		||||
    image: wazuh/wazuh:3.9.5_7.2.1
 | 
			
		||||
    hostname: wazuh-manager
 | 
			
		||||
    restart: always
 | 
			
		||||
    ports:
 | 
			
		||||
@@ -13,7 +13,7 @@ services:
 | 
			
		||||
      - "55000:55000"
 | 
			
		||||
 | 
			
		||||
  elasticsearch:
 | 
			
		||||
    image: wazuh/wazuh-elasticsearch:3.10.0_7.3.2
 | 
			
		||||
    image: wazuh/wazuh-elasticsearch:3.9.5_7.2.1
 | 
			
		||||
    hostname: elasticsearch
 | 
			
		||||
    restart: always
 | 
			
		||||
    ports:
 | 
			
		||||
@@ -30,7 +30,7 @@ services:
 | 
			
		||||
    mem_limit: 2g
 | 
			
		||||
 | 
			
		||||
  kibana:
 | 
			
		||||
    image: wazuh/wazuh-kibana:3.10.0_7.3.2
 | 
			
		||||
    image: wazuh/wazuh-kibana:3.9.5_7.2.1
 | 
			
		||||
    hostname: kibana
 | 
			
		||||
    restart: always
 | 
			
		||||
    depends_on:
 | 
			
		||||
@@ -39,7 +39,7 @@ services:
 | 
			
		||||
      - elasticsearch:elasticsearch
 | 
			
		||||
      - wazuh:wazuh
 | 
			
		||||
  nginx:
 | 
			
		||||
    image: wazuh/wazuh-nginx:3.10.0_7.3.2
 | 
			
		||||
    image: wazuh/wazuh-nginx:3.9.5_7.2.1
 | 
			
		||||
    hostname: nginx
 | 
			
		||||
    restart: always
 | 
			
		||||
    environment:
 | 
			
		||||
 
 | 
			
		||||
@@ -1,5 +1,5 @@
 | 
			
		||||
# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
ARG ELASTIC_VERSION=7.3.2
 | 
			
		||||
ARG ELASTIC_VERSION=7.2.1
 | 
			
		||||
FROM docker.elastic.co/elasticsearch/elasticsearch:${ELASTIC_VERSION}
 | 
			
		||||
ARG S3_PLUGIN_URL="https://artifacts.elastic.co/downloads/elasticsearch-plugins/repository-s3/repository-s3-${ELASTIC_VERSION}.zip"
 | 
			
		||||
 | 
			
		||||
@@ -15,7 +15,7 @@ ENV XPACK_ML="true"
 | 
			
		||||
 | 
			
		||||
ENV ENABLE_CONFIGURE_S3="false"
 | 
			
		||||
 | 
			
		||||
ARG TEMPLATE_VERSION=v3.10.0
 | 
			
		||||
ARG TEMPLATE_VERSION=v3.9.5
 | 
			
		||||
 | 
			
		||||
# Elasticearch cluster configuration environment variables
 | 
			
		||||
# If ELASTIC_CLUSTER is set to "true" the following variables will be added to the Elasticsearch configuration
 | 
			
		||||
 
 | 
			
		||||
@@ -1,7 +1,7 @@
 | 
			
		||||
# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
FROM docker.elastic.co/kibana/kibana:7.3.2
 | 
			
		||||
ARG ELASTIC_VERSION=7.3.2
 | 
			
		||||
ARG WAZUH_VERSION=3.10.0
 | 
			
		||||
FROM docker.elastic.co/kibana/kibana:7.2.1
 | 
			
		||||
ARG ELASTIC_VERSION=7.2.1
 | 
			
		||||
ARG WAZUH_VERSION=3.9.5
 | 
			
		||||
ARG WAZUH_APP_VERSION="${WAZUH_VERSION}_${ELASTIC_VERSION}"
 | 
			
		||||
 | 
			
		||||
USER root
 | 
			
		||||
 
 | 
			
		||||
@@ -1,14 +1,14 @@
 | 
			
		||||
# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
FROM phusion/baseimage:latest
 | 
			
		||||
 | 
			
		||||
ARG FILEBEAT_VERSION=7.3.2
 | 
			
		||||
ARG FILEBEAT_VERSION=7.2.1
 | 
			
		||||
 | 
			
		||||
ARG WAZUH_VERSION=3.10.0-1
 | 
			
		||||
ARG WAZUH_VERSION=3.9.5-1
 | 
			
		||||
 | 
			
		||||
ENV API_USER="foo" \
 | 
			
		||||
   API_PASS="bar"
 | 
			
		||||
 | 
			
		||||
ARG TEMPLATE_VERSION="v3.10.0"
 | 
			
		||||
ARG TEMPLATE_VERSION="v3.9.5"
 | 
			
		||||
 | 
			
		||||
# Set repositories.
 | 
			
		||||
RUN set -x && echo "deb https://packages.wazuh.com/3.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list && \
 | 
			
		||||
 
 | 
			
		||||
@@ -1,53 +1,16 @@
 | 
			
		||||
# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2)
 | 
			
		||||
filebeat.inputs:
 | 
			
		||||
  - type: log
 | 
			
		||||
    paths:
 | 
			
		||||
      - '/var/ossec/logs/alerts/alerts.json'
 | 
			
		||||
 | 
			
		||||
# Wazuh - Filebeat configuration file
 | 
			
		||||
filebeat.modules:
 | 
			
		||||
  - module: wazuh
 | 
			
		||||
    alerts:
 | 
			
		||||
      enabled: true
 | 
			
		||||
    archives:
 | 
			
		||||
      enabled: false
 | 
			
		||||
 | 
			
		||||
setup.template.json.enabled: true
 | 
			
		||||
setup.template.json.path: "/etc/filebeat/wazuh-template.json"
 | 
			
		||||
setup.template.json.name: "wazuh"
 | 
			
		||||
setup.template.json.path: '/etc/filebeat/wazuh-template.json'
 | 
			
		||||
setup.template.json.name: 'wazuh'
 | 
			
		||||
setup.template.overwrite: true
 | 
			
		||||
setup.ilm.enabled: false
 | 
			
		||||
 | 
			
		||||
processors:
 | 
			
		||||
  - decode_json_fields:
 | 
			
		||||
      fields: ['message']
 | 
			
		||||
      process_array: true
 | 
			
		||||
      max_depth: 200
 | 
			
		||||
      target: ''
 | 
			
		||||
      overwrite_keys: true
 | 
			
		||||
  - drop_fields:
 | 
			
		||||
      fields: ['message', 'ecs', 'beat', 'input_type', 'tags', 'count', '@version', 'log', 'offset', 'type', 'host']
 | 
			
		||||
  - rename:
 | 
			
		||||
      fields:
 | 
			
		||||
        - from: "data.aws.sourceIPAddress"
 | 
			
		||||
          to: "@src_ip"
 | 
			
		||||
      ignore_missing: true
 | 
			
		||||
      fail_on_error: false
 | 
			
		||||
      when:
 | 
			
		||||
        regexp:
 | 
			
		||||
          data.aws.sourceIPAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
 | 
			
		||||
  - rename:
 | 
			
		||||
      fields:
 | 
			
		||||
        - from: "data.srcip"
 | 
			
		||||
          to: "@src_ip"
 | 
			
		||||
      ignore_missing: true
 | 
			
		||||
      fail_on_error: false
 | 
			
		||||
      when:
 | 
			
		||||
        regexp:
 | 
			
		||||
          data.srcip: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
 | 
			
		||||
  - rename:
 | 
			
		||||
      fields:
 | 
			
		||||
        - from: "data.win.eventdata.ipAddress"
 | 
			
		||||
          to: "@src_ip"
 | 
			
		||||
      ignore_missing: true
 | 
			
		||||
      fail_on_error: false
 | 
			
		||||
      when:
 | 
			
		||||
        regexp:
 | 
			
		||||
          data.win.eventdata.ipAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
 | 
			
		||||
 | 
			
		||||
output.elasticsearch:
 | 
			
		||||
  hosts: ['http://elasticsearch:9200']
 | 
			
		||||
  #pipeline: geoip
 | 
			
		||||
  indices:
 | 
			
		||||
    - index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}'
 | 
			
		||||
output.elasticsearch.hosts: ['http://elasticsearch:9200']
 | 
			
		||||
		Reference in New Issue
	
	Block a user