Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.

Wazuh 3.6.1 #708

Closed
dougburks opened this issue Mar 27, 2015 · 9 comments
Closed

Wazuh 3.6.1 #708

dougburks opened this issue Mar 27, 2015 · 9 comments

Comments

@dougburks
Copy link
Contributor

Need the new OSSEC agent to parse EventChannel logs properly (for sysmon).

@dougburks dougburks changed the title Update OSSEC OSSEC 2.9 Jun 21, 2015
@adigiuseppe
Copy link

Hi Doug,

First off, huge thanks for a great NSM distro.

Is this standard OSSEC 2.9 or the Wazuh fork of OSSEC? If it's the plain old OSSEC, I'd suggest you check out what the Wazuh HIDS folks are doing to enhance OSSEC.

P.S. I have "upgraded" the Security 14.0.4.1 OSSEC in-place to the Wazuh fork of OSSEC 2.9 and it works correctly with ELSA, etc. I simply followed the steps here to install on top of the SO OSSEC: Installing Wazuh HIDS.

@dougburks
Copy link
Contributor Author

Hi adigiuseppe,

This hasn't been implemented yet since OSSEC 2.9 hasn't been released. Once it is released, I'll take a look at standard OSSEC vs Wazuh.

@adigiuseppe
Copy link

OK, I ask because Wazuh is forked off the OSSEC 2.9 code branch already; they also contribute back to the upstream OSSEC project, I believe.

@dougburks
Copy link
Contributor Author

Notes for packaging:

I think the default limit is the same as it was in 2.9.0 (2048 I believe). 
It is supposed to be changeable with `make MAXAGENTS=NUMBER` or 
probably `MAXAGENTS=NUMBER ./install.sh` 

https://groups.google.com/d/topic/ossec-list/xiVOGEBqTVg/discussion

@dougburks
Copy link
Contributor Author

Another note for packaging:

ossec-server.conf should have local_rules.xml after securityonion_rules.xml to allow users to override defaults:
https://groups.google.com/d/topic/security-onion/m_pD9HidK_o/discussion

@dougburks
Copy link
Contributor Author

@nicknomo
Copy link

nicknomo commented Sep 2, 2017

I'd really like to see Wazuh in security onion. It already is integrated with the ELK stack, and it seems like you are headed there anyway. I'd love to see this in a future release of security onion.

@dougburks
Copy link
Contributor Author

@dougburks
Copy link
Contributor Author

Published:
https://blog.securityonion.net/2018/10/wazuh-361-elastic-641-and-associated.html

@dougburks dougburks removed this from To do in Future Release 1 Jan 19, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants