Setup Wazuh - Open Source Security Platform

  Рет қаралды 48,872

UpBrightSkills

UpBrightSkills

4 жыл бұрын

#wazuh #siem #opensourcesiem
Setup Guide for Wazuh - How to get Started with Wazuh.
Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring, incident response and compliance.
Feature Like
1. Security Analytics
2. Intrusion Detection
3. Log Data Analysis
4. File Integrity Monitoring
5. Vulnerability Detection
6. Configuration Assessment
7. Incident Response
8. Regulatory Compliance
9. Cloud Security
10. Containers Security
Wazuh - wazuh.com/
Wazuh Ova Download (Version 3.12) - documentation.wazuh.com/3.12/...
Wazuh Agent Download - documentation.wazuh.com/3.12/...

Пікірлер: 68
@yash561
@yash561 4 жыл бұрын
Thanks for step by step information, very helpful for every person who has no prior knowledge.
@anniebourgeois931
@anniebourgeois931 4 жыл бұрын
Great video. Thanks for the run-through!
@UpBrightSkills
@UpBrightSkills 4 жыл бұрын
Thanks !!
@shanb7207
@shanb7207 5 ай бұрын
Thanks for the very informative video Kapil. Could you please make another video on how to use this on a production environment as you mentioned making a cluster and then deploying it? It would be a huge help for understanding the installation and the entire setup process.
@piyushchokshi2261
@piyushchokshi2261 4 жыл бұрын
Thank you so much Kapil for sharing this wonderful tutorial it's such good things for learning. This knowledge sharing it's very helpful.
@UpBrightSkills
@UpBrightSkills 4 жыл бұрын
So nice of you
@haiderelbaghdady3172
@haiderelbaghdady3172 4 жыл бұрын
Thanks Kapil what a great tutorial, very helpful
@UpBrightSkills
@UpBrightSkills 4 жыл бұрын
Thanks for your comments !!
@dotcaodin
@dotcaodin 3 жыл бұрын
Thanks for sharing.
@krishnabhatt9291
@krishnabhatt9291 3 жыл бұрын
Thank you Sir. The video was very helpful...
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
Glad to hear that
@adistamanna
@adistamanna 3 жыл бұрын
Thank you for such a descriptive video #gr8 job . Looking forward for more videos. Meanwhile can you please confirm in case of DHCP environment what will happen to the agent registered with my manager since I binded it with the IP and IP can be static as well as Dynamic. Will my agent still communicate with manager?
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
In this case there will be a different approach. Here we have to Auto search host and then monitor those. We don't have to add them maually.
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
For the agent having dynamic ip's, when you register an agent on wazuh manager - instead on mention ip address you can mention "any". This will solve your problem.
@adistamanna
@adistamanna 3 жыл бұрын
@@UpBrightSkills also if we have a written set of code n we want to implement the same for look n feel on kibana but when we paste on JSON (under advance settings) we get some error like heavy file n takes me to the kibana dashboard how to fix that any idea??
@sureshchowdary5143
@sureshchowdary5143 3 жыл бұрын
Thanks for the step by step information, Am trying to open the wazuh manager using Chrome and Firefox but it's throwing error "elastic did not load properly. check the server output for more information". can you please help me on this .
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
Just, restart elasticsearch service using this command - service elasticsearch restart (this will solve your problem)
@manojm.m6853
@manojm.m6853 3 жыл бұрын
thanks for step by step information ,and i have one question. Can we edit the report format? Is there any possibility of editing report format generated by wazuh.
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
That i also need to check buddy, will check and get back to you.
@christianborla
@christianborla 2 жыл бұрын
Hi Manoj M.M. I hope you are doing fine! Unfortunately only you can customize the title of the Wazuh automatic reports, configuration section options are: * Filtering configuration by: group, category, rule, level, location, srcip, user * You can customize: title and email_to * An option to include full log with the report: showlogs Let me know if that is useful! Regards.
@YogeshSharma-uf8il
@YogeshSharma-uf8il 4 жыл бұрын
Amazing Video.
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
Thanks!
@manojthanet7751
@manojthanet7751 4 жыл бұрын
Nice video and plz upload about email alerting and rule set part video
@UpBrightSkills
@UpBrightSkills 4 жыл бұрын
Thanks for inputs !! Refer to this video for alert setup. One more video coming this sunday for intergity monitoring. kzfaq.info/get/bejne/jK5hl6WFys3GoGg.html
@kennethshibaba4490
@kennethshibaba4490 10 ай бұрын
Hi do you have a video that shows how remove the agent from the list in the UI? Thanks
@UpBrightSkills
@UpBrightSkills 4 ай бұрын
Removing agent can be done from CLI, once removed from CLI it will also get removed from UI.
@systemsecurity2076
@systemsecurity2076 Жыл бұрын
Wow
@InfinitiCyberSolutions
@InfinitiCyberSolutions Жыл бұрын
I'm on VMware workstation pro. Not sure why but ip addr doesn't show an ip address for my wazuh manager. Do I have to manually assign one? I thought it shared the host's IP address by default. Help please.
@UpBrightSkills
@UpBrightSkills Жыл бұрын
It should detect ip automatically if dhcp is available if not then you can manually assign the ip address.
@aqsaqureshi8600
@aqsaqureshi8600 2 жыл бұрын
which password we have to right in root@ip in putty configuration, i
@DijitalBakan
@DijitalBakan 3 жыл бұрын
thank you man
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
You're welcome!
@DijitalBakan
@DijitalBakan 3 жыл бұрын
@@UpBrightSkills wazuh documentations link give me please
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
Here is the link - documentation.wazuh.com/4.0/user-manual/
@SuperChelseaSW6
@SuperChelseaSW6 4 жыл бұрын
Hello sir. How do we configure openscap for ubuntu? There is only for centos on the documentation.
@UpBrightSkills
@UpBrightSkills 4 жыл бұрын
Follow this to run openscap for ubuntu, there are several policy already present in wazuh to scan your debian systems. documentation.wazuh.com/3.12/user-manual/capabilities/policy-monitoring/openscap/how-it-works.html?highlight=openscap%20ubuntu
@SuperChelseaSW6
@SuperChelseaSW6 4 жыл бұрын
@@UpBrightSkills I have ubuntu 20.04 . So will it work on the new version?
@UpBrightSkills
@UpBrightSkills 4 жыл бұрын
It should work on latest version too !!
@avitansahar
@avitansahar 2 жыл бұрын
i got "Wazuh dashboard server is not ready yet" do you know why? wazuh version 4.3
@UpBrightSkills
@UpBrightSkills 2 жыл бұрын
Pls check elastic search service
@nimeshsilva7749
@nimeshsilva7749 2 ай бұрын
can you describe whats the password goes on puttys?
@khajamoin2897
@khajamoin2897 2 жыл бұрын
i am not getting the ipv4 address, its showing only ipv6., can you please help me how to get the ipv4 address to access the dash board
@Lolarkz
@Lolarkz 4 ай бұрын
did you find it?#
@nhatratlachat1172
@nhatratlachat1172 3 жыл бұрын
thank u
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
Welcome
@metacraft3490
@metacraft3490 2 жыл бұрын
can it monitor network traffic, can I forward Firewall syslogs to it?
@pedronicolasgomez5677
@pedronicolasgomez5677 2 жыл бұрын
Hi, To monitor network devices, you can use syslog to forward events from them to the Wazuh Manager. The procedure basically consists in: 1. Adding the syslog configuration to the Manager and restart the wazuh-manager service. 2. Enable syslog in data source. 3. Add custom decoders/rules. You can find the complete procedure documented here: wazuh.com/blog/how-to-configure-rsyslog-client-to-send-events-to-wazuh/ and there's additional information here: documentation.wazuh.com/current/user-manual/capabilities/log-data-collection/how-it-works.html#remote-syslog. Also, in case you need to create decoders/rules (most probably), you can find information for this here: documentation.wazuh.com/current/user-manual/ruleset/getting-started.html documentation.wazuh.com/current/user-manual/ruleset/custom.html documentation.wazuh.com/current/user-manual/ruleset/ruleset-xml-syntax/decoders.html documentation.wazuh.com/current/user-manual/ruleset/ruleset-xml-syntax/rules.html I hope it helps. Best regards.
@lamiyarahman2954
@lamiyarahman2954 Жыл бұрын
Its showing wazuh dashboard is not ready yet!
@UpBrightSkills
@UpBrightSkills Жыл бұрын
Check elastic search service. That must be stopped or taking time to start.
@lamiyarahman2954
@lamiyarahman2954 Жыл бұрын
@@UpBrightSkills yes tried that it worked but later stoped again. And now facing problem in agent connection. Hopefully it will be solved. And thank you for the video and replying.
@cintakebenaran4678
@cintakebenaran4678 3 жыл бұрын
bagaimana cara integrasi dengan snort atau suricata and with pcap recording . can you help me?
@javimed9669
@javimed9669 2 жыл бұрын
Hello. To collect Snort logs, edit ossec.conf and add snort-full as a new log format and your Snort log path as the location for it. Restart your Wazuh agent and it will start reading the logs. To integrate Suricata with Wazuh read "Catch suspicious network traffic" and "Network IDS integration" in Wazuh's documentation. Join the Wazuh community to get more help.
@chundurusriharsha2402
@chundurusriharsha2402 2 жыл бұрын
Can we add the AWS server too? in our localhost?
@UpBrightSkills
@UpBrightSkills 2 жыл бұрын
Yes u can monitor aws servers too
@chundurusriharsha2402
@chundurusriharsha2402 2 жыл бұрын
@@UpBrightSkills how to add into my wazuh which is in my localhost? To find the logs and so on?
@nihar1611
@nihar1611 3 жыл бұрын
Not getting a valid ip after using ip addr Please help
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
Not getting ip means ? You are not getting ip for accessing wazuh portal ? If yes, then kindly check your dhcp server amd connectivity to that or elae you can configure static ip address.
@dmmikerpg
@dmmikerpg 3 жыл бұрын
Now if only we could get the agent running a resident virus scanner.
@srich9382
@srich9382 Жыл бұрын
Does wazuh manager install only Linux?
@srich9382
@srich9382 Жыл бұрын
@Belen V when I restart wazhu manager. Wazhu dashboard restart manual. How to overcome that
@chundurusriharsha2402
@chundurusriharsha2402 3 жыл бұрын
I am getting "kibana server not ready yet" may i know the reason.
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
Check your elasticsearch service. If that service is not running then you get such error.
@chundurusriharsha2402
@chundurusriharsha2402 3 жыл бұрын
@@UpBrightSkills how to check
@UpBrightSkills
@UpBrightSkills 3 жыл бұрын
service elasticsearch status | service elasticsearch restart. These are the 2 commands which you can use to check the status of service and to start the service
@pedronicolasgomez5677
@pedronicolasgomez5677 2 жыл бұрын
Hi, The message "Kibana server is not ready yet" usually appears when you just started Kibana. If this is not the case, it can also be caused by the following errors: - Your service or Kibana configuration has some error that causes it to constantly reboot. - Your elasticsearch service is not up or has some error. - Resources are insufficient. I recommend that at least to host the elasticsearch and kibana service, you should dedicate 4 GB of RAM and 2 CPU cores. If you have just started the kibana service, please wait a few minutes and try again. If this is not the case, then you will have to check the status of the elasticsearch and kibana services. Also check if the hardware resources are sufficient. Check the status of the Kibana service systemctl status kibana -l Check the kibana logs journalctl -u kibana | egrep -i "error" Check the status of the Elasticsearch service systemctl status elasticsearch -l Check the elasticsearch logs egrep -i "error" /var/log/elasticsearch/elasticsearch.log Best regards, Pedro Nicolas
@asgharnazir6909
@asgharnazir6909 2 жыл бұрын
whats is the password for login through putty?
@UpBrightSkills
@UpBrightSkills 2 жыл бұрын
wazuh | wazuh
Wazuh - How to Scan for Vulnerabilities in Windows and Linux
17:53
UpBrightSkills
Рет қаралды 53 М.
БОЛЬШОЙ ПЕТУШОК #shorts
00:21
Паша Осадчий
Рет қаралды 2,8 МЛН
Khó thế mà cũng làm được || How did the police do that? #shorts
01:00
ИРИНА КАЙРАТОВНА - АЙДАХАР (БЕКА) [MV]
02:51
ГОСТ ENTERTAINMENT
Рет қаралды 6 МЛН
Wazuh OVA setup guide
6:48
Wazuh · The Open Source Security Platform
Рет қаралды 34 М.
WAZUH - Setup Email Notification / Alerts
7:52
UpBrightSkills
Рет қаралды 19 М.
you need this FREE CyberSecurity tool
32:06
NetworkChuck
Рет қаралды 1,2 МЛН
WAZUH - File Integrity Monitoring (FIM)
9:55
UpBrightSkills
Рет қаралды 21 М.
Wazuh Agent Setup: Your Essential Guide
11:39
syncbricks
Рет қаралды 1,9 М.
Wazuh - Monitor & Analyze AWS CloudTrail Service
12:48
UpBrightSkills
Рет қаралды 6 М.
Cloud Security Tutorial For Beginners | What is Cloud Security?
16:05
Tech With Soleyman
Рет қаралды 4,1 М.
Syslog and Wazuh - Let's Build A Host Intrusion Detection System
15:12
Tutorial: Wazuh SIEM - Installation and Configuration (Complete Steps)
26:08
iPhone 12 socket cleaning #fixit
0:30
Tamar DB (mt)
Рет қаралды 53 МЛН
Asus  VivoBook Винда за 8 часов!
1:00
Sergey Delaisy
Рет қаралды 1,1 МЛН