Wazuh Indexer Install - Installing our SIEM Backend Storage

  Рет қаралды 34,119

Taylor Walton

Taylor Walton

Жыл бұрын

Join me as we start Part One of our World's Best SOC Built on Open Source Tools series, installing our backend storage. We will install the Wazuh-Indexer to store our security logs collected.
Blog Post: / part-1-wazuh-indexer-s...
Contact Me: taylor.walton@socfortress.co
LinkedIn: / socfortressmdr
Twitter: / socfortress
Our Blog: / socfortress
Wazuh Indexer Docs: documentation.wazuh.com/curre...
Capacity Planning: / capacity-planning-for-...
Buy Me A Coffee: bit.ly/3woh21M
Security Operations Center as a Service: www.socfortress.co/
Free For Life Tier: www.socfortress.co/trial.html
Professional Services: www.socfortress.co/ps.html
Discord Channel: / discord
Series Playlist: • World's Best SIEM Stack

Пікірлер: 49
@racg1210
@racg1210 Жыл бұрын
What a great video Taylor, thank you so much for this
@ramnathnair5743
@ramnathnair5743 Жыл бұрын
Thank you Taylor! really appreciated your time and effort.
@TheMedtemo
@TheMedtemo Жыл бұрын
Best combination of best open source tools. Thanks for sharing 👍
@cyberbrainfoodletseat8260
@cyberbrainfoodletseat8260 Жыл бұрын
Taylor, awesome stuff, amazing content that actually works if you follow. Big fan of Opensource.
@hackyourfuture
@hackyourfuture Жыл бұрын
hey taylor your videos are amazing.....thanks for sharing your knowledge 🚀🚀🚀
@boolve
@boolve 9 ай бұрын
You did spend a good piece of time explaining everything. Nice
@FrenchSparda
@FrenchSparda Жыл бұрын
Great !! Many thanks, I'll start to follow your vids and install all services needed. Merci !!
@sq9176
@sq9176 Жыл бұрын
Thanks, buddy. Love your videos.
@dibyendusdiary
@dibyendusdiary Күн бұрын
Thank you so much. it helps a lot.
@miguelsaiz8151
@miguelsaiz8151 Жыл бұрын
Great video my friend
@gohpatrick1182
@gohpatrick1182 Жыл бұрын
One of the best Open Source video setup! Thanks for the video! What server are you running? VM in your local machine?
@oolyo6604
@oolyo6604 Жыл бұрын
Thank you Taylor for the video it was great as usual been watching wazuh videos from your channel and it helped me i have question bro I’m small company which can’t avoid market EDRs which one you would recommend elastic edr or wazuh?
@sintayehuseyoum7190
@sintayehuseyoum7190 Жыл бұрын
very helpful
@jonbrandenburg9880
@jonbrandenburg9880 Жыл бұрын
I first want to say thank you for providing this content. I've watched the entire "World's Best Free SIEM Stack" series and it's been a huge help getting me started with more advanced collecting and analyzing of my logs. But before I go down the path you've provided, I'm wondering what a scaled back approach might look like. I'm working within a school district and my environment is fairly small. I have around 30 network devices, one firewall, VMWare with 3 hosts and15 VM's (Windows and Linux) and another 5 standalones on prem Windows servers. Then there is about 150 Windows and Mac devices. So, I guess I'm wondering if I can just take pieces of this and have a good enough working "SIEM" to help me detect, isolate, respond and clean up any type of security event that may occur? Or do I just install the full Wazuh Security Platform and that'll be good enough? Any thoughts or comments would be appreciated.
@GordonSquared
@GordonSquared Жыл бұрын
Very nice video.. Could I run these as vm's on one host? If so how much ram would i need? Not for large production just home lab
@dareogunsola6561
@dareogunsola6561 Жыл бұрын
Running into an annoying issue where graylog cannot verify hostname. Getting this error: Unable to retrieve version from Elasticsearch node: Hostname not verified. Any pointers?
@javeriajameel7500
@javeriajameel7500 Жыл бұрын
Hello, Can anyone tell me is there any API to get stored alerts from wazuh indexer automatically?
@cybertester9344
@cybertester9344 Жыл бұрын
Great tutorial, love this series
@thecrazymouse7220
@thecrazymouse7220 8 ай бұрын
Hope you are watching these notes... That was a speed session - and I have question.. I notice that when setting up these apps, it all defaults to the main drive your /usr profile is located. For the Indexer, I want to store all the data captured on to a second drive I have mounted. /dev/sdb (labeled: Data). In the opensearch.yml the two lines you skipped over, path.data and path.logs, are these the areas to change to force to that second drive? Would I change the /var/lib/wazuh-indexer to /dev/sdb/wazuh-indexer/data and /dev/sdb/wazuh-indexer/logs ?? Would that work? Since my main drive is small.. just looking at how to redirect data to the second drive. when looking at properties i think it is /media/ubuntu/Data Parent Folder...
@daan99pl
@daan99pl Жыл бұрын
Taylor, no money in pocket? What environment do you need?
@kevinkinsey8138
@kevinkinsey8138 Жыл бұрын
So if we already have Elasticsearch, do we need to drop it and use W.Indexer instead?
@javimed9669
@javimed9669 Жыл бұрын
Hi. You can use the Wazuh server 4.3+ along with Elastic Stack as an alternative deployment. Please check installation steps in Wazuh docs "Installing Wazuh with Elastic Stack basic license". As explained in the video, Wazuh indexer is Wazuh's own fork of OpenSearch (formerly OpenDistro, based on Elasticsearch).
@jodayabi
@jodayabi Жыл бұрын
get confused why elasticsearch and not Opensearch. am i lost?
@jasonforry5466
@jasonforry5466 Жыл бұрын
Hi Guys, I am looking to use this SIEM stack as a Capstone project. Is it expensive to launch? It doesnt need to be used for production....TIA
@abhinavkohli4293
@abhinavkohli4293 28 күн бұрын
i am also looking for using it as a project but it seems too advanced can u help me like where to start
@tharunkarthikeyan5695
@tharunkarthikeyan5695 Жыл бұрын
Hey Taylor, I have followed the steps as described in the video and medium post, but am encountering a problem in the last step. When I try to access my dashboard webpage, I am greeted with a message saying "Wazuh dashboard server is not ready yet". I have tried looking through blogs but the only solution I seem to reach is to run the systemctl restart wazuh-dashboard. It would be a great deal if you get help me out here. Thank you again for the video.
@Jxsprlyh
@Jxsprlyh 9 ай бұрын
Any updates on this error? I received this error as well
@chahiramaoua4944
@chahiramaoua4944 8 ай бұрын
any updates @@Jxsprlyh ? i have the same error
@austinpwr1
@austinpwr1 7 ай бұрын
I got past the "Wazuh dashboard server is not ready yet", but I am running into a issues Wazuh API offline in GUI. I have ran through this lab around 6 times now still same issue. I get an error check Wazuh API connection and Check alert index pattern. Has anyone resolve this yet..
@stylishctf5146
@stylishctf5146 3 ай бұрын
@@austinpwr1 how did u fix it ?
@PawsShip
@PawsShip Жыл бұрын
Hi Brother, I am facing below issue in graylog, i followed the same steps as you did in the videos. graylog searc tab - While retrieving data for this widget, the following error(s) occurred: Elasticsearch exception [type=illegal_argument_exception, reason=key [types] is not supported in the metadata section]. please help me out, from last 1 week i am triying.
@taylorwalton_socfortress
@taylorwalton_socfortress Жыл бұрын
try commenting out `compatibility.override_main_response_version: true` in the wazuh-indexer config file and then restart the wazuh-indexer service reference: community.graylog.org/t/elasticsearch-exception-reason-key-types-is-not-supported-in-the-metadata-section/27468/6
@PawsShip
@PawsShip Жыл бұрын
@@taylorwalton_socfortress Yes, i have doone changes, as mentioned in the above link. now graylog log shows that Elasticsearch version currently running (OpenSearch:2.6.0) is incompatible with the one Graylog was started with (Elasticsearch:7.10.2) - a restart is required
@orhancevik1512
@orhancevik1512 Жыл бұрын
please can someone help me, i get the error when i want to start the wazuh this error: controll process exited with error code, see system-ctl status wazuh-indexer service
@icguarin23
@icguarin23 6 ай бұрын
Hey have you found the solution?
@datboyblu3
@datboyblu3 11 ай бұрын
Followed your guide and the official docs, however, I'm getting the following error message when installing the Indexer: "Unable to locate package wazuh-indexer". I'm running Ubuntu 22.04.3...Everything's been working great until this installation. Not sure what is wrong with my installation.
@tester0083
@tester0083 11 ай бұрын
If you look at (26:19), he actually had the same problem. "apt-get update" and you'll be good.
@datboyblu3
@datboyblu3 11 ай бұрын
Did the same thing, but I think it has to do with Wazuh not having an aarch64 build for the indexer @@tester0083
@chahiramaoua4944
@chahiramaoua4944 8 ай бұрын
getting this error : Wazuh dashboard server is not ready yet indexer active and the dashbord is active :( any help plz
@dannymiller3762
@dannymiller3762 8 ай бұрын
I had this issue, not sure about yours, but I copied the wrong password when updating the kibanaserver password
@syedomairmasood6785
@syedomairmasood6785 11 ай бұрын
Getting this error INFO: No current API selected INFO: Getting API hosts... INFO: API hosts found: 1 INFO: Checking API host id [default]... INFO: Could not connect to API id [default]: 3099 - ERROR3099 - Invalid credentials INFO: Removed [navigate] cookie ERROR: No API available to connect
@alfarashfidqy6571
@alfarashfidqy6571 4 ай бұрын
after following each steps carefully, i got wazuh-indexer and wazuh-dashboard running on systemctl, but when i hit the ip address, it says wazuh dashboard server is not ready yet. any solutions?
@stylishctf5146
@stylishctf5146 3 ай бұрын
did u fix it ?
@alfarashfidqy6571
@alfarashfidqy6571 3 ай бұрын
@@stylishctf5146 yes. In my case, I didn’t point to the right certs. So i double check everything and point to the right certs, then it sorts itself out.
@stylishctf5146
@stylishctf5146 3 ай бұрын
@@alfarashfidqy6571 oh damn, i just reinstalled wazuh and everything and it's working now ahaha xD
@sabarivenkateshk9827
@sabarivenkateshk9827 Жыл бұрын
Hey Taylor I got a error while doing gpg key part .. gpg: keyblock resource '/usr/share/keyrings/wazuh.gpg': Permission denied Thanks in advance :)
@joelnicholasfrancis2700
@joelnicholasfrancis2700 Жыл бұрын
Same here Got any solutions?
@tester0083
@tester0083 11 ай бұрын
make sure you are the root user. it is not enough to use sudo as a different user. type "sudo su" and then you will be root.
Graylog Install - Best Log Ingester for Your SIEM!
31:18
Taylor Walton
Рет қаралды 27 М.
Wazuh Install - Worlds Best OpenSource EDR!
26:23
Taylor Walton
Рет қаралды 28 М.
DAD LEFT HIS OLD SOCKS ON THE COUCH…😱😂
00:24
JULI_PROETO
Рет қаралды 16 МЛН
Amazing weight loss transformation !! 😱😱
00:24
Tibo InShape
Рет қаралды 60 МЛН
Получилось у Миланы?😂
00:13
ХАБИБ
Рет қаралды 3,4 МЛН
you need this FREE CyberSecurity tool
32:06
NetworkChuck
Рет қаралды 1,2 МЛН
Wazuh Agent Install - World's Best OpenSource EDR Agent!
20:47
Taylor Walton
Рет қаралды 20 М.
The moment we stopped understanding AI [AlexNet]
17:38
Welch Labs
Рет қаралды 810 М.
Open Source Incident Response Platform - Your SOC Needs This!
21:46
Taylor Walton
Рет қаралды 30 М.
Wazuh Home-Lab using Docker | Setting up Wazuh from scratch
13:42
Rajneesh Gupta
Рет қаралды 3,3 М.
DHH - Ruby on Rails, 37signals, and the future of web development
1:09:57
Look, this is the 97th generation of the phone?
0:13
Edcers
Рет қаралды 7 МЛН
Копия iPhone с WildBerries
1:00
Wylsacom
Рет қаралды 8 МЛН
Как распознать поддельный iPhone
0:44
PEREKUPILO
Рет қаралды 2,3 МЛН
Лучший браузер!
0:27
Honey Montana
Рет қаралды 363 М.
Лазер против камеры смартфона
1:01
Newtonlabs
Рет қаралды 726 М.