差異處
這裏顯示兩個版本的差異處。
| 兩邊的前次修訂版 前次修改 下次修改 | 前次修改 | ||
| tech:wazuh [2023/12/06 11:53] – [參考網址] jonathan | tech:wazuh [2025/01/19 08:47] (目前版本) – [Agent 端] jonathan | ||
|---|---|---|---|
| 行 10: | 行 10: | ||
| echo " | echo " | ||
| </ | </ | ||
| - | * 安裝 Wazuh v4.6.0 < | + | * 安裝 Wazuh v4.7.0 < |
| - | git clone https:// | + | git clone https:// |
| cd wazuh-docker/ | cd wazuh-docker/ | ||
| docker compose -f generate-indexer-certs.yml run --rm generator | docker compose -f generate-indexer-certs.yml run --rm generator | ||
| 行 20: | 行 20: | ||
| ===== 設定啟用 ===== | ===== 設定啟用 ===== | ||
| + | ==== Server 端 ==== | ||
| * 其他文件提到修改 / | * 其他文件提到修改 / | ||
| + | ==== Agent 端 ==== | ||
| + | === 安裝 Agent 方式 === | ||
| + | * Exp. Wazuh Server IP : 10.20.2.38 | ||
| + | == Ubuntu / Debian == | ||
| + | * <cli> | ||
| + | apt install lsb-release && wget https:// | ||
| + | systemctl daemon-reload | ||
| + | systemctl enable wazuh-agent | ||
| + | systemctl restart wazuh-agent | ||
| + | </ | ||
| + | |||
| + | == Alpine == | ||
| + | * <cli> | ||
| + | wget -O / | ||
| + | echo " | ||
| + | apk update | ||
| + | apk add wazuh-agent | ||
| + | export WAZUH_MANAGER=" | ||
| + | / | ||
| + | sed -i " | ||
| + | </ | ||
| + | |||
| + | === 修改 Agent 端設定 === | ||
| + | * Linux Agent 主要安裝路徑 /var/ossec | ||
| + | * 修改 ossec.conf 檔 -> / | ||
| + | * 修改後重啟 Agent < | ||
| + | |||
| + | === 移除 Agent 方式 === | ||
| + | * ref - https:// | ||
| + | == Ubuntu / Debian == | ||
| + | * <cli> | ||
| + | apt remove --purge wazuh-agent | ||
| + | </ | ||
| + | == alpine == | ||
| + | * <cli> | ||
| + | / | ||
| + | apk del wazuh-agent | ||
| + | rm -rf /var/ossec | ||
| + | rm / | ||
| + | sed -i '/ | ||
| + | </ | ||
| + | |||
| ===== 參考網址 ===== | ===== 參考網址 ===== | ||
| * https:// | * https:// | ||