feat(siem): fleet rollout tooling — agents + PVE rsyslog forwarding [#335]

deploy-agent.sh (Ubuntu VMs) + deploy-rsyslog.sh (PVE hosts, TCP/514 via
Tailscale). Landed: agents on netinfra-01/02, librenms, awx (7 total
active on manager); rsyslog forwarding verified on all 7 PVE hosts
(persistent 514 sessions on the manager). Deferred: k8s nodes (k8s-chat
coordination), docker json-log caps (needs daemon restart window).
Meat + verification: https://projects.knownelement.com/issues/335#note-4006
This commit is contained in:
2026-09-03 06:30:25 -05:00
parent 5c5e173a1b
commit 06679d9a0c
3 changed files with 65 additions and 0 deletions
+34
View File
@@ -0,0 +1,34 @@
#!/bin/bash
#
# deploy-agent.sh — Wazuh agent rollout for Ubuntu VMs [#335]
# Run as root on the target VM. Idempotent; safe to re-run.
# Manager: tsys-wazuh.knel.net (syslog/agent ports verified 2026-09-02).
#
set -euo pipefail
MGR="tsys-wazuh.knel.net"
VER="4.14.7-1"
if ! dpkg -s wazuh-agent >/dev/null 2>&1; then
echo "installing wazuh-agent $VER (manager: $MGR)"
curl -sSf --max-time 120 -o /tmp/wazuh-agent.deb \
"https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_${VER}_amd64.deb"
WAZUH_MANAGER="$MGR" WAZUH_REGISTRATION_SERVER="$MGR" \
DEBIAN_FRONTEND=noninteractive dpkg -i /tmp/wazuh-agent.deb
rm -f /tmp/wazuh-agent.deb
else
echo "wazuh-agent already installed: $(dpkg -l wazuh-agent | tail -1 | awk '{print $3}')"
fi
CONF=/var/ossec/etc/ossec.conf
if ! grep -q "<address>$MGR</address>" "$CONF"; then
echo "correcting manager address in ossec.conf"
cp "$CONF" "$CONF.bak.$(date +%Y%m%d%H%M%S)"
sed -i "s|<address>[^<]*</address>|<address>$MGR</address>|" "$CONF"
fi
systemctl enable wazuh-agent >/dev/null 2>&1 || true
systemctl restart wazuh-agent
sleep 8
systemctl -q is-active wazuh-agent && echo "wazuh-agent ACTIVE"
grep -iE "enroll|connected to" /var/ossec/logs/ossec.log | tail -3 || echo "(no enrollment lines yet — check manager side)"