feat(siem): fleet rollout tooling — agents + PVE rsyslog forwarding [#335]
deploy-agent.sh (Ubuntu VMs) + deploy-rsyslog.sh (PVE hosts, TCP/514 via Tailscale). Landed: agents on netinfra-01/02, librenms, awx (7 total active on manager); rsyslog forwarding verified on all 7 PVE hosts (persistent 514 sessions on the manager). Deferred: k8s nodes (k8s-chat coordination), docker json-log caps (needs daemon restart window). Meat + verification: https://projects.knownelement.com/issues/335#note-4006
This commit is contained in:
@@ -363,6 +363,7 @@ oam/ OAM platform tooling (oxidized, unpoller, smokeping, netdisc
|
|||||||
librenms-agent: check_mk agent + snmp-extend scripts ported from KNELServerBuild [#474])
|
librenms-agent: check_mk agent + snmp-extend scripts ported from KNELServerBuild [#474])
|
||||||
proxmox/ Proxmox fleet docs (hardware audit, capacity, storage) + perf tuning (perf/)
|
proxmox/ Proxmox fleet docs (hardware audit, capacity, storage) + perf tuning (perf/)
|
||||||
awx/ Ansible AWX deployment (k3s + AWX Operator)
|
awx/ Ansible AWX deployment (k3s + AWX Operator)
|
||||||
|
siem/ Wazuh/SIEM deploy tooling (agents on VMs, rsyslog forwarding on PVE) [#335]
|
||||||
cmdb/ GLPI/CMDB seed tooling (inventory→CSV converter; design: Discourse t/319, #705)
|
cmdb/ GLPI/CMDB seed tooling (inventory→CSV converter; design: Discourse t/319, #705)
|
||||||
tests/ Test suite + VM validation harness + remote.sh SSH chokepoint
|
tests/ Test suite + VM validation harness + remote.sh SSH chokepoint
|
||||||
scripts/ Framework: git hooks, rule engine (check-rules.sh), shared lib
|
scripts/ Framework: git hooks, rule engine (check-rules.sh), shared lib
|
||||||
|
|||||||
@@ -0,0 +1,34 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
#
|
||||||
|
# deploy-agent.sh — Wazuh agent rollout for Ubuntu VMs [#335]
|
||||||
|
# Run as root on the target VM. Idempotent; safe to re-run.
|
||||||
|
# Manager: tsys-wazuh.knel.net (syslog/agent ports verified 2026-09-02).
|
||||||
|
#
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
MGR="tsys-wazuh.knel.net"
|
||||||
|
VER="4.14.7-1"
|
||||||
|
|
||||||
|
if ! dpkg -s wazuh-agent >/dev/null 2>&1; then
|
||||||
|
echo "installing wazuh-agent $VER (manager: $MGR)"
|
||||||
|
curl -sSf --max-time 120 -o /tmp/wazuh-agent.deb \
|
||||||
|
"https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_${VER}_amd64.deb"
|
||||||
|
WAZUH_MANAGER="$MGR" WAZUH_REGISTRATION_SERVER="$MGR" \
|
||||||
|
DEBIAN_FRONTEND=noninteractive dpkg -i /tmp/wazuh-agent.deb
|
||||||
|
rm -f /tmp/wazuh-agent.deb
|
||||||
|
else
|
||||||
|
echo "wazuh-agent already installed: $(dpkg -l wazuh-agent | tail -1 | awk '{print $3}')"
|
||||||
|
fi
|
||||||
|
|
||||||
|
CONF=/var/ossec/etc/ossec.conf
|
||||||
|
if ! grep -q "<address>$MGR</address>" "$CONF"; then
|
||||||
|
echo "correcting manager address in ossec.conf"
|
||||||
|
cp "$CONF" "$CONF.bak.$(date +%Y%m%d%H%M%S)"
|
||||||
|
sed -i "s|<address>[^<]*</address>|<address>$MGR</address>|" "$CONF"
|
||||||
|
fi
|
||||||
|
|
||||||
|
systemctl enable wazuh-agent >/dev/null 2>&1 || true
|
||||||
|
systemctl restart wazuh-agent
|
||||||
|
sleep 8
|
||||||
|
systemctl -q is-active wazuh-agent && echo "wazuh-agent ACTIVE"
|
||||||
|
grep -iE "enroll|connected to" /var/ossec/logs/ossec.log | tail -3 || echo "(no enrollment lines yet — check manager side)"
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
#
|
||||||
|
# deploy-rsyslog.sh — rsyslog forwarding to Wazuh for PVE hosts [#335]
|
||||||
|
# Run as root on the target host. Idempotent; safe to re-run.
|
||||||
|
# Forwards everything via TCP/514 to tsys-wazuh.knel.net (Tailscale
|
||||||
|
# overlay; manager allowlist = 100.64.0.0/10). journald stays the local SoR.
|
||||||
|
#
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
MGR="tsys-wazuh.knel.net"
|
||||||
|
|
||||||
|
if ! dpkg -s rsyslog >/dev/null 2>&1; then
|
||||||
|
echo "installing rsyslog"
|
||||||
|
DEBIAN_FRONTEND=noninteractive apt-get install -y rsyslog
|
||||||
|
fi
|
||||||
|
|
||||||
|
F=/etc/rsyslog.d/90-forward-wazuh.conf
|
||||||
|
if [ ! -f "$F" ]; then
|
||||||
|
printf '# Wazuh syslog forwarding (Tailscale overlay) [#335]\n*.* @@%s:514\n' "$MGR" > "$F"
|
||||||
|
echo "forward rule installed"
|
||||||
|
else
|
||||||
|
echo "forward rule already present"
|
||||||
|
fi
|
||||||
|
|
||||||
|
systemctl enable --now rsyslog >/dev/null 2>&1 || true
|
||||||
|
systemctl restart rsyslog
|
||||||
|
sleep 2
|
||||||
|
systemctl -q is-active rsyslog && echo "rsyslog ACTIVE"
|
||||||
|
logger -p auth.warning "wazuh-trail-test host=$(hostname) stamp=$(date +%s)"
|
||||||
|
echo "trail event sent from $(hostname)"
|
||||||
Reference in New Issue
Block a user