root@wazuh-worker-1:~# cat /etc/netplan/00-installer-config.yaml
# This is the network config written by 'subiquity'
network:
ethernets:
ens33:
dhcp4: no
dhcp6: no
addresses: [192.168.1.210/24]
gateway4: 192.168.1.2
nameservers:
addresses: [114.114.114.114,8.8.8.8]
version: 2
root@wazuh-worker-1:~# curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | apt-key add -
OK
第二步导入wazuh仓库的软件包的安装信息;
root@wazuh-worker-1:~# echo "deb https://packages.wazuh.com/4.x/apt/ stable main" | tee -a /etc/apt/sources.list.d/wazuh.list
deb https://packages.wazuh.com/4.x/apt/ stable main
root@wazuh-worker-1:/opt# dpkg -i wazuh-manager_4.1.5-1_amd64.deb
Selecting previously unselected package wazuh-manager.
(Reading database ... 67182 files and directories currently installed.)
Preparing to unpack wazuh-manager_4.1.5-1_amd64.deb ...
Unpacking wazuh-manager (4.1.5-1) ...
Setting up wazuh-manager (4.1.5-1) ...
Processing triggers for ureadahead (0.100.0-21) ...
Processing triggers for systemd (237-3ubuntu10.42) ...
安装wazuh服务端之后,需要设置开机启动和启动服务。
root@wazuh-worker-1:/opt# systemctl daemon-reload
root@wazuh-worker-1:/opt# systemctl enable wazuh-manager
Synchronizing state of wazuh-manager.service with SysV service script with /lib/systemd/systemd-sysv-install.
Executing: /lib/systemd/systemd-sysv-install enable wazuh-manager
Created symlink /etc/systemd/system/multi-user.target.wants/wazuh-manager.service → /usr/lib/systemd/system/wazuh-manager.service.
root@wazuh-worker-1:/opt# systemctl start wazuh-manager
查看wazuh服务端服务是否起来
root@wazuh-worker-1:/opt# systemctl status wazuh-manager
● wazuh-manager.service - Wazuh manager
Loaded: loaded (/usr/lib/systemd/system/wazuh-manager.service; enabled; vendor preset: enabled)
Active: active (running) since Fri 2021-06-25 14:10:34 UTC; 44s ago
Process: 37814 ExecStart=/usr/bin/env ${DIRECTORY}/bin/ossec-control start (code=exited, status=0/SUCCESS)
Tasks: 95 (limit: 1077)
CGroup: /system.slice/wazuh-manager.service
├─37882 /var/ossec/framework/python/bin/python3 /var/ossec/api/scripts/wazuh-apid.py
├─37922 /var/ossec/bin/ossec-authd
├─37938 /var/ossec/bin/wazuh-db
├─37961 /var/ossec/bin/ossec-execd
├─37975 /var/ossec/bin/ossec-analysisd
├─38010 /var/ossec/bin/ossec-syscheckd
├─38026 /var/ossec/bin/ossec-remoted
├─38062 /var/ossec/bin/ossec-logcollector
├─38080 /var/ossec/bin/ossec-monitord
└─38093 /var/ossec/bin/wazuh-modulesd
Jun 25 14:10:25 wazuh-worker-1 env[37814]: Started wazuh-db...
Jun 25 14:10:26 wazuh-worker-1 env[37814]: Started ossec-execd...
Jun 25 14:10:27 wazuh-worker-1 env[37814]: Started ossec-analysisd...
Jun 25 14:10:28 wazuh-worker-1 env[37814]: Started ossec-syscheckd...
Jun 25 14:10:29 wazuh-worker-1 env[37814]: Started ossec-remoted...
Jun 25 14:10:30 wazuh-worker-1 env[37814]: Started ossec-logcollector...
Jun 25 14:10:31 wazuh-worker-1 env[37814]: Started ossec-monitord...
Jun 25 14:10:32 wazuh-worker-1 env[37814]: Started wazuh-modulesd...
Jun 25 14:10:34 wazuh-worker-1 env[37814]: Completed.
Jun 25 14:10:34 wazuh-worker-1 systemd[1]: Started Wazuh manager.