From da5658a99ada6eb773c06d39566b8dbcec6dcc42 Mon Sep 17 00:00:00 2001 From: Rudi Klein Date: Thu, 23 May 2024 18:51:30 +0200 Subject: [PATCH] build fix --- Writerside/notifier.tree | 1 - Writerside/topics/Wazuh-notifier.md | 43 ++++++++++++++--------------- 2 files changed, 21 insertions(+), 23 deletions(-) diff --git a/Writerside/notifier.tree b/Writerside/notifier.tree index 3da815d..2482177 100644 --- a/Writerside/notifier.tree +++ b/Writerside/notifier.tree @@ -7,5 +7,4 @@ start-page="Wazuh-notifier.md"> - \ No newline at end of file diff --git a/Writerside/topics/Wazuh-notifier.md b/Writerside/topics/Wazuh-notifier.md index 22996e6..600338a 100644 --- a/Writerside/topics/Wazuh-notifier.md +++ b/Writerside/topics/Wazuh-notifier.md @@ -7,7 +7,6 @@ - [Configuration](#configuration) - [The YAML configuration](#the-yaml-configuration) - ## Introduction Wazuh notifier enables the Wazuh manager to be notified when selected events occur, using 3 messaging platforms: @@ -30,20 +29,20 @@ Download the files from https://github.com/kleinprojects/wazuh-notify to your se #### _Python_ {id="python_1"} -##### Copy the 2 Python scripts to the /var/ossec/active-response/bin/ folder +Copy the 2 Python scripts to the /var/ossec/active-response/bin/ folder ``` $ sudo cp /wazuh-*.py /var/ossec/active-response/bin/ ``` -##### Set the correct ownership {id="set-the-correct-ownership_1"} +Set the correct ownership {id="set-the-correct-ownership_1"} ``` $ sudo chown root:wazuh /var/ossec/active-response/bin/wazuh-notify.py $ sudo chown root:wazuh /var/ossec/active-response/bin/wazuh_notify_module.py ``` -##### Set the correct permissions {id="set-the-correct-permissions_1"} +Set the correct permissions {id="set-the-correct-permissions_1"} ``` $ sudo chmod uog+rx /var/ossec/active-response/bin/wazuh-notify.py @@ -52,19 +51,19 @@ $ sudo chmod uog+rx /var/ossec/active-response/bin/wazuh_notify_module.py #### _Golang_ {id="golang_1"} -##### Copy the Go executable to the /var/ossec/active-response/bin/ folder +Copy the Go executable to the /var/ossec/active-response/bin/ folder ``` $ sudo cp /wazuh-notify /var/ossec/active-response/bin/ ``` -##### the correct ownership {id="set-the-correct-ownership_2"} +Set the correct ownership {id="set-the-correct-ownership_2"} ``` $ sudo chown root:wazuh /var/ossec/active-response/bin/wazuh-notify ``` -##### Set the correct permissions {id="set-the-correct-permissions_2"} +Set the correct permissions {id="set-the-correct-permissions_2"} ``` $ sudo chmod uog+rx /var/ossec/active-response/bin/wazuh-notify @@ -72,19 +71,19 @@ $ sudo chmod uog+rx /var/ossec/active-response/bin/wazuh-notify ### Step 3 -##### Copy the YAML file to /var/ossec/etc/ +Copy the YAML file to /var/ossec/etc/ ``` $ sudo cp /wazuh-notify-config.yaml /var/ossec/etc/ ``` -##### Set the correct ownership {id="set-the-correct-ownership_3"} +Set the correct ownership {id="set-the-correct-ownership_3"} ``` $ sudo chown root:wazuh /var/ossec/etc/wazuh-notify-config.yaml ``` -##### Set the correct permissions {id="set-the-correct-permissions_3"} +Set the correct permissions {id="set-the-correct-permissions_3"} ``` $ sudo chmod uog+r /var/ossec/etc/wazuh-notify-config.yaml @@ -92,19 +91,19 @@ $ sudo chmod uog+r /var/ossec/etc/wazuh-notify-config.yaml ### Step 4 -##### Create an .env file in /var/ossec/etc/ +Create an .env file in /var/ossec/etc/ ``` $ sudo touch /var/ossec/etc/.env ``` -#### Set the correct ownership {id="set-the-correct-ownership_4"} +Set the correct ownership {id="set-the-correct-ownership_4"} ``` $ sudo chown root:wazuh /var/ossec/etc/wazuh-notify-config.yaml ``` -#### Set the correct permissions {id="set-the-correct-permissions_4"} +Set the correct permissions {id="set-the-correct-permissions_4"} ``` $ sudo chmod uog+r /var/ossec/etc/wazuh-notify-config.yaml @@ -112,11 +111,11 @@ $ sudo chmod uog+r /var/ossec/etc/wazuh-notify-config.yaml ## Configuration -#### Golang {id="golang_2"} +#### _Golang_ {id="golang_2"} -Modify the /var/ossec/etc/ossec.conf configuration file and add the following
+Modify the /var/ossec/etc/ossec.conf configuration file and add the following:
-Command section +*Command section* ``` @@ -126,7 +125,7 @@ Command section ``` -Active response section +*Active response section* ``` @@ -137,9 +136,9 @@ Active response section ``` -#### Python {id="python_2"} +#### _Python_ {id="python_2"} -Command section +*Command section* ``` @@ -149,7 +148,7 @@ Command section ``` -Active response section +*Active response section* ``` @@ -160,7 +159,7 @@ Active response section ``` -### NOTE: +#### NOTE: The `````` in the `````` section needs to be the same as the `````` in the `````` section. @@ -170,7 +169,7 @@ trigger that runs the ``````. Add the rules you want to be informed about between the ``````, with the rules id's separated by comma's. Example: ```5402, 3461, 8777
``` -(Please refer to the Wazuh online documentation for more information [^Wazuh docs]) +(Please refer to the [Wazuh online documentation](https://documentation.wazuh.com/current/user-manual/capabilities/active-response/index.html) for more information [^Wazuh docs]) [^Wazuh docs]: https://documentation.wazuh.com/current/user-manual/capabilities/active-response/index.html