Browse Source

bugfixes

135-scirius
Steven Foerster 5 years ago
parent
commit
bd6197ab36
  1. 11
      scripts/services/scirius/init.sh

11
scripts/services/scirius/init.sh

@ -73,21 +73,22 @@ pushd .
cd /opt/mistborn cd /opt/mistborn
# ensure group exists # ensure group exists
sudo docker-compose -f extra/wazuh.yml exec wazuh /var/ossec/bin/agent_groups -a -g suricata -q 2>/dev/null sudo docker-compose -f extra/wazuh.yml exec -T wazuh /var/ossec/bin/agent_groups -a -g suricata -q 2>/dev/null
# add this host to group # add this host to group
WAZUH_ID=$(sudo docker-compose -f extra/wazuh.yml exec wazuh /var/ossec/bin/manage_agents -l | egrep ^\ *ID | grep $(hostname) | awk '{print $2}' | tr -d ',') WAZUH_ID=$(sudo docker-compose -f extra/wazuh.yml exec -T wazuh /var/ossec/bin/manage_agents -l | egrep ^\ *ID | grep $(hostname) | awk '{print $2}' | tr -d ',')
sudo docker-compose -f extra/wazuh.yml exec wazuh /var/ossec/bin/agent_groups -a -i ${WAZUH_ID} -g suricata -q sudo docker-compose -f extra/wazuh.yml exec -T wazuh /var/ossec/bin/agent_groups -a -i ${WAZUH_ID} -g suricata -q
# write agent.conf # write agent.conf
sudo docker-compose -f extra/wazuh.yml exec wazuh cat > /var/ossec/etc/shared/linux/agent.conf << EOF AGENT_CONFIG="
<agent_config> <agent_config>
<localfile> <localfile>
<log_format>json</log_format> <log_format>json</log_format>
<location>/var/log/suricata/eve.json</location> <location>/var/log/suricata/eve.json</location>
</localfile> </localfile>
</agent_config> </agent_config>
EOF "
sudo docker-compose -f extra/wazuh.yml exec -T wazuh bash -c "echo ${AGENT_CONFIG} > /var/ossec/etc/shared/suricata/agent.conf"
# restart manager # restart manager
sudo docker-compose -f extra/wazuh.yml restart wazuh sudo docker-compose -f extra/wazuh.yml restart wazuh

Loading…
Cancel
Save