Syslog and Wazuh - Let's Build A Host Intrusion Detection System

Поделиться
HTML-код
  • Опубликовано: 10 июл 2021
  • Join me as we configure your Wazuh Manager to receive Syslog output. Receive your Firewall logs! Let's deploy a Host Intrusion Detection System and SIEM with free open source tools. Join me as we explore and learn together.
    Check us out: www.opensecure.co/
    Interact with our demo: www.opensecure.co/demo
    Hire us: www.opensecure.co/contact-us
  • НаукаНаука

Комментарии • 54

  • @lamarlewis7638
    @lamarlewis7638 2 года назад

    Great work on the video. Thank you for saving me some time! 😊

  • @MrBitviper
    @MrBitviper 2 года назад

    thanks for the concise and clear video
    much appreciated

  • @arifbudiman7754
    @arifbudiman7754 2 года назад

    Great Video Man, thanks for the insight 😊

  • @AnthonyElabed
    @AnthonyElabed 2 месяца назад

    Amazing video, thank you so much, you are a life saver for a project I'm working!! For linux users remember that the logs on your client are stored in /var/log/syslog

  • @JeDeXxRioProKing
    @JeDeXxRioProKing 3 года назад

    Great Content , Thanks for video

  • @iDjDepp
    @iDjDepp 2 года назад

    Great video, really helped set up the transmission. You mentioned transferring data from network devices such as Cisco. Maybe there are ready-made dashboard templates and how to process this data?

  • @oliveiras.de.emerson
    @oliveiras.de.emerson 2 года назад +1

    I love you guy

  • @TheMeshal20
    @TheMeshal20 2 года назад +2

    Thank so mush , can you make a video to integrate pfsnes firewall and Email server

  • @chinatu10
    @chinatu10 Год назад

    Great video, but do you have a video that integrates with edr solutions

  • @streetechco123
    @streetechco123 11 месяцев назад

    dear taylor, what happen if the server its full with the logs, how do you delete the logs that are into the wazuh server?

  • @chadmarkley
    @chadmarkley 2 года назад

    Great video!! I used your Docker video to get the Wazuh cluster setup and running. Works great. Question. Under Settings and Configuration, i don't seem to have the "edit configuration" option. Any idea how i can get that to show up? Having that would be SO MUCH EASIER than trying to do it from inside the docker container using VI! Thanks

  • @DannyDi84
    @DannyDi84 Год назад

    As far as I know, syslogs are sent in plain text, so I guess it wouldn't be recommended to use this method when the Wazuh Server is on a hosted VM in another Network. Is there a solution to this?

  • @muharaveen46
    @muharaveen46 Год назад

    Hi! I'm having the issue "Kibana service is not ready yet" . Am I doing something wrong?

  • @jasonmichel1946
    @jasonmichel1946 2 года назад

    Can you add multiple address ranges for allowed ips in the same block or do you have to create a new block for each entry for syslog?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад +1

      Hey Jason, you will need to add a new 192.168.2.0/24 block that details the new CIDR range.
      Thanks for watching!

  • @huseyinozer2737
    @huseyinozer2737 Год назад +1

    Hello first of all thanks for video,
    Syslogs from Synology do not appear on wazuh. When I listen to port 514, I see messages coming, but the messages do not appear in the discover section. It was written in some forums that it could not be solved because it came in rfc3164 message format. When I write the log to the test decoder section, I get the error "decoder not found". Any idea?

    • @tamaskiss6379
      @tamaskiss6379 4 месяца назад

      Hi, i have this problem too. Did you find any solution?

  • @user-jw3mx8we8h
    @user-jw3mx8we8h 5 месяцев назад

    Hope for next video, fortigate sync with wazuh

  • @syedomairmasood6785
    @syedomairmasood6785 8 месяцев назад

    can you paste all the commands that are in your notepad?

  • @TheT8T
    @TheT8T 2 года назад

    I am missing something... I have configured my Fortigate to forward logs to the Wazuh Manager. I see them in the Archives.json and the Archives.log. I do not see them in the dashboard of Wazuh. Following another tutorial that has since been taken down from YT, it has 2 Decoder files installed. What am I missing?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      Hey Chris, if it is writing to the archives.json then that is telling me Wazuh is receiving the logs, so that's good. What it is probably lacking is a decoder and rule to match on the ingested logs. Only logs that are matched are written to the alerts.json file and allows you to view them in kibana. A good way to test is copy the log entry within the archives.json and run the /var/ossev/bin/ossec-logtest , paste in the copied log entry, and see what Wazuh outputs. From there you can start to build decoders and rules to match. Hope this helps!

  • @rakeshbaboeram1808
    @rakeshbaboeram1808 Год назад

    Hi Taylor. Thanks for a great video. I've been able to setup syslog on a firewall and linux machine. I see the syslog packets hitting the Wazuh Manager. unfortunately, I don't see any alerts in the "discover". Any ideas what I'm doing wrong?

    • @seyladamarisgomez7488
      @seyladamarisgomez7488 Год назад +1

      Hi Rakesh!
      Did you continue with this problem?
      Regards.

    • @rakeshbaboeram1808
      @rakeshbaboeram1808 Год назад +1

      @@seyladamarisgomez7488 unfortunately not

    • @ryanhall5059
      @ryanhall5059 9 месяцев назад +1

      I'm on a fresh install and having this issue also. I have pulled wireshark and have confirmed syslog is being sent to the server. Just nothing shows up.

  • @Samran_Shahzad
    @Samran_Shahzad 5 месяцев назад

    Hi, anyone tell me that how can I confirm that my linux rsyslog is coming in wazuh dashboard how to check that?? How to configure rsyslog of kali linux without adding as an agent??

  • @gaplans
    @gaplans 3 года назад

    Thanks for video.
    It was a life saver ( gaplan )

  • @marciolima174
    @marciolima174 2 года назад

    In my case I use opendistro and kibana and wazuh and filebeat on different servers, in sysloghost which ip do I need to set? Since the opendistro
    opens the interface of the wazuh config.

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      You will need to point your syslog host to the IP of the Wazuh Manager. Wazuh will take those logs and send them to elastic.

    • @marciolima174
      @marciolima174 2 года назад

      @@taylorwalton_socfortress Thanks.

  • @brunobustos1368
    @brunobustos1368 7 месяцев назад

    como estas muy buen video , pero quiero saber como puedo integrar un waf imperva con wazuh por medio syslog , para que los eventos se vean en el dashboard.

  • @arunr039
    @arunr039 2 года назад

    Great video.
    i have a question how to get application logs (api/http)in wazuh and how do i visualize in kibana
    thanks in advance

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      Hey Arun you will need to enable the logs to be forwarded to the Wazuh manger. We did something similar with nginx logs here: ruclips.net/video/iHFZ-QDTX6o/видео.html
      Let me know if you have other questions and thanks for watching!

  • @safwanshahjehan7434
    @safwanshahjehan7434 2 года назад

    hey, great video! do you have any tutorials on viewing apache logs on Wazuh?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      Hey Safwan, I have not done a video regarding apache specifically, but the process should be the same. If you have a wazuh-agent running on your apache server, configure this block in the ossec.conf

      syslog
      /path/to/apache.log
      There are already decoders built for apache logs so you should start to see results after you restart the wazuh agent.
      Hope that helps and thanks for watching!

  • @user-cr5lb7ze7b
    @user-cr5lb7ze7b 9 месяцев назад

    I am unable to use the public ip addresses. Like my syslog server is located on different AWS server and wazuh manager is located on different location. So how do I connect these with the public ip address. I am unable to use the public address in wazuh conf file.

    • @zedtrek
      @zedtrek 5 месяцев назад

      Not sure would be a good idea to expose that kind of traffic anyway. I would use a VPN..

  • @fahmi8999
    @fahmi8999 6 месяцев назад

    Do you have videos that share how to develop Wazuh SIEM dashboard?

    • @user-jw3mx8we8h
      @user-jw3mx8we8h 5 месяцев назад

      its easy you can follow documentation

  • @numanmaavia8575
    @numanmaavia8575 2 года назад +1

    Hey open Secure, make a video how to integrate Azure Activity log onto wazuh. Thanks

  • @ryoka1g
    @ryoka1g 2 года назад

    any idea on how to integrate fortinet logs to wazuh??

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      Hey Chris, I do not have experience with Fortimet but this guide should help: docs.fortinet.com/document/fortianalyzer/7.0.2/administration-guide/19991/configuring-log-forwarding. Just need to point to the wazuh manager

    • @ryoka1g
      @ryoka1g 2 года назад

      @@taylorwalton_socfortress i actually managed as it was fairly simple (i guess syslog to syslog lol) now im trying to learn how to analyse these syslogs and find any attacks or smth

  • @gheryking
    @gheryking Год назад

    pleasesusbscribe... ready!!, great job.