Multi-Tenant Wazuh - Learn How to Deploy a Multi-Tenant Wazuh and OpenSearch Cluster!

Поділитися
Вставка
  • Опубліковано 27 жов 2024

КОМЕНТАРІ • 34

  • @jag831
    @jag831 2 роки тому +3

    I'm slowly turning to your channel instead of the official documentation.. Your videos are always on-point and with a perfect rhythm and pace for the topic at hand!

  • @aviwemusa6109
    @aviwemusa6109 3 місяці тому

    Can you please do Wazuh multi-site implementation that helps organizations unify their security monitoring capabilities across multiple geographically dispersed locations or sites with single dashboard?

  • @JoeLopezNJ
    @JoeLopezNJ 2 роки тому +1

    This is not OpenSearch,. This is the predecessor Open Distro that is being retired. Wazuh doesn't yet support Opensearch since Kibana no longer exists and has been changed/ forked to opensearch-dashboard

  • @abdulsamad-as
    @abdulsamad-as 2 роки тому

    Thanks for best guide

  • @trev8813
    @trev8813 2 роки тому +1

    Great video! Do you know if you can add these different labels to ingested AWS or GCP logs as well? So one logs coming from one AWS account could be labeled "AWS-A" and logs coming from another AWS account could be labeled "AWS-B"? Thanks!

  • @tombanaria97
    @tombanaria97 3 місяці тому

    It looks like the permissions from Opensearch cluster has changed. Can you help me figure out the corresponding cluster value for opensearch?

  • @Claudia-x5y
    @Claudia-x5y 2 місяці тому

    Hello Taylor, could you please redo this video on Wazuh 4.8. Thank You

  • @radisociale
    @radisociale Рік тому

    great video, I recently installed the multi-server wazuh but since this video was released there have been some changes to the UI and some parameters don't apply anymore (I don't really have anywhere to paste what you did ). Any advice?

  • @bitstop2003
    @bitstop2003 11 місяців тому

    agree with jag831. your video is better than Wazuh documentation. However, im stuck somewhere and need help. How do i troubleshoot the "Wazuh API error: ERR_BAD_Request - Permission denied: Resource type: *.* " ?
    a full detail error:
    You have no permissions. Contact to an administrator:
    no permissions for [indices:data/read/search] and User [name=venus, backend_roles=[], requestedTenant=]: security_exception: [security_exception] Reason: no permissions for [indices:data/read/search] and User [name=venus, backend_roles=[], requestedTenant=]

  • @PaulEmmanuelAustria
    @PaulEmmanuelAustria 8 місяців тому

    Will this setup same as multiple wazuh server connected to a single wazuh manager? As far as I understand, the two agents are server A and ServerB.

  • @Nafay1991
    @Nafay1991 2 роки тому +1

    i followed exactly your video but getting errors.. you might work something else which is miss from video

  • @erikkirschner8681
    @erikkirschner8681 Рік тому +2

    hello, I try this setup on wazuh appliance v4.3.10 anf I recieve this message after login like group user:
    You have no permissions. Contact to an administrator: no permissions for [indices:data/read/search] and User [name=gc1, backend_roles=[], requestedTenant=null]: security_exception
    @Taylor, can you help me please, or do you have any idea where is problem?
    thnak you

    • @fernandolopez204
      @fernandolopez204 Рік тому

      could you solve this error?

    • @erikkirschner8681
      @erikkirschner8681 Рік тому +1

      @@fernandolopez204 Yes, in documentation are some script and steps for this problem...

    • @fernandolopez204
      @fernandolopez204 Рік тому +1

      @@erikkirschner8681 Thanks for answering... could you guide me a bit or give me more information? I'm new to Wazuh and I still can't find the solution to the problem within the documentation.

    • @bitstop2003
      @bitstop2003 11 місяців тому

      I have the exact problem, I read the documentation, but couldn't find a solution. Can you help?

    • @BruceMartins
      @BruceMartins 3 місяці тому +1

      go into Opensearch security, select Internal users and edit the users you added using the above video. Each user needs two backend roles added one called "kibanauser" the other "readall" click save changes and you should be able to login with those users afterwards

  • @weslysibagariang843
    @weslysibagariang843 Рік тому +1

    Hi, thanks for the content.
    I followed your steps but i got this error:
    {You have no permissions. Contact to an administrator:
    no permissions for [indices:data/read/search] and User [name=user1, backend_roles=[], requestedTenant=null]: security_exception}.
    Can you please help to resolve this?

    • @fernandolopez204
      @fernandolopez204 Рік тому

      could you solve this error?

    • @UberBaby168
      @UberBaby168 Рік тому

      Hi Taylor, I'm using v4.6.0 and also got the same permission error after following your step by step twice! Please advise. Thanks!

    • @BruceMartins
      @BruceMartins 3 місяці тому

      go into Opensearch security, select Internal users and edit the users you added using the above video. Each user needs two backend roles added one called "kibanauser" the other "readall" click save changes and you should be able to login with those users afterwards

  • @sephirothfemto
    @sephirothfemto Рік тому

    I am missing agent.labels in the events. How can I add it?

  • @paulolima3848
    @paulolima3848 2 роки тому

    Hi, thanks for the content! It's very usefull specially to MSP that are starting a SOC-SIEM service.
    I have a question about the way to labeling the syslog events as you did with the agents. There is any way to segregate syslog events from firewalls and switchs by Clients?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 роки тому +1

      You could use a sequence of rules to separate firewall and switch events per client by using a field name of the agent label. Something like the below may work:
      firewall
      customer1
      Customer1 Firewall Alert
      firewall
      customer2
      Customer2 Firewall Alert
      switch
      customer1
      Customer1 Switch Alert
      etc. Hope this helps and thanks for watching!

    • @ngenen
      @ngenen 2 роки тому +1

      @@taylorwalton_socfortress can you make a video about this aproach? I dont get how the if_group would work with several devices sending syslog to the wazuh manager.

  • @makarachhum1641
    @makarachhum1641 3 роки тому

    That's an awesome tutorial video !!!!

  • @nopromises884
    @nopromises884 2 роки тому

    its possible in do in elasticsearch? rather then Open Distro? thanks

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 роки тому +1

      Unfortunately no. You’d have to pay for an elasticsearch license

    • @nopromises884
      @nopromises884 2 роки тому

      @@taylorwalton_socfortress thanks for your quick response.one further query if i use open distro can i use own certified and can i use all beats like filebeat,metricbeat etc. and can i use thehive,cortex,misp in open-distro as like elasticsearch thanks.

  • @tashfeenlatif5496
    @tashfeenlatif5496 2 роки тому

    time 5.54 .where to get these IP's that you use

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 роки тому +2

      That is the public IP address of my Wazuh Manager. Thanks for watching :)

    • @tashfeenlatif5496
      @tashfeenlatif5496 2 роки тому

      @@taylorwalton_socfortress i get it know .Thanks for response