Wazuh Install - Worlds Best OpenSource EDR!

Поділитися
Вставка
  • Опубліковано 13 жов 2022
  • Join me as we continue on to Phase 3 of the World's Best SIEM Stack Series, installing the Wazuh Manager.
    Blog Post: / part-3-wazuh-manager-i...
    Contact Me: taylor.walton@socfortress.co
    LinkedIn: / socfortressmdr
    Twitter: / socfortress
    Our Blog: / socfortress
    Graylog Install: • Graylog Install - Best...
    Buy Me A Coffee: bit.ly/3woh21M
    Our Blog: / socfortress
    Security Operations Center as a Service: www.socfortress.co/
    Free For Life Tier: www.socfortress.co/trial.html
    Professional Services: www.socfortress.co/ps.html
    Discord Channel: / discord
    Series Playlist: • World's Best SIEM Stack
  • Наука та технологія

КОМЕНТАРІ • 34

  • @user-nn3uj8qo4e
    @user-nn3uj8qo4e Рік тому +1

    Thanks for great mood

  • @DavidWilliams-ug6un
    @DavidWilliams-ug6un Рік тому +2

    That was just great 👍

  • @vinayvinni9757
    @vinayvinni9757 Рік тому +3

    Fan of your work from india😃

  • @SiberKost
    @SiberKost Рік тому

    you are very genius and cool buddy

  • @ArmAikido
    @ArmAikido 8 місяців тому

    One question. Finally, is this entire series about EDR or SIEM?

  • @DM-gp6pd
    @DM-gp6pd Рік тому

    Super informative and practical series. But can you please uncover one topic about efficient way of transferring sysmon for linux events from endpoints to backend systems. Because they are stored in XML format and it's not so obvious which forwarders and options should be used.

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  Рік тому +2

      Checkout the decoder video:) Decoding Linux For Sysmon - Learn How To Ingest Sysmon For Linux Alerts into Wazuh
      ua-cam.com/video/y5K1pctFoaw/v-deo.html

  • @alejandroparrello6493
    @alejandroparrello6493 Рік тому +2

    you're the boss!! 👏☝️😉 regards from Argentina 👋😁

  • @tracerv0
    @tracerv0 Рік тому

    Good audio.

  • @MrSuhailmt
    @MrSuhailmt Рік тому

    Great content. Helped me alot. which tool you are using for ssh? it looks cool.

  • @surathwalpita
    @surathwalpita 8 днів тому

    While retrieving data for this widget, the following error(s) occurred:
    Elasticsearch exception [type=illegal_argument_exception, reason=key [types] is not supported in the metadata section]. Why I'm having this error ?

  • @photondoh5384
    @photondoh5384 Рік тому +3

    I wish wazuh had iso 27001 compliance dashboard.

    • @jarmandog8372
      @jarmandog8372 Рік тому

      That'd be amazing, maybe a custom dashboard? That's a great idea

    • @jig270
      @jig270 Рік тому

      it has i think nist ,you can compare nist and is027001 fro their site and use it.

  • @hydradragonantivirus
    @hydradragonantivirus Місяць тому

    How to compile it?

  • @krosstty
    @krosstty 3 місяці тому

    Hi, thanks a lot for your great content. It´s possible to help me with follow issue: [Alerts index pattern] No template found for the selected index-pattern title [wazuh-alerts-*]

  • @user-yu4im1mi4o
    @user-yu4im1mi4o 11 місяців тому +4

    In case if someone has the issue with error "Elasticsearch exception [type=illegal_argument_exception, reason=key [types] is not supported in the metadata section]." when try to see received messages (16:27), you needed to remove this from the Opensearch config file: compatibility.override_main_response_version: true (or just comment) and restart wazuh-dashboard and graylog-server

    • @joelnicholasfrancis2700
      @joelnicholasfrancis2700 11 місяців тому

      It gives me the same error

    • @mcastill3
      @mcastill3 11 місяців тому

      Same error for me

    • @user-lj6hj1sh4n
      @user-lj6hj1sh4n 11 місяців тому

      I also encountered the same problem, deleted the required line from opensearch.yml, did systemctl restart graylog-server, but still Elasticsearch exception [type=illegal_argument_exception, reason=key [types] is not supported in the metadata section].

    • @ArmAikido
      @ArmAikido 10 місяців тому +1

      The problem can be solved by installing Graylog 5.0 with MongoDB 6.0

    • @NareshKumar-hw4nl
      @NareshKumar-hw4nl 8 місяців тому

      hi Please comment out the line under /etc/wazuh-indexer/opensearch.yml
      #compatibility.override_main_response_version: true
      This worked for me.
      i got same error even after installing Gralog 5.0 and mongoDb 6.0

  • @pragmatickaos852
    @pragmatickaos852 Місяць тому

    I don't understand why Graylog is in the picture. You're already using Fluent Bit, which can already do all the filtering and renaming and much more. It can even integrate with GeoLite2 IP geolocation. I decided not to install Graylog.

  • @nopromises884
    @nopromises884 Рік тому +2

    i am deploy wazuh manager graylog successfully i can see data in grafana but i cant see wazuh dashboard security event and and other alert from from wazuh .is there any way to see both dashboard wazuh and grafana?

    • @lupeadorin4282
      @lupeadorin4282 3 місяці тому

      Did you find any way to resolve this issue?

  • @totonhaldar4282
    @totonhaldar4282 4 місяці тому

    খুব ভালো জ্ঞনলস

  • @amruth1936
    @amruth1936 Рік тому

    Hi Bro,
    I followed all your steps . regarding wazuh * and graylog. now i am unable to assign a group to wazuh agent . Please guid me

    • @amruth1936
      @amruth1936 Рік тому

      error is - Assign the agent to a group
      This section could not be configured because you do not have permission to read groups.

    • @PawsShip
      @PawsShip Рік тому

      @taylorwalton_socfortress

  • @gregg718
    @gregg718 Рік тому

    Could I do this install on Ubuntu Server or Ubuntu Desktop? I would like to do this using a VM does that require Docker?

  • @simoner105
    @simoner105 Рік тому

    fluent-bit is impossible to install on Kali linux

  • @iamreiver
    @iamreiver 6 місяців тому

    You pronounce it wrong.
    Huh
    Duh
    Wazuh

  • @user-zx6yo7yf5w
    @user-zx6yo7yf5w Рік тому

    к