Multi-Node Indexer Additions

223 views
Skip to first unread message

Sam Heuchert

unread,
Nov 2, 2023, 4:03:31 PM11/2/23
to Wazuh | Mailing List
I currently have a 4-node cluster running in a distributed Wazuh deployment.  I'm hoping to add an additional four nodes to my original four nodes.  What is the process for doing this?

Thanks!

Luciano Gorza

unread,
Nov 3, 2023, 8:42:09 AM11/3/23
to Wazuh | Mailing List
Hi Sam, you just add the master's address in the /var/ossec/etc/ossec.conf file of each new worker node and that's it. I leave you these useful documentation links:

Sam Heuchert

unread,
Nov 12, 2023, 1:31:04 PM11/12/23
to Wazuh | Mailing List
Hi Luciano,

Thank you for the information, but I was hoping to glean information of adding to my Wazuh Indexer cluster, not my worker cluster.  Can you assist?

Luciano Gorza

unread,
Dec 14, 2023, 7:41:10 AM12/14/23
to Wazuh | Mailing List
Hi Sam, I'm really sorry for the delay, the google group was down for a while...

To add a Wazuh indexer node to an existing cluster, follow the step-by-step installation procedure.
In the certificate creation step, you can use the previous config.yml. A new file can be created if required. Download the file, modify it using the names of the existing nodes, and then add the new node.
Once the new node has been created, configure it to be part of the cluster.
Next, in the Deploying certificates step, deploy only the certificate for the new node, so use the new node name in the variable NODE_NAME=<indexer-node-name>.
Then, reinitialize the cluster.

Best regards,

Luciano Gorza

unread,
Dec 14, 2023, 8:03:32 AM12/14/23
to Wazuh | Mailing List

After the steps I mentioned in the last message, y forgot this one:

  • After that, add the new indexer node to the Filebeat configuration file, as explained here.
Reply all
Reply to author
Forward
0 new messages