Ah of course the admin password 🙄
{
"name" : "node-1",
"cluster_name" : "wazuh-cluster",
"cluster_uuid" : "20Fnamj-QP-BDLlfD3px5w",
"version" : {
"number" : "7.10.2",
"build_type" : "rpm",
"build_hash" : "e505b10357c03ae8d26d675172402f2f2144ef0f",
"build_date" : "2022-01-14T03:38:06.881862Z",
"build_snapshot" : false,
"lucene_version" : "8.10.1",
"minimum_wire_compatibility_version" : "6.8.0",
"minimum_index_compatibility_version" : "6.0.0-beta1"
},
"tagline" : "The OpenSearch Project: https://opensearch.org/"
}
Wazuh version: {"WAZUH_VERSION":"v4.3.5"},{"WAZUH_REVISION":"40317"},{"WAZUH_TYPE":"server"}
Filebeat running OK:
filebeat test output
elasticsearch: https://127.0.0.1:9200...
parse url... OK
connection...
parse host... OK
dns lookup... OK
addresses: 127.0.0.1
dial up... OK
TLS...
security: server's certificate chain verification is enabled
handshake... OK
TLS version: TLSv1.3
dial up... OK
talk to server... OK
version: 7.10.2
systemctl status wazuh-dashboard:
* wazuh-dashboard.service - wazuh-dashboard
Loaded: loaded (/etc/systemd/system/wazuh-dashboard.service; enabled; vendor preset: enabled)
Active: active (running) since Fri 2022-07-01 18:07:19 UTC; 3 days ago
Main PID: 108 (node)
Tasks: 11 (limit: 232003)
Memory: 200.3M
CPU: 8min 17.813s
CGroup: /system.slice/wazuh-dashboard.service
`-108 /usr/share/wazuh-dashboard/bin/../node/bin/node --no-warnings --max-http-header-size=65536 --unhandled-rejections=warn /usr/share/wazuh-dashboard/bin/../src/cli/dist -c /etc/wazuh-dashboard/>
Jul 05 09:14:56 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:14:56Z","tags":[],"pid":108,"method":"get","statusCode":200,"req":{"url":"/ui/favicons/favicon.ico","method":"ge>
Jul 05 09:14:56 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:14:56Z","tags":[],"pid":108,"method":"get","statusCode":200,"req":{"url":"/ui/fonts/inter_ui/Inter-UI-Light-BETA>
Jul 05 09:14:56 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:14:56Z","tags":[],"pid":108,"method":"get","statusCode":200,"req":{"url":"/ui/fonts/inter_ui/Inter-UI-Bold.woff2>
Jul 05 09:14:57 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:14:56Z","tags":[],"pid":108,"method":"post","statusCode":200,"req":{"url":"/api/request","method":"post","header>
Jul 05 09:14:57 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:14:56Z","tags":[],"pid":108,"method":"post","statusCode":200,"req":{"url":"/api/request","method":"post","header>
Jul 05 09:14:57 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:14:56Z","tags":[],"pid":108,"method":"post","statusCode":200,"req":{"url":"/api/request","method":"post","header>
Jul 05 09:14:57 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:14:56Z","tags":[],"pid":108,"method":"post","statusCode":200,"req":{"url":"/api/check-stored-api","method":"post>
Jul 05 09:14:57 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:14:57Z","tags":[],"pid":108,"method":"get","statusCode":200,"req":{"url":"/ui/favicons/favicon.ico","method":"ge>
Jul 05 09:15:24 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:15:24Z","tags":[],"pid":108,"method":"get","statusCode":200,"req":{"url":"/plugins/wazuh/assets/images/themes/li>
Jul 05 09:15:24 wazuh opensearch-dashboards[108]: {"type":"response","@timestamp":"2022-07-05T09:15:24Z","tags":[],"pid":108,"method":"get","statusCode":200,"req":{"url":"/ui/default_branding/opensearch_mark_d>
ossec.log:
2022/07/05 10:09:01 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2022/07/05 10:09:02 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2022/07/05 10:11:52 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:11:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:11:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:11:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:11:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:11:52 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 10:16:52 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:16:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:16:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:16:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:16:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:16:52 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 10:21:52 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:21:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:21:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:21:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:21:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:21:52 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 10:26:52 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:26:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:26:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:26:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:26:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:26:52 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 10:31:52 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:31:52 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:31:52 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:31:53 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:31:53 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:31:53 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 10:36:53 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:36:53 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:36:53 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:36:53 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:36:53 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:36:53 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 10:41:53 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:41:53 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:41:53 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:41:53 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:41:53 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:41:53 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 10:45:33 wazuh-modulesd:vulnerability-detector: INFO: (5400): Starting 'Ubuntu Trusty' database update.
2022/07/05 10:46:01 wazuh-modulesd:vulnerability-detector: INFO: (5430): The update of the 'Ubuntu Trusty' feed finished successfully.
2022/07/05 10:46:53 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:46:53 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:51:53 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:51:53 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:51:53 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:51:53 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:51:53 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 10:54:00 wazuh-modulesd:vulnerability-detector: INFO: (5400): Starting 'Ubuntu Bionic' database update.
2022/07/05 10:54:04 wazuh-modulesd:vulnerability-detector: INFO: (5430): The update of the 'Ubuntu Bionic' feed finished successfully.
2022/07/05 10:54:27 wazuh-modulesd:vulnerability-detector: INFO: (5400): Starting 'Ubuntu Focal' database update.
2022/07/05 10:54:53 wazuh-modulesd:vulnerability-detector: INFO: (5430): The update of the 'Ubuntu Focal' feed finished successfully.
2022/07/05 10:54:53 wazuh-modulesd:vulnerability-detector: INFO: (5400): Starting 'Debian Stretch' database update.
2022/07/05 10:54:54 wazuh-modulesd:vulnerability-detector: INFO: (5430): The update of the 'Debian Stretch' feed finished successfully.
2022/07/05 10:54:54 wazuh-modulesd:vulnerability-detector: INFO: (5400): Starting 'Debian Buster' database update.
2022/07/05 10:54:55 wazuh-modulesd:vulnerability-detector: INFO: (5430): The update of the 'Debian Buster' feed finished successfully.
2022/07/05 10:55:03 wazuh-modulesd:vulnerability-detector: INFO: (5400): Starting 'Debian Bullseye' database update.
2022/07/05 10:55:04 wazuh-modulesd:vulnerability-detector: INFO: (5430): The update of the 'Debian Bullseye' feed finished successfully.
2022/07/05 10:56:51 wazuh-modulesd:vulnerability-detector: INFO: (5400): Starting 'National Vulnerability Database' database update.
2022/07/05 10:56:56 wazuh-modulesd:vulnerability-detector: INFO: (5430): The update of the 'National Vulnerability Database' feed finished successfully.
2022/07/05 10:56:56 wazuh-modulesd:vulnerability-detector: INFO: (5400): Starting 'Microsoft Security Update' database update.
2022/07/05 10:56:56 wazuh-modulesd:vulnerability-detector: INFO: (5430): The update of the 'Microsoft Security Update' feed finished successfully.
2022/07/05 10:56:57 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 10:56:57 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 10:56:57 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 10:56:57 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 10:56:57 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 10:56:57 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 11:01:57 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 11:01:57 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 11:01:57 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 11:01:57 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 11:01:57 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 11:01:57 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 11:06:57 wazuh-modulesd:vulnerability-detector: INFO: (5431): Starting vulnerability scan.
2022/07/05 11:06:57 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '007' vulnerabilities.
2022/07/05 11:06:57 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '007'
2022/07/05 11:06:57 wazuh-modulesd:vulnerability-detector: INFO: (5450): Analyzing agent '008' vulnerabilities.
2022/07/05 11:06:57 wazuh-modulesd:vulnerability-detector: INFO: (5471): Finished vulnerability assessment for agent '008'
2022/07/05 11:06:57 wazuh-modulesd:vulnerability-detector: INFO: (5472): Vulnerability scan finished.
2022/07/05 11:09:02 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2022/07/05 11:09:03 wazuh-modulesd:syscollector: INFO: Evaluation finished.