

output.elasticsearch:
ssl.certificate_authorities:
- /etc/filebeat/certs/root-ca.pem
ssl.certificate: "/etc/filebeat/certs/wazuh-server.pem"
ssl.key: "/etc/filebeat/certs/wazuh-server-key.pem"
--
You received this message because you are subscribed to the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/a70d61f7-6ac0-4bb7-8a7a-55077aae689fn%40googlegroups.com.







Hello!I'm setting up wazuh dashboard. To do this I need to configure wazuh-manager, wazuh-indexer, filebeat, elasticsearch.
output.elasticsearch:
ssl.certificate_authorities:
- /etc/filebeat/certs/root-ca.pem
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/71bb0434-dd2e-4d9b-a921-8965774a5535n%40googlegroups.com.





I'm trying to set up a dashboard! All-in-one deployment without Kibana
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/0a00c665-44ba-410b-8e87-b34dac97aaben%40googlegroups.com.

Sep 20 13:39:22 centos71 systemd-entrypoint[2885]: WARNING: System::setSecurityManager will be removed in a future release
Sep 20 13:39:22 centos71 systemd-entrypoint[2885]: WARNING: Please consider reporting this to the maintainers of org.opensearch.bootstrap.OpenSearch
Sep 20 13:39:22 centos71 systemd-entrypoint[2885]: WARNING: System::setSecurityManager has been called by org.opensearch.bootstrap.OpenSearch (file:/usr/share/wazuh-indexer/lib/opensearch-2.6. 0.jar)
Sep 20 13:39:22 centos71 systemd-entrypoint[2885]: WARNING: A terminally deprecated method in java.lang.System has been called
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9a43d171-6983-467b-a3e0-0a49740f4d75n%40googlegroups.com.

To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/fad710bf-386d-468e-b32e-a9fd117653fan%40googlegroups.com.

To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/45ee8270-addd-4824-bb94-1981df20d7een%40googlegroups.com.


To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ec7874bc-1f72-40f2-b96b-c88c07f1cd76n%40googlegroups.com.

To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/a3b6ec4a-ae88-49aa-871d-48d2802f3a5an%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/da6e49b6-5e85-4ed9-89cc-8537fb705a16n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/f4d246ec-bd29-405e-afd0-e08b3f8f3deen%40googlegroups.com.
Sep 21 16:37:39 ossec systemd[1]: Starting Wazuh-indexer...
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: Exception in thread "main" SettingsException[Failed to load settings from [opensearch.yml]]; nested: ParsingException[Failed to parse object: expecting token of type [START_OBJECT] but found [VALUE_STRING]];
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.common.settings.Settings$Builder.loadFromStream(Settings.java:1140)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.common.settings.Settings$Builder.loadFromPath(Settings.java:1111)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.node.InternalSettingsPreparer.prepareEnvironment(InternalSettingsPreparer.java:96)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.cli.EnvironmentAwareCommand.createEnv(EnvironmentAwareCommand.java:118)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.cli.EnvironmentAwareCommand.createEnv(EnvironmentAwareCommand.java:109)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:104)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.cli.Command.mainWithoutErrorHandling(Command.java:138)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.cli.MultiCommand.execute(MultiCommand.java:104)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.cli.Command.mainWithoutErrorHandling(Command.java:138)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.cli.Command.main(Command.java:101)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.common.settings.KeyStoreCli.main(KeyStoreCli.java:56)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: Caused by: ParsingException[Failed to parse object: expecting token of type [START_OBJECT] but found [VALUE_STRING]]
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.common.xcontent.XContentParserUtils.parsingException(XContentParserUtils.java:97)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.common.xcontent.XContentParserUtils.ensureExpectedToken(XContentParserUtils.java:90)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.common.settings.Settings.fromXContent(Settings.java:621)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: at org.opensearch.common.settings.Settings$Builder.loadFromStream(Settings.java:1136)
Sep 21 16:37:41 ossec systemd-entrypoint[115191]: Exception in thread "main" SettingsException[Failed to load settings from [opensearch.yml]]; nested: ParsingException[Failed to parse object: expecting token of type [START_OBJECT] but found [VALUE_STRING]];
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9ccdcbcc-8bd3-4925-ab2b-7d5055234efen%40googlegroups.com.


network.host: "127.0.0.1"
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/8ea577a3-1650-47eb-8109-2f0269803631n%40googlegroups.com.
- CN=node-1,OU=Wazuh,O=Wazuh,L=California,C=US
- "CN=node-1,OU=Wazuh,O=Wazuh,L=California,C=US"
... .opendistro-anomaly-detector*", ".opendistro-anomaly-check>
Sep 21 16:58:09 ossec systemd-entrypoint[116185]: in 'reader', line 45, column 1:
Sep 21 16:58:09 ossec systemd-entrypoint[116185]: found unexpected end of stream
Sep 21 16:58:09 ossec systemd-entrypoint[116185]: ^
Sep 21 16:58:09 ossec systemd-entrypoint[116185]: ... .opendistro-anomaly-detector*", ".opendistro-anomaly-check>
Sep 21 16:58:09 ossec systemd-entrypoint[116185]: in 'reader', line 41, column 211:
Sep 21 16:58:09 ossec systemd-entrypoint[116185]: Caused by: while scanning a quoted scalar
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/3dc511b6-3277-4baa-a2aa-e369986eeff1n%40googlegroups.com.

To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/28ebe5db-5613-4f0b-84a9-5d97dc8323d8n%40googlegroups.com.
Exception in thread "main" org.opensearch.bootstrap.BootstrapException: java.nio.file.AccessDeniedException: /etc/wazuh-indexer/backup
# mkdir indexer-certs-sv
# mv /etc/wazuh-indexer/certs/* indexer-certs-sv/
# apt remove --purge wazuh-indexer
# rm -rf /var/lib/wazuh-indexer
# apt install wazuh-indexer
# mkdir /etc/wazuh-indexer/certs
# mv indexer-certs-sv/* /etc/wazuh-indexer/certs/
# chmod 500 /etc/wazuh-indexer/certs
# chmod 400 /etc/wazuh-indexer/certs/*
# chown -R wazuh-indexer:wazuh-indexer /etc/wazuh-indexer/certs
# systemctl start wazuh-indexer
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/34706697-b609-4d2f-b07b-5a525321606en%40googlegroups.com.

But a problem arose, I forgot my dashboard password and I had to generate new ones. But an error appeared in filebeat. How can I add a new password?
Using the instructions, I created new passwords
https://documentation.wazuh.com/current/user-manual/user-administration/password-management.html
curl -so wazuh-passwords-tool.sh https://packages.wazuh.com/4.5/wazuh-passwords-tool.sh
bash wazuh-passwords-tool.sh -a
We got it as an example
INFO: Wazuh API admin credentials not provided, Wazuh API passwords not changed.
INFO: The password for user admin is kwd139yG?YoIK?lRnqcXQ4R4gJDlAqKn
INFO: The password for user kibanaserver is Bu1WIELh9RdRlf*oGjinN1?yhF6XzA7V
INFO: The password for user kibanaro is 7kZvau11cPn6Y1SbOsdr8Kwr*BRiK3u+
INFO: The password for user logstash is SUbk4KTmLl*geQbUg0c5tyfwahjDMhx5
INFO: The password for user readall is ?w*Itj1Lgz.5w.C7vOw0Kxi7G94G8bG*
INFO: The password for user snapshotrestore is Z6UXgM8Sr0bfV.i*6yPPEUY3H6Du2rdz
WARNING: Wazuh indexer passwords changed. Remember to update the password in the Wazuh dashboard and Filebeat nodes if necessary, and restart the services.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/d6e219b7-9a92-411a-b799-6a5e57a9a1c0n%40googlegroups.com.