Need help to restore wazuh default conf file

106 views
Skip to first unread message

Monir AFG

unread,
Dec 4, 2024, 8:33:11 AM12/4/24
to Wazuh | Mailing List
Hi everyone,

I added several codes to the Wazuh manager's conf file, but I can't remember which ones. Now, my Wazuh manager isn't running. I had 12 agents, and everything was working perfectly before this change. 
Can anyone please help me restore the conf file to its default version, or let me know which parts I should remove to revert it to default?
here is how the conf file now:

<ossec_config>
    <global>
        <email_notification>yes</email_notification>
        <smtp_server>your_smtp_server</smtp_server>
        <email_from>wa...@example.com</email_from>
        <email_to>reci...@example.com</email_to>
        <email_maxperhour>12</email_maxperhour>
    </global>
    <alerts>
        <email_alert_level>10</email_alert_level>
    </alerts>
    <jsonout_output>yes</jsonout_output>
    <alerts_log>yes</alerts_log>
    <logall>no</logall>
    <logall_json>no</logall_json>
    <email_notification>no</email_notification>
    <smtp_server>smtp.example.wazuh.com</smtp_server>
    <email_from>wa...@example.wazuh.com</email_from>
    <email_to>reci...@example.wazuh.com</email_to>
    <email_maxperhour>12</email_maxperhour>
    <email_log_source>alerts.log</email_log_source>
    <agents_disconnection_time>10m</agents_disconnection_time>
    <agents_disconnection_alert_time>0</agents_disconnection_alert_time>
    <update_check>yes</update_check>
</global>

<alerts>
    <log_alert_level>3</log_alert_level>
    <email_alert_level>12</email_alert_level>
</alerts>

<logging>
    <log_format>plain</log_format>
</logging>

<remote>
    <connection>secure</connection>
    <port>1514</port>
    <protocol>tcp</protocol>
    <queue_size>131072</queue_size>
</remote>

<rootcheck>
    <disabled>no</disabled>
    <check_files>yes</check_files>
    <check_trojans>yes</check_trojans>
    <check_dev>yes</check_dev>
    <check_sys>yes</check_sys>
    <check_pids>yes</check_pids>
    <check_ports>yes</check_ports>
    <check_if>yes</check_if>

    <frequency>43200</frequency>

    <rootkit_files>etc/rootcheck/rootkit_files.txt</rootkit_files>
    <rootkit_trojans>etc/rootcheck/rootkit_trojans.txt</rootkit_trojans>

    <skip_nfs>yes</skip_nfs>

    <ignore>/var/lib/containerd</ignore>
    <ignore>/var/lib/docker/overlay2</ignore>
</rootcheck>

<wodle name="cis-cat">
    <disabled>yes</disabled>
    <timeout>1800</timeout>
    <interval>1d</interval>
    <scan_on_start>yes</scan_on_start>

    <java_path>wodles/java</java_path>
    <ciscat_path>wodles/ciscat</ciscat_path>
</wodle>

<wodle name="osquery">
    <disabled>yes</disabled>
    <run_daemon>yes</run_daemon>
    <log_path>/var/log/osquery/osqueryd.results.log</log_path>
    <config_path>/etc/osquery/osquery.conf</config_path>
    <add_labels>yes</add_labels>
</wodle>

<wodle name="syscollector">
    <disabled>no</disabled>
    <interval>1h</interval>
    <scan_on_start>yes</scan_on_start>
    <hardware>yes</hardware>
    <os>yes</os>
    <network>yes</network>
    <packages>yes</packages>
    <ports all="no">yes</ports>
    <processes>yes</processes>

    <synchronization>
        <max_eps>10</max_eps>
    </synchronization>
</wodle>

<sca>
    <enabled>yes</enabled>
    <scan_on_start>yes</scan_on_start>
    <interval>12h</interval>
    <skip_nfs>yes</skip_nfs>
</sca>

<vulnerability-detection>
    <enabled>yes</enabled>
    <index-status>yes</index-status>
    <feed-update-interval>60m</feed-update-interval>
</vulnerability-detection>

<indexer>
    <enabled>yes</enabled>
    <hosts>
        <host>https://127.0.0.1:9200</host>
    </hosts>
    <ssl>
        <certificate_authorities>
            <ca>/etc/filebeat/certs/root-ca.pem</ca>
        </certificate_authorities>
        <certificate>/etc/filebeat/certs/wazuh-server.pem</certificate>
        <key>/etc/filebeat/certs/wazuh-server-key.pem</key>
    </ssl>
</indexer>

<syscheck>
    <disabled>no</disabled>

    <frequency>43200</frequency>

    <scan_on_start>yes</scan_on_start>

    <alert_new_files>yes</alert_new_files>

    <auto_ignore frequency="10" timeframe="3600">no</auto_ignore>

    <directories>/etc,/usr/bin,/usr/sbin</directories>
    <directories>/bin,/sbin,/boot</directories>

    <ignore>/etc/mtab</ignore>
    <ignore>/etc/hosts.deny</ignore>
    <ignore>/etc/mail/statistics</ignore>
    <ignore>/etc/random-seed</ignore>
    <ignore>/etc/random.seed</ignore>
    <ignore>/etc/adjtime</ignore>
    <ignore>/etc/httpd/logs</ignore>
    <ignore>/etc/utmpx</ignore>
    <ignore>/etc/wtmpx</ignore>
    <ignore>/etc/cups/certs</ignore>
    <ignore>/etc/dumpdates</ignore>
    <ignore>/etc/svc/volatile</ignore>

    <ignore type="sregex">.log$|.swp$</ignore>

    <nodiff>/etc/ssl/private.key</nodiff>

    <skip_nfs>yes</skip_nfs>
    <skip_dev>yes</skip_dev>
    <skip_proc>yes</skip_proc>
    <skip_sys>yes</skip_sys>

    <process_priority>10</process_priority>

    <max_eps>50</max_eps>

    <synchronization>
        <enabled>yes</enabled>
        <interval>5m</interval>
        <max_eps>10</max_eps>
    </synchronization>
</syscheck>
<global>
    <white_list>127.0.0.1</white_list>
    <white_list>^localhost.localdomain$</white_list>
    <white_list>127.0.0.53</white_list>
</global>

<command>
    <name>disable-account</name>
    <executable>disable-account</executable>
    <timeout_allowed>yes</timeout_allowed>
</command>

<command>
    <name>restart-wazuh</name>
    <executable>restart
Capture.PNG

Md. Nazmur Sakib

unread,
Dec 5, 2024, 5:00:22 AM12/5/24
to Wazuh | Mailing List

Hi Monir,

To share the configuration I need to know the manager OS and OS version and the version of your Wazuh Manager.


Some parts of the configuration are missing. If you can send me the full configuration file I will be able to validate the configuration. You can copy the configuration from

/var/ossec/etc/ossce.conf to a text file and send it to me.

Also, share the logs from the manager

cat /var/ossec/logs/ossec.log | grep -iE "error|warn"


Looking forward to your update on the issue.
Reply all
Reply to author
Forward
0 new messages