Wazuh Install - Worlds Best OpenSource EDR!

preview_player
Показать описание
Join me as we continue on to Phase 3 of the World's Best SIEM Stack Series, installing the Wazuh Manager.

Рекомендации по теме
Комментарии
Автор

One question. Finally, is this entire series about EDR or SIEM?

ArmAikido
Автор

Super informative and practical series. But can you please uncover one topic about efficient way of transferring sysmon for linux events from endpoints to backend systems. Because they are stored in XML format and it's not so obvious which forwarders and options should be used.

DM-gppd
Автор

I wish wazuh had iso 27001 compliance dashboard.

photondoh
Автор

In case if someone has the issue with error "Elasticsearch exception [type=illegal_argument_exception, reason=key [types] is not supported in the metadata section]." when try to see received messages (16:27), you needed to remove this from the Opensearch config file: true (or just comment) and restart wazuh-dashboard and graylog-server

VahanTorosyan-fn
Автор

you're the boss!! 👏☝️😉 regards from Argentina 👋😁

alejandroparrello
Автор

Great content. Helped me alot. which tool you are using for ssh? it looks cool.

MrSuhailmt
Автор

Hi, thanks a lot for your great content. It´s possible to help me with follow issue: [Alerts index pattern] No template found for the selected index-pattern title [wazuh-alerts-*]

krosstty
Автор

I don't understand why Graylog is in the picture. You're already using Fluent Bit, which can already do all the filtering and renaming and much more. It can even integrate with GeoLite2 IP geolocation. I decided not to install Graylog.

pragmatickaos
Автор

i am deploy wazuh manager graylog successfully i can see data in grafana but i cant see wazuh dashboard security event and and other alert from from wazuh .is there any way to see both dashboard wazuh and grafana?

nopromises
Автор

Hi Bro,
I followed all your steps . regarding wazuh * and graylog. now i am unable to assign a group to wazuh agent . Please guid me

amruth
Автор

While retrieving data for this widget, the following error(s) occurred:
Elasticsearch exception [type=illegal_argument_exception, reason=key [types] is not supported in the metadata section]. Why I'm having this error ?

surathwalpita
Автор

Could I do this install on Ubuntu Server or Ubuntu Desktop? I would like to do this using a VM does that require Docker?

gregg
Автор

fluent-bit is impossible to install on Kali linux

simoner
Автор

You pronounce it wrong.
Huh
Duh
Wazuh

iamreiver