Difference between revisions of "Cyber Security: Ubuntu 26.04: Wazuh Agent Install"

From OnnoWiki
Jump to navigation Jump to search
(Created page with "Prompt: install wazuh agent untuk IP wazuh manager 192.168.0.5 nama device server-korban-192.168.0.100 CLI: sudo apt-get update sudo apt-get install -y gnupg apt-transpo...")
 
Line 1: Line 1:
 
Prompt:
 
Prompt:
  
  install wazuh agent untuk IP wazuh manager 192.168.0.5 nama device server-korban-192.168.0.100
+
  install wazuh agent untuk IP wazuh manager 192.168.0.105 nama device server-korban-192.168.0.100
  
 
CLI:
 
CLI:
Line 21: Line 21:
 
Install:
 
Install:
  
  sudo WAZUH_MANAGER="192.168.0.5" \
+
  sudo WAZUH_MANAGER="192.168.0.105" \
  WAZUH_AGENT_NAME="server-korban-192.168.0.100" \
+
  WAZUH_AGENT_NAME="server-wazuh" \
 
  apt-get install -y wazuh-agent
 
  apt-get install -y wazuh-agent
  

Revision as of 03:33, 23 June 2026

Prompt:

install wazuh agent untuk IP wazuh manager 192.168.0.105 nama device server-korban-192.168.0.100

CLI:

sudo apt-get update
sudo apt-get install -y gnupg apt-transport-https curl
curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | \
sudo gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import

sudo chmod 644 /usr/share/keyrings/wazuh.gpg


echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | \
sudo tee /etc/apt/sources.list.d/wazuh.list

sudo apt-get update

Install:

sudo WAZUH_MANAGER="192.168.0.105" \
WAZUH_AGENT_NAME="server-wazuh" \
apt-get install -y wazuh-agent


Load & Cek:

sudo systemctl daemon-reload
sudo systemctl enable wazuh-agent
sudo systemctl start wazuh-agent
sudo systemctl status wazuh-agent


Cek Config

sudo grep -A5 -B2 "192.168.0.5" /var/ossec/etc/ossec.conf
nc -zv 192.168.0.5 1514 1515

Di Wazuh Server

sudo /var/ossec/bin/agent_control -l

Atau lewat dashboard:

Wazuh Dashboard → Agents management → Summary