-
Notifications
You must be signed in to change notification settings - Fork 98
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump Wazuh indexer to OpenSearch 2.8.0 #2391
Comments
Update 30/08/2023
|
Update report
Missing RPM files
|
Testing on debian package
|
Local Testing on RPM package
|
Update ReportPackage building has been sucessful for RPM and Debian in Jenkins:
Testing on the |
Update report - Local test of RPM stackInstalled Indexer 🟢
Installed Manager 🟢
Installed Dashboard 🟢
Test app behavior 🔴
|
RPM indexer 🔴
[root@wazuh-manager vagrant]# yum install -y /home/vagrant/wazuh-indexer-4.6.0-wp.2392.2.x86_64.rpm
Failed to set locale, defaulting to C.UTF-8
Last metadata expiration check: 0:08:56 ago on Fri Sep 1 10:10:07 2023.
Dependencies resolved.
===================================================================================================================================================================================================================
Package Architecture Version Repository Size
===================================================================================================================================================================================================================
Installing:
wazuh-indexer x86_64 4.6.0-wp.2392.2 @commandline 673 M
Transaction Summary
===================================================================================================================================================================================================================
Install 1 Package
Total size: 673 M
Installed size: 930 M
Downloading Packages:
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
Preparing : 1/1
Running scriptlet: wazuh-indexer-4.6.0-wp.2392.2.x86_64 1/1
Installing : wazuh-indexer-4.6.0-wp.2392.2.x86_64 1/1
Running scriptlet: wazuh-indexer-4.6.0-wp.2392.2.x86_64 1/1
Created opensearch keystore in /etc/wazuh-indexer/opensearch.keystore
Verifying : wazuh-indexer-4.6.0-wp.2392.2.x86_64 1/1
Installed:
wazuh-indexer-4.6.0-wp.2392.2.x86_64
Complete!
[root@wazuh-manager vagrant]# nano /etc/wazuh-indexer/opensearch.yml
[root@wazuh-manager vagrant]# NODE_NAME=node-1
[root@wazuh-manager vagrant]# mkdir /etc/wazuh-indexer/certs
[root@wazuh-manager vagrant]# tar -xf ./wazuh-certificates.tar -C /etc/wazuh-indexer/certs/ ./$NODE_NAME.pem ./$NODE_NAME-key.pem ./admin.pem ./admin-key.pem ./root-ca.pem
[root@wazuh-manager vagrant]# mv -n /etc/wazuh-indexer/certs/$NODE_NAME.pem /etc/wazuh-indexer/certs/indexer.pem
[root@wazuh-manager vagrant]# mv -n /etc/wazuh-indexer/certs/$NODE_NAME-key.pem /etc/wazuh-indexer/certs/indexer-key.pem
[root@wazuh-manager vagrant]# chmod 500 /etc/wazuh-indexer/certs
[root@wazuh-manager vagrant]# chmod 400 /etc/wazuh-indexer/certs/*
[root@wazuh-manager vagrant]# chown -R wazuh-indexer:wazuh-indexer /etc/wazuh-indexer/certs
[root@wazuh-manager vagrant]# systemctl start wazuh-indexer
Job for wazuh-indexer.service failed because the control process exited with error code.
See "systemctl status wazuh-indexer.service" and "journalctl -xe" for details.
DEB indexer 🔴
root@ubuntu-focal:/home/vagrant# apt install -y /home/vagrant/wazuh-indexer_4.6.0-wp.2392_amd64.deb
Reading package lists... Done
Building dependency tree
Reading state information... Done
Note, selecting 'wazuh-indexer' instead of '/home/vagrant/wazuh-indexer_4.6.0-wp.2392_amd64.deb'
The following NEW packages will be installed:
wazuh-indexer
0 upgraded, 1 newly installed, 0 to remove and 0 not upgraded.
Need to get 0 B/685 MB of archives.
After this operation, 969 MB of additional disk space will be used.
Get:1 /home/vagrant/wazuh-indexer_4.6.0-wp.2392_amd64.deb wazuh-indexer amd64 4.6.0-wp.2392 [685 MB]
Selecting previously unselected package wazuh-indexer.
(Reading database ... 63489 files and directories currently installed.)
Preparing to unpack .../wazuh-indexer_4.6.0-wp.2392_amd64.deb ...
Creating wazuh-indexer group... OK
Creating wazuh-indexer user... OK
Unpacking wazuh-indexer (4.6.0-wp.2392) ...
Setting up wazuh-indexer (4.6.0-wp.2392) ...
Created opensearch keystore in /etc/wazuh-indexer/opensearch.keystore
Processing triggers for systemd (245.4-4ubuntu3.17) ...
Processing triggers for libc-bin (2.31-0ubuntu9.9) ...
root@ubuntu-focal:/home/vagrant# nano /etc/wazuh-indexer/opensearch.yml
root@ubuntu-focal:/home/vagrant# NODE_NAME=node-1
root@ubuntu-focal:/home/vagrant# mkdir /etc/wazuh-indexer/certs
root@ubuntu-focal:/home/vagrant# tar -xf ./wazuh-certificates.tar -C /etc/wazuh-indexer/certs/ ./$NODE_NAME.pem ./$NODE_NAME-key.pem ./admin.pem ./admin-key.pem ./root-ca.pem
root@ubuntu-focal:/home/vagrant# mv -n /etc/wazuh-indexer/certs/$NODE_NAME.pem /etc/wazuh-indexer/certs/indexer.pem
root@ubuntu-focal:/home/vagrant# mv -n /etc/wazuh-indexer/certs/$NODE_NAME-key.pem /etc/wazuh-indexer/certs/indexer-key.pem
root@ubuntu-focal:/home/vagrant# chmod 500 /etc/wazuh-indexer/certs
root@ubuntu-focal:/home/vagrant# chmod 400 /etc/wazuh-indexer/certs/*
root@ubuntu-focal:/home/vagrant# chown -R wazuh-indexer:wazuh-indexer /etc/wazuh-indexer/certs
root@ubuntu-focal:/home/vagrant# systemctl daemon-reload
root@ubuntu-focal:/home/vagrant# systemctl enable wazuh-indexer
Created symlink /etc/systemd/system/multi-user.target.wants/wazuh-indexer.service → /lib/systemd/system/wazuh-indexer.service.
root@ubuntu-focal:/home/vagrant# systemctl start wazuh-indexer
Job for wazuh-indexer.service failed because the control process exited with error code.
See "systemctl status wazuh-indexer.service" and "journalctl -xe" for details.
root@ubuntu-focal:/home/vagrant# ls -lah /usr/share/wazuh-indexer/bin/systemd-entrypoint
-rw-r----- 1 wazuh-indexer wazuh-indexer 583 Aug 31 18:54 /usr/share/wazuh-indexer/bin/systemd-entrypoint |
Update report - RPM
The error is probably related to an outdated base package, the file was installed correctly
|
Update report - DEB
|
Update reportManual testing of setting up the Wazuh Indexer shows that it is installed and starts correctly, but when connecting to a dashboard we can see the
|
Update reportTesting done on |
Update report
Password change output
Commands output
|
Update report
Testing done with step-by step installation.Testing done with
|
Description
It is necessary to adapt the Wazuh indexer to version 2.8.0 of OpenSearch
Request: https://github.com/wazuh/internal-devel-requests/issues/194
Tasks
wazuh-packages/stack/indexer/base/builder.sh
Line 19 in 55cfe35
Test the package (CentOS/Debian)InstallUpgradeRemoveLogsAlertsVersions referencesValidation
Working branch
The text was updated successfully, but these errors were encountered: