2018-01-24 14:28:02 +00:00
|
|
|
---
|
2018-04-23 17:15:38 +00:00
|
|
|
#
|
|
|
|
# Wazuh app - App configuration file
|
2019-01-14 16:36:47 +00:00
|
|
|
# Copyright (C) 2015-2019 Wazuh, Inc.
|
2018-04-23 17:15:38 +00:00
|
|
|
#
|
|
|
|
# This program is free software; you can redistribute it and/or modify
|
|
|
|
# it under the terms of the GNU General Public License as published by
|
|
|
|
# the Free Software Foundation; either version 2 of the License, or
|
|
|
|
# (at your option) any later version.
|
|
|
|
#
|
|
|
|
# Find more information about this on the LICENSE file.
|
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# ======================== Wazuh app configuration file ========================
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# Please check the documentation for more information on configuration options:
|
|
|
|
# https://documentation.wazuh.com/current/installation-guide/index.html
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# Also, you can check our repository:
|
|
|
|
# https://github.com/wazuh/wazuh-kibana-app
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# ------------------------------- Index patterns -------------------------------
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-01-24 14:28:02 +00:00
|
|
|
# Default index pattern to use.
|
2018-05-07 11:30:55 +00:00
|
|
|
#pattern: wazuh-alerts-3.x-*
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# ----------------------------------- Checks -----------------------------------
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# Defines which checks must to be consider by the healthcheck
|
|
|
|
# step once the Wazuh app starts. Values must to be true or false.
|
2018-05-07 11:30:55 +00:00
|
|
|
#checks.pattern : true
|
|
|
|
#checks.template: true
|
|
|
|
#checks.api : true
|
|
|
|
#checks.setup : true
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-10-01 07:05:15 +00:00
|
|
|
# --------------------------------- Extensions ---------------------------------
|
|
|
|
#
|
|
|
|
# Defines which extensions should be activated when you add a new API entry.
|
|
|
|
# You can change them after Wazuh app starts.
|
|
|
|
# Values must to be true or false.
|
|
|
|
#extensions.pci : true
|
|
|
|
#extensions.gdpr : true
|
2019-08-07 08:31:59 +00:00
|
|
|
#extensions.hipaa : true
|
|
|
|
#extensions.nist : true
|
2018-10-01 07:05:15 +00:00
|
|
|
#extensions.audit : true
|
2019-03-21 17:21:29 +00:00
|
|
|
#extensions.oscap : false
|
2018-10-01 07:05:15 +00:00
|
|
|
#extensions.ciscat : false
|
|
|
|
#extensions.aws : false
|
|
|
|
#extensions.virustotal: false
|
2018-10-03 09:43:16 +00:00
|
|
|
#extensions.osquery : false
|
2019-04-12 10:49:31 +00:00
|
|
|
#extensions.docker : false
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# ---------------------------------- Time out ----------------------------------
|
2018-01-30 10:42:48 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# Defines maximum timeout to be used on the Wazuh app requests.
|
2018-05-10 18:01:20 +00:00
|
|
|
# It will be ignored if it is bellow 1500.
|
2018-01-30 10:42:48 +00:00
|
|
|
# It means milliseconds before we consider a request as failed.
|
2019-04-10 13:07:56 +00:00
|
|
|
# Default: 20000
|
|
|
|
#timeout: 20000
|
2018-02-27 12:16:56 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# ------------------------------ Advanced indices ------------------------------
|
2018-02-27 12:16:56 +00:00
|
|
|
#
|
2019-08-07 08:31:59 +00:00
|
|
|
# Configure .wazuh indices shards and replicas.
|
2018-05-07 11:30:55 +00:00
|
|
|
#wazuh.shards : 1
|
2018-12-26 14:13:25 +00:00
|
|
|
#wazuh.replicas : 0
|
2018-03-13 14:16:06 +00:00
|
|
|
#
|
2018-04-22 18:52:55 +00:00
|
|
|
# --------------------------- Index pattern selector ---------------------------
|
2018-03-13 14:16:06 +00:00
|
|
|
#
|
2018-05-10 18:01:20 +00:00
|
|
|
# Defines if the user is allowed to change the selected
|
|
|
|
# index pattern directly from the Wazuh app top menu.
|
2018-06-19 13:35:16 +00:00
|
|
|
# Default: true
|
2018-05-07 11:30:55 +00:00
|
|
|
#ip.selector: true
|
2018-04-26 08:25:05 +00:00
|
|
|
#
|
2018-10-05 13:10:59 +00:00
|
|
|
# List of index patterns to be ignored
|
|
|
|
#ip.ignore: []
|
|
|
|
#
|
2018-05-10 18:01:20 +00:00
|
|
|
# -------------------------------- X-Pack RBAC ---------------------------------
|
2018-04-26 08:25:05 +00:00
|
|
|
#
|
2018-05-10 18:01:20 +00:00
|
|
|
# Custom setting to enable/disable built-in X-Pack RBAC security capabilities.
|
2018-04-26 08:25:05 +00:00
|
|
|
# Default: enabled
|
2018-05-07 11:30:55 +00:00
|
|
|
#xpack.rbac.enabled: true
|
|
|
|
#
|
2018-05-10 18:01:20 +00:00
|
|
|
# ------------------------------ wazuh-monitoring ------------------------------
|
|
|
|
#
|
2018-05-07 11:30:55 +00:00
|
|
|
# Custom setting to enable/disable wazuh-monitoring indices.
|
2018-05-21 08:16:07 +00:00
|
|
|
# Values: true, false, worker
|
2018-06-19 13:35:16 +00:00
|
|
|
# If worker is given as value, the app will show the Agents status
|
|
|
|
# visualization but won't insert data on wazuh-monitoring indices.
|
2018-05-21 08:16:07 +00:00
|
|
|
# Default: true
|
2018-05-07 15:07:19 +00:00
|
|
|
#wazuh.monitoring.enabled: true
|
2018-05-07 11:30:55 +00:00
|
|
|
#
|
|
|
|
# Custom setting to set the frequency for wazuh-monitoring indices cron task.
|
2019-03-21 15:19:25 +00:00
|
|
|
# Default: 900 (s)
|
|
|
|
#wazuh.monitoring.frequency: 900
|
2018-05-10 18:01:20 +00:00
|
|
|
#
|
2018-08-23 08:40:01 +00:00
|
|
|
# Configure wazuh-monitoring-3.x-* indices shards and replicas.
|
2018-12-26 14:13:25 +00:00
|
|
|
#wazuh.monitoring.shards: 2
|
|
|
|
#wazuh.monitoring.replicas: 0
|
2018-10-30 11:23:45 +00:00
|
|
|
#
|
2019-02-14 08:47:02 +00:00
|
|
|
# Configure wazuh-monitoring-3.x-* indices custom creation interval.
|
|
|
|
# Values: h (hourly), d (daily), w (weekly), m (monthly)
|
2019-02-14 08:51:16 +00:00
|
|
|
# Default: d
|
2019-02-14 08:47:02 +00:00
|
|
|
#wazuh.monitoring.creation: d
|
|
|
|
#
|
2018-12-17 09:52:57 +00:00
|
|
|
# Default index pattern to use for Wazuh monitoring
|
|
|
|
#wazuh.monitoring.pattern: wazuh-monitoring-3.x-*
|
|
|
|
#
|
|
|
|
#
|
2018-10-30 11:23:45 +00:00
|
|
|
# ------------------------------- App privileges --------------------------------
|
2019-04-12 10:49:31 +00:00
|
|
|
#admin: true
|
2019-04-15 10:47:45 +00:00
|
|
|
#
|
2019-10-09 10:13:14 +00:00
|
|
|
# ------------------------------- App logging level -----------------------------
|
2019-05-16 10:10:35 +00:00
|
|
|
# Set the logging level for the Wazuh App log files.
|
2019-04-15 10:47:45 +00:00
|
|
|
# Default value: info
|
|
|
|
# Allowed values: info, debug
|
2019-08-14 10:33:00 +00:00
|
|
|
#logs.level: info
|
2019-10-09 10:13:14 +00:00
|
|
|
#
|
|
|
|
#-------------------------------- API entries -----------------------------------
|
|
|
|
#The following configuration is the default structure to define an API entry.
|
|
|
|
#
|
|
|
|
#hosts:
|
|
|
|
# - <id>:
|
|
|
|
# url: http(s)://<url>
|
|
|
|
# port: <port>
|
|
|
|
# user: <user>
|
|
|
|
# password: <password>
|
|
|
|
|
|
|
|
hosts:
|
|
|
|
- default:
|
|
|
|
url: http://localhost
|
|
|
|
port: 55000
|
|
|
|
user: foo
|
|
|
|
password: bar
|