OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • 24.1 Legacy Series »
  • Wazuh active response dosn't work
« previous next »
  • Print
Pages: [1]

Author Topic: Wazuh active response dosn't work  (Read 1701 times)

_tribal_

  • Newbie
  • *
  • Posts: 33
  • Karma: 1
    • View Profile
Wazuh active response dosn't work
« on: March 04, 2024, 12:34:55 am »
Trying to configure wazuh active response... events to the server wazuh sends...and triggered, but the plugin on the router gives an error :o:
Code: [Select]
wazuh-execd[8576] execd.c 271 at ExecdRun(): DEBUG: Active response won't be added to timeout list. Message not received with alert keys from script 'active-response/bin/opnsense-fw'
and  in SERVICES: WAZUH AGENT: LOGFILE / OSSEC:
Code: [Select]
wazuh-logcollector[70753] logcollector.c 1101 at handle_file(): DEBUG: (1963): Unable to open file '/var/ossec/logs/active-responses.log'.
wazuh server settings:
Code: [Select]
  <command>
    <name>opnsense-fw</name>
    <executable>opnsense-fw</executable>
    <timeout_allowed>yes</timeout_allowed>
  </command>

  <active-response>
    <disabled>no</disabled>
    <command>opnsense-fw</command>
    <location>all</location>
    <rules_group>attack</rules_group>
    <timeout>180</timeout>
  </active-response>

opnsense wazuh plugin settings:
Code: [Select]
  <!-- Active response -->
  <active-response>
    <disabled>no</disabled>
    <repeated_offenders>180,1800,3600,14400,28800</repeated_offenders>
  </active-response>

I have tried different variants with the exact agent index and without repeated blocking, the error is still present.

Who has this plugin working, can you tell me what I'm doing wrong? :'(

os-wazuh-agent 1.0_1
OPNsense 24.1.2_1-amd64 OPNsense 24.1.4-amd64
FreeBSD 13.2-RELEASE-p10
OpenSSL 3.0.13

UPD. maybe it's related with health check finds 2 errors in wazuh agent plugin:
Code: [Select]
wazuh-agent is missing a required shared library: libthr.so.3
wazuh-agent is missing a required shared library: libc.so.7
« Last Edit: March 21, 2024, 09:47:53 pm by _tribal_ »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Wazuh active response dosn't work
« Reply #1 on: March 21, 2024, 10:21:31 pm »
Active response is on the Manager, not the agent, correct?
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

_tribal_

  • Newbie
  • *
  • Posts: 33
  • Karma: 1
    • View Profile
Re: Wazuh active response dosn't work
« Reply #2 on: March 22, 2024, 12:12:39 am »
I didn't quite understand the question.
Active response hould be configured in both agent and manager. I took the settings for agent (opnsense plugin) and manager (separate server) from OPNsense documentation, with a small modification from Wazuh documentation (added intervals of address repeat blocking). But when the rule is triggered in the manager, the address that should be added to the alias for blocking is not forwarded to the agent, instead I get an error message, which I showed in my post.
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Wazuh active response dosn't work
« Reply #3 on: March 22, 2024, 08:20:49 am »
Active response doesnt need an agent. The manager can execute the script and send the api call to OPNsense :)
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

_tribal_

  • Newbie
  • *
  • Posts: 33
  • Karma: 1
    • View Profile
Re: Wazuh active response dosn't work
« Reply #4 on: March 22, 2024, 11:21:22 am »
Okay, then why am I seeing this error in the wazuh agent log?
Code: [Select]
wazuh-execd[8576] execd.c 271 at ExecdRun(): DEBUG: Active response won't be added to timeout list. Message not received with alert keys from script 'active-response/bin/opnsense-fw'
And ip address does not appear in FIREWALL: ALIASES: __wazuh_agent_drop  ::)

That's what I wrote about in the original post.
« Last Edit: March 22, 2024, 11:23:37 am by _tribal_ »
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • 24.1 Legacy Series »
  • Wazuh active response dosn't work
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2