TCR

How to Configure File Integrity Monitoring with Wazuh: A Step-by-Step Guide

December 13, 2024 | by JSK

fim

Step 1: Access the Wazuh Dashboard

Step 2: Modify the ossec.conf File on the Client Machine

Copy Commands
sudo su
Copy Commands
cp /var/ossec/etc/ossec.conf /var/ossec/etc/ossec.backup.conf
Copy Commands
nano /var/ossec/etc/ossec.conf
Copy Commands
<directories realtime="yes">/home/client/test</directories>
Command Blocks
<!-- File integrity monitoring -->
<syscheck>
<disabled>no</disabled>
<!-- Frequency that syscheck is executed, default every 12 hours -->
<frequency>43200</frequency>
<scan_on_start>yes</scan_on_start>
<!-- Directories to check (perform all possible verifications) -->
<directories>/etc,/usr/bin,/usr/sbin</directories>
<directories>/bin,/sbin,/boot</directories>
<directories realtime="yes">/home/client/test</directories>
</syscheck>
Copy Commands
systemctl restart wazuh-agent
Copy Commands
exit
Copy Commands
mkdir test
Copy Commands
touch test/sample.txt
Copy Commands
echo "Test file for FIM" >> test/sample.txt

VirusTotal Integration

Copy Commands
sudo nano /var/ossec/etc/ossec.conf
Command Blocks
<integration>
 <name>virustotal</name>
 <api_key><VIRUSTOTAL_API_KEY></api_key>
 <group>syscheck</group>
 <alert_format>json</alert_format>
</integration>
Copy Commands
systemctl restart wazuh-manager

Reference Links:

RELATED POSTS

View all

view all