Closed davidjiglesias closed 6 months ago
The environment consists of 6 machines with the following characteristics.
[root@indexer1 ~]# rpm -qa | grep wazuh
wazuh-indexer-4.8.0-1.x86_64
[root@indexer1 ~]# rpm -qi wazuh-indexer-4.8.0-1.x86_64
Name : wazuh-indexer
Version : 4.8.0
Release : 1
Architecture: x86_64
Install Date: Mon 26 Feb 2024 18:25:39
Group : System Environment/Daemons
Size : 1055875422
License : GPL
Signature : RSA/SHA256, Sat 24 Feb 2024 21:01:41, Key ID 96b3ee5f29111145
Source RPM : wazuh-indexer-4.8.0-1.src.rpm
Build Date : Sat 24 Feb 2024 17:51:28
Build Host : ip-172-31-14-8.ec2.internal
Packager : Wazuh, Inc <info@wazuh.com>
Vendor : Wazuh, Inc <info@wazuh.com>
URL : https://www.wazuh.com/
Summary : Wazuh indexer is a search and analytics engine for security-related data. Documentation can be found at https://documentation.wazuh.com/current/getting-started/components/wazuh-indexer.html
Description :
Wazuh indexer is a near real-time full-text search and analytics engine that gathers security-related data into one platform. This Wazuh central component indexes and stores alerts generated by the Wazuh server. Wazuh indexer can be configured as a single-node or multi-node cluster, providing scalability and high availability. Documentation can be found at https://documentation.wazuh.com/current/getting-started/components/wazuh-indexer.html
[root@indexer1 ~]#
The service was correctly installed, enabled, and started.
[root@indexer1 ~]# curl -u admin:K.EaBal90w4AhYfCdU*h4abhjc8NPGJD -k https://172.20.10.4:9200/_cat/indices?v=true
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open wazuh-alerts-4.x-2024.02.26 0UQuJkZXToW9U5XoN-rqQQ 3 1 6 0 142kb 71kb
green open .opensearch-observability aqsI1GiBQvWMrzJ4-hZqxw 1 1 0 0 416b 208b
green open .plugins-ml-config CT4lilj3SFmUEjbCtjZLhw 1 1 1 0 7.8kb 3.9kb
green open wazuh-statistics-2024.9w QEwja17mRKeX4opl1_T5fA 1 0 170 0 246.7kb 246.7kb
green open wazuh-alerts-4.x-2024.02.27 zsNQU6qQTSmyVh-QzSi5gw 3 1 58 0 896.1kb 449.1kb
green open wazuh-monitoring-2024.9w PwqdScOyQm6-g0vVlKX4DQ 1 0 0 0 208b 208b
green open .kibana_1 FD8vVJbARFSNycH3STRfzQ 1 1 6 0 35.6kb 17.8kb
green open .opendistro_security 3SGjPzoER32M7_iRu366YA 1 1 10 0 130.4kb 65.2kb
[root@indexer1 ~]#
[root@indexer1 ~]# curl -u admin:K.EaBal90w4AhYfCdU*h4abhjc8NPGJD -k https://172.20.10.4:9200/_cat/templates?v=true
name index_patterns order version composed_of
wazuh-agent [wazuh-monitoring-*] 0
wazuh [wazuh-alerts-4.x-*, wazuh-archives-4.x-*] 0 1
wazuh-statistics [wazuh-statistics-*] 0
ss4o_metrics_template [ss4o_metrics-*-*] 1 1 []
ss4o_traces_template [ss4o_traces-*-*] 1 1 []
[root@indexer1 ~]#
[root@indexer1 ~]# curl -u admin:K.EaBal90w4AhYfCdU*h4abhjc8NPGJD -k https://172.20.10.4:9200/_cat/shards?v=true
index shard prirep state docs store ip node
wazuh-alerts-4.x-2024.02.26 0 r STARTED 3 32.5kb 172.20.10.4 node-1
wazuh-alerts-4.x-2024.02.26 0 p STARTED 3 32.4kb 172.20.10.5 node-2
wazuh-alerts-4.x-2024.02.26 1 r STARTED 2 18.4kb 172.20.10.4 node-1
wazuh-alerts-4.x-2024.02.26 1 p STARTED 2 18.4kb 172.20.10.5 node-2
wazuh-alerts-4.x-2024.02.26 2 r STARTED 1 20.1kb 172.20.10.4 node-1
wazuh-alerts-4.x-2024.02.26 2 p STARTED 1 20.1kb 172.20.10.5 node-2
.plugins-ml-config 0 p STARTED 1 3.9kb 172.20.10.4 node-1
.plugins-ml-config 0 r STARTED 1 3.9kb 172.20.10.5 node-2
.opensearch-observability 0 r STARTED 0 208b 172.20.10.4 node-1
.opensearch-observability 0 p STARTED 0 208b 172.20.10.5 node-2
wazuh-statistics-2024.9w 0 p STARTED 170 246.7kb 172.20.10.5 node-2
wazuh-alerts-4.x-2024.02.27 0 p STARTED 24 149kb 172.20.10.4 node-1
wazuh-alerts-4.x-2024.02.27 0 r STARTED 24 149kb 172.20.10.5 node-2
wazuh-alerts-4.x-2024.02.27 1 r STARTED 17 157.1kb 172.20.10.4 node-1
wazuh-alerts-4.x-2024.02.27 1 p STARTED 17 144.7kb 172.20.10.5 node-2
wazuh-alerts-4.x-2024.02.27 2 p STARTED 17 155.4kb 172.20.10.4 node-1
wazuh-alerts-4.x-2024.02.27 2 r STARTED 17 140.8kb 172.20.10.5 node-2
.opensearch-sap-log-types-config 0 p STARTED 172.20.10.4 node-1
.opensearch-sap-log-types-config 0 r STARTED 172.20.10.5 node-2
wazuh-monitoring-2024.9w 0 p STARTED 0 208b 172.20.10.4 node-1
.opendistro_security 0 r STARTED 10 65.2kb 172.20.10.4 node-1
.opendistro_security 0 p STARTED 10 65.2kb 172.20.10.5 node-2
.kibana_1 0 r STARTED 6 17.8kb 172.20.10.4 node-1
.kibana_1 0 p STARTED 6 17.8kb 172.20.10.5 node-2
[root@indexer1 ~]#
[root@indexer1 ~]# curl -u admin:K.EaBal90w4AhYfCdU*h4abhjc8NPGJD -k https://172.20.10.4:9200/_cluster/state/nodes?pretty
{
"cluster_name" : "wazuh-cluster",
"cluster_uuid" : "AAZXq9vYRvqCXD7WbxKuAA",
"nodes" : {
"WPYRTqdsRR2jlShkq9kamQ" : {
"name" : "node-1",
"ephemeral_id" : "PSPXkD-mQmKvBTp1RNrXcg",
"transport_address" : "172.20.10.4:9300",
"attributes" : {
"shard_indexing_pressure_enabled" : "true"
}
},
"h3IkE1MCTj6BkMDka1Gl4w" : {
"name" : "node-2",
"ephemeral_id" : "ygqcozeZQbaW6MFg4TRanA",
"transport_address" : "172.20.10.5:9300",
"attributes" : {
"shard_indexing_pressure_enabled" : "true"
}
}
}
}
[root@indexer1 ~]# curl -u admin:K.EaBal90w4AhYfCdU*h4abhjc8NPGJD -k https://172.20.10.4:9200/_cluster/health?pretty
{
"cluster_name" : "wazuh-cluster",
"status" : "green",
"timed_out" : false,
"number_of_nodes" : 2,
"number_of_data_nodes" : 2,
"discovered_master" : true,
"discovered_cluster_manager" : true,
"active_primary_shards" : 13,
"active_shards" : 24,
"relocating_shards" : 0,
"initializing_shards" : 0,
"unassigned_shards" : 0,
"delayed_unassigned_shards" : 0,
"number_of_pending_tasks" : 0,
"number_of_in_flight_fetch" : 0,
"task_max_waiting_in_queue_millis" : 0,
"active_shards_percent_as_number" : 100.0
}
An agent was installed and connected. No issues encountered.
Followed the next guide: https://documentation.wazuh.com/current/user-manual/uninstall/central-components.html#uninstall-the-wazuh-indexer
[root@indexer1 ~]#yum remove wazuh-indexer -y
rm -rf /var/lib/wazuh-indexer/
rm -rf /usr/share/wazuh-indexer/
rm -rf /etc/wazuh-indexer/
Dependencies resolved.
==============================================================================================================================================================
Package Architecture Version Repository Size
==============================================================================================================================================================
Removing:
wazuh-indexer x86_64 4.8.0-1 @wazuh 1.0 G
Transaction Summary
==============================================================================================================================================================
Remove 1 Package
Freed space: 1.0 G
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
Preparing : 1/1
Running scriptlet: wazuh-indexer-4.8.0-1.x86_64 1/1
Stopping wazuh-indexer service... OK
Erasing : wazuh-indexer-4.8.0-1.x86_64 1/1
warning: /etc/wazuh-indexer/opensearch.yml saved as /etc/wazuh-indexer/opensearch.yml.rpmsave
warning: /etc/wazuh-indexer/opensearch-security/internal_users.yml saved as /etc/wazuh-indexer/opensearch-security/internal_users.yml.rpmsave
Running scriptlet: wazuh-indexer-4.8.0-1.x86_64 1/1
Verifying : wazuh-indexer-4.8.0-1.x86_64 1/1
Removed:
wazuh-indexer-4.8.0-1.x86_64
Complete!
[root@indexer1 ~]#systemctl status wazuh-indexer
systemctl cat wazuh-indexer.service
yum list installed | grep wazuh-indexer
Unit wazuh-indexer.service could not be found.
No files found for wazuh-indexer.service.
[root@indexer1 ~]#
[root@indexer2 ~]#yum remove wazuh-indexer -y
rm -rf /var/lib/wazuh-indexer/
rm -rf /usr/share/wazuh-indexer/
rm -rf /etc/wazuh-indexer/
Dependencies resolved.
==============================================================================================================================================================
Package Architecture Version Repository Size
==============================================================================================================================================================
Removing:
wazuh-indexer x86_64 4.8.0-1 @wazuh 1.0 G
Transaction Summary
==============================================================================================================================================================
Remove 1 Package
Freed space: 1.0 G
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
Preparing : 1/1
Running scriptlet: wazuh-indexer-4.8.0-1.x86_64 1/1
Stopping wazuh-indexer service... OK
Erasing : wazuh-indexer-4.8.0-1.x86_64 1/1
warning: /etc/wazuh-indexer/opensearch.yml saved as /etc/wazuh-indexer/opensearch.yml.rpmsave
Running scriptlet: wazuh-indexer-4.8.0-1.x86_64 1/1
Verifying : wazuh-indexer-4.8.0-1.x86_64 1/1
Removed:
wazuh-indexer-4.8.0-1.x86_64
Complete!
[root@indexer2 ~]#
[root@indexer2 ~]#systemctl status wazuh-indexer
systemctl cat wazuh-indexer.service
yum list installed | grep wazuh-indexer
Unit wazuh-indexer.service could not be found.
No files found for wazuh-indexer.service.
[root@indexer2 ~]#
@thecotilking what about these logs?
Feb 27 12:54:18 indexer1 systemd-entrypoint[1012]: ERROR StatusConsoleListener Unable to locate appender "task_detailslog_rolling_old" for logger config "tas>
Feb 27 12:54:18 indexer1 systemd-entrypoint[1012]: ERROR StatusConsoleListener Unable to locate appender "deprecation_rolling_old" for logger config "org.ope>
Feb 27 12:54:18 indexer1 systemd-entrypoint[1012]: ERROR StatusConsoleListener Unable to locate appender "deprecation_rolling" for logger config "org.opensea>
Feb 27 12:54:18 indexer1 systemd-entrypoint[1012]: ERROR StatusConsoleListener Unable to locate appender "index_search_slowlog_rolling_old" for logger config>
Feb 27 12:54:18 indexer1 systemd-entrypoint[1012]: ERROR StatusConsoleListener Unable to locate appender "index_search_slowlog_rolling" for logger config "in>
LGTM!
End-to-End (E2E) Testing Guideline
Release testing
objective andVery high
priority. Communicate these to the team and QA via the c-release Slack channel.For the conclusions and the issue testing and updates, use the following legend:
Status legend
Issue delivery and completion
review_assignee
field in the project. The reviewer must then review the test steps and results. Ensure that all iteration cycles are completed by Feb 28, 2024 date (issue must be inPending final review
status) and notify the QA team via Slack using the c-release channel.Deployment requirements
Test description
Best effort to test the Wazuh indexer package. Think critically and at least review/test:
Known issues
Conclusions
Summarize the errors detected (Known Issues included). Illustrate using the table below. REMOVE CURRENT EXAMPLES:
System::setSecurityManager
, also appeared in the previous test,Feedback
We value your feedback. Please provide insights on your testing experience.
Reviewers validation
The criteria for completing this task is based on the validation of the conclusions and the test results by all reviewers.
All the checkboxes below must be marked in order to close this issue.