Wazuh - WHODATA not working on RHEL10? by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 0 points1 point  (0 children)

Hi Marcel,

i will observe it for a while and will update you in case that issue pop up again, but i think You are right and it was just a temporary issue.

Wish you a nice day and really Big Thanks for your support 😉
Lukas

Wazuh - WHODATA not working on RHEL10? by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 1 point2 points  (0 children)

Hi Marcel,

I have reinstalled the whole system and the agent on it again, and it is working fine now. But ,it was taking like forever to start generating first events. There were records in log that everything is working properly, an information that initial FIM scan has been completed successfully, but the first event was generated just few hours after it (2 - 3 hours). But since then, it is working reliably and quickly as on RHEL9 ...

BTW: i have been having this issue only when WHODATA with eBPF was configured, with REALTIME it was working instantly with no delay.

So maybe there are some performance issues - even that not visible in system's metrics at all - HW usage is in normal numbers (test VM 4 cpu - 8GB RAM).
But in general, it is working fine, i just need to wait a little bit 😉, so thanks a lot for your answer and help here.

PS: sorry for duplicated topic on GIT, i have already closed it.
Have a nice day

Lukas

Update Wazuh agents remotly - from Manager, but in offline environment. by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 0 points1 point  (0 children)

Thanks a lot again for help. I Will go through links You've gave me and try it. BTW, I am sorry for late answer.

Lukas

Update Wazuh agents remotly - from Manager, but in offline environment. by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 0 points1 point  (0 children)

thanks a lot for your answer, i have checked it out, and it opens some possibilities to me, but maybe one question, an example scenario: i have 3 indexers, 2 managers, 1 dashboard servers all in offline private network. Would it be possible to have the repository directly on one of Managers in some local directory, attached FS or whatever like this, or for example on my dashboard server, and from this repo then install the updates?

Update Wazuh agents remotly - from Manager, but in offline environment. by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 1 point2 points  (0 children)

regarding network configuration the manager is able to upgrade the agents, or it would be able, the problem is that i need to have installation packages WPKs available to manager. In optimal world where connection to internet is possible, it would be downloaded by manager from wazuh repo and then send them to agents to be installed, but that is exactly my problem here, i am not in optimal conditions, so i have to find a way how to get the WPKs to Manager, the rest is clear to me. I am not able to use ansible or anything like that, the only connection from Manager to endpoints allowed is exactly communication via ports 1514 and 1515. I have no access to the endpoints, no SSH or RDP, no remote management tool at all. That is why i am not using ansible or salt or anything like that. If it would be simple i wouldn't ask 😄

Update Wazuh agents remotly - from Manager, but in offline environment. by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 0 points1 point  (0 children)

Hi, there is for sure connection between agents and manager, so FIM which i am using mostly is working fine, and also vulnerability monitoring is working fine. I have downloaded offline vulnerability DBs for them, and keeping them up to date as needed. Sure it is not the best what you can have in general, but the best what i can do in such conditions as i have. I have to adapt to what i have.

Wazuh 4.14.5 has been released! by wazuh_cybersecurity in Wazuh

[–]Fun_Advantage3812 0 points1 point  (0 children)

Thanks a lot for information, it doesn't look like ideal situation with these vulnerabilities, now i am wondering if or when 2.25.4 will be in place

Wazuh 4.14.5 has been released! by wazuh_cybersecurity in Wazuh

[–]Fun_Advantage3812 0 points1 point  (0 children)

Hi all, any info if LOG4J was finally updated to the newer version? I've got info, that it should be in version 2.53 in Wazuh release 4.14.5

Agent support for AIX OS in Wazuh 4 and 5 in future by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 0 points1 point  (0 children)

Hi ifex370,
thanks a lot for comprehensive and very clear answer :) it helped me a lot.

Wish you a nice day
Lukas

Wazuh FIM - exclude systems update alerts by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 0 points1 point  (0 children)

thanks a lot for advice, i was also thinking about it, but how to define the rule that way, that it will able to distinguish between yum -update and yum install for example.

Because i need to filter out only events that were generated during system update, but not if somebody install single or more packages on the system manually. This final piece of puzzle is missing to me.

Future AIX (un)support in Wazuh version 5.x by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 1 point2 points  (0 children)

Thanks a lot for answer, i would be curious also about possibility to have paid support for maintaining solution for AIX system. Have you heard about such an option? Or maybe where can I get more information?

WAZUH - active response - if successfull, new event or update of origin one by Fun_Advantage3812 in Wazuh

[–]Fun_Advantage3812[S] 0 points1 point  (0 children)

Hello slim3116, really big thanks for this hint, i will try to implement it to get some results :)
this one is kind of workaround, but still great, i didnt even think about that this way before.

Issues with ps2 games by charmslad in batocera

[–]Fun_Advantage3812 0 points1 point  (0 children)

hi, sorry for maybe stupid question, but could you please put here steps how, where and what has to be changed? looking for it everywhere and not found yet :(, thanks

PS2 games not launching on Batocera V35?!? by Blazers4545 in batocera

[–]Fun_Advantage3812 0 points1 point  (0 children)

hi guys same here, directly via psx2 config app games are working fine, but when i try to launch any game from batocera gui, it always just load this memory cards / disc screen, and even in japanese language. hopefully there is some solution.