netzen I'm starting to process first data from @cPFence in Wazuh. Are you interested in any specific data? Since I'm also new to cPFence, I currently have ModSecurity logs in Wazuh, and I'm thinking about what else might be useful. Thanks for your help

Here are some useful logs you can process in Wazuh:

  • Detected Viruses:
    /var/log/cpfenceav/infections.history

  • Killed Queries:
    /var/log/cpfenceav/killed_queries.history

  • IPDB Logs:

    sudo tail -f /var/log/syslog | grep -E 'cPFence Blocked:|cPFence DDos Protection:'
  • Owl Logs:
    sudo tail -f /opt/cpfence/app/owl/tmp/logs/main_log

    You’ve done a great job so far. Good luck!.

    @netzen This is great. I tried Wazuh over the weekend too and your inputs are motivating! I will try setting up and see how it works for my use case! I will also post my learnings. I am able to work on Wazuh only on the weekends though thanks to the workload 🙂

    cPFence Thank you for sharing these log locations! I already have IPDB and Owl logs successfully integrated and forwarding to Wazuh. Regarding the Detected Viruses and Killed Queries - these haven't been generated on my server yet, probably because nothing suspicious was detected 😊 Would you mind sending some example logs to info@netzen.cz? That would help me process and test the integration properly.

    I'm making good progress with the Wazuh integration overall. In about 2-3 days, I should be ready to share my configurations with everyone. Thanks again for your help, and wishing you all the best!

      netzen

      You’re welcome. I’ve sent an email with a sample file. Glad to hear about your progress.

      Due to the pre-Christmas rush, I’m running a bit late on my promised timeline. I plan to get back to this topic between the holidays. My apologies for the delay, and wishing you all a wonderful Christmas season! 🎄

        netzen Bro take all the time in the world, you're doing us all a huge favour sharing your findings! Merry Christmas to you too🦌 Pěknou dovolenou!

        netzen Take all the time you need; no need to apologize. We will be here 🙂 Merry Christmas.

        Thanks everyone - I hope to share my configuration for this setup after Christmas. I've successfully mapped UUIDs to domains, allowing me to visualize both container metrics and system metrics on a dashboard like this. While there are multiple display options available, this layout works best for me.

        7 days later
        2 months later

        I sincerely apologize for not continuing here with the promised process. Firstly, I was waiting for the Enhance update, and secondly, to be honest, I was overwhelmed with other events. If there is interest, I can continue.

          Yes, I would be interested

          Yes, interested.

          Interested

          6 days later
          Write a Reply...
          Follow @enhancecp