# Wazuh Manager — Production ossec.conf # Full distributed config with 2 managers, multi-org CloudTrail, n8n integration, TLS # Replace: CLUSTER_KEY, INDEXER_HOSTS, N8N_URL, MANAGER_IPS wazuh-production manager-1 10.0.1.20 10.0.1.20 10.0.1.21 CHANGE_TO_32_CHAR_UNIQUE_CLUSTER_KEY yes yes security-alerts@company.com wazuh@wazuh.internal.yourdomain.com 100 1 yes yes 6 yes yes no host-deny host-deny.sh srcip yes 10 firewall-drop firewall-drop.sh srcip yes 10 info json no 300 yes yes yes /etc /usr/bin /usr/sbin /bin /sbin /var/log /home /opt /etc/passwd /etc/shadow /etc/group /etc/gshadow /etc/sudoers /etc/sudoers.d/ /var/log/journal /var/log/sa /var/log/gdm .log$ HKEY_LOCAL_MACHINE\Software\Classes\* HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce yes HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run no yes yes yes yes yes yes yes 3600 /var/ossec/etc/shared/rootkit_files.txt /var/ossec/etc/shared/rootkit_trojans.txt /var/ossec/etc/shared/system_audit_rcl.txt /var/ossec/etc/shared/cis_debian_linux_rcl.txt yes /var/ossec/shared/cis-centos7-benchmark.xml 604800 no 1h yes yes yes yes yes yes yes no 5m yes yes cloudtrail-org-alpha-logs arn:aws:iam::111111111111:role/WazuhCrossAccountRead 2025-01-01T00:00:00Z us-east-1,eu-west-1 cloudtrail-org-beta-logs arn:aws:iam::222222222222:role/WazuhCrossAccountRead 2025-01-01T00:00:00Z us-east-1 cloudtrail-org-gamma-logs arn:aws:iam::333333333333:role/WazuhCrossAccountRead 2025-01-01T00:00:00Z us-east-1,ap-southeast-1 arn:aws:iam::111111111111:role/WazuhCrossAccountRead 2025-01-01T00:00:00Z us-east-1,eu-west-1 yes 1h yes amazon-linux ALAS ALAS-1 1d wazuh-n8n https://n8n.internal.yourdomain.com/webhook/wazuh-alerts 6 json 30 3 slack https://hooks.slack.com/services/XXX/YYY/ZZZ 12 json no 1515 yes 20000 HIGH:!ADH:!AECDH:!MD5:!RC4 /var/ossec/etc/ssl cacert.pem /var/ossec/etc/ssl agentcert.pem /var/ossec/etc/ssl agentkey.pem no no no 0 /var/ossec/etc/key no yes secure 1514 tcp 131072 no custom-block-ip aws-security-group-block.py srcip 10 syslog /var/log/messages syslog /var/log/secure apache /var/log/httpd/access_log apache /var/log/httpd/error_log nginx /var/log/nginx/access.log json /var/log/ossec/archives.json