You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wazuh 4.4.1安装失败求助:indexer报错及Docker安装也失败

Wazuh 4.4.1安装失败:Indexer安装报错(含Docker安装失败情况)

问题概述

  • 安装Wazuh 4.4.1时,Wazuh indexer持续安装失败
  • 已完成原有安装清理、添加Wazuh仓库、生成配置文件等前置操作
  • 尝试Docker安装Wazuh同样失败,已分配6GB内存仍未解决

安装日志详情

04/05/2023 13:42:25 INFO: Starting Wazuh installation assistant. Wazuh version: 4.4.1 
04/05/2023 13:42:25 INFO: Verbose logging redirected to /var/log/wazuh-install.log 
04/05/2023 13:42:25 INFO: --- Removing existing Wazuh installation --- 
04/05/2023 13:42:25 INFO: Removing Wazuh indexer. 
04/05/2023 13:42:26 INFO: Wazuh indexer removed. 
04/05/2023 13:42:26 INFO: Wazuh GPG key was not found in the system 
04/05/2023 13:42:26 INFO: Installation cleaned. 
04/05/2023 13:42:30 INFO: Wazuh repository added. 
04/05/2023 13:42:30 INFO: --- Configuration files --- 
04/05/2023 13:42:30 INFO: Generating configuration files. 
04/05/2023 13:42:32 INFO: Created wazuh-install-files.tar. It contains the Wazuh cluster key, certificates, and passwords necessary for installation. 
04/05/2023 13:42:32 INFO: --- Wazuh indexer --- 
04/05/2023 13:42:32 INFO: Starting Wazuh indexer installation. 
04/05/2023 13:43:13 ERROR: Wazuh indexer installation failed. 
04/05/2023 13:43:13 INFO: --- Removing existing Wazuh installation --- 
04/05/2023 13:43:13 INFO: Removing Wazuh indexer. 
04/05/2023 13:43:15 INFO: Wazuh indexer removed. 
04/05/2023 13:43:15 INFO: Installation cleaned.

排查与解决建议

1. 修复GPG密钥问题

日志明确提示Wazuh GPG key was not found in the system,手动重新导入密钥:

curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg

执行完成后重新运行安装助手。

2. 获取详细错误信息

当前日志仅显示安装失败,查看完整安装日志定位具体问题:

cat /var/log/wazuh-install.log | grep -A 20 -B 5 "ERROR"

重点关注依赖缺失、端口占用、文件权限不足等细节。

3. 系统资源深度检查

  • 用free -h确认内存是否被其他进程占用,确保可用内存不低于2GB(Wazuh indexer最低要求)
  • 用df -h检查根目录及/var分区剩余空间,需至少预留10GB可用空间
  • 用nproc确认CPU核心数,建议不低于2核

4. Docker安装额外排查

  • 检查Docker服务状态:systemctl status docker,确保服务正常运行
  • 查看失败容器的日志:
    docker ps -a # 列出所有容器,找到对应Wazuh容器ID
    docker logs <容器ID>
    
  • 确认Docker Compose版本符合要求,Wazuh 4.4.1建议使用Compose v2版本

5. 手动安装Indexer排除脚本问题

如果安装助手持续失败,尝试手动安装Wazuh indexer:

  1. 安装基础依赖:
    apt install -y apt-transport-https
    
  2. 配置仓库:
    echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main" | tee /etc/apt/sources.list.d/wazuh.list
    
  3. 更新并安装:
    apt update && apt install wazuh-indexer
    

安装过程中观察实时报错,直接定位问题根源。

内容的提问来源于stack exchange,提问作者SlingShot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 18:57:46