通过Wazuh API执行远程命令无响应问题求助
问题诊断与解决方案
核心原因
你的customA命令未配置允许远程执行的参数,导致Windows代理接收到API发送的命令后拒绝执行。虽然触发规则时命令能正常运行,是因为规则触发的主动响应受active-response块中的location配置控制,而API远程执行需要命令本身显式允许远程调用。
修复步骤
1. 修改管理器命令配置
编辑Wazuh管理器的/var/ossec/etc/ossec.conf,在customA的command块中添加<remote_allowed>yes</remote_allowed>参数:
<command> <name>customA</name> <executable>launcher.cmd</executable> <extra_args>custom_remove.py</extra_args> <remote_allowed>yes</remote_allowed> </command>
2. 重启Wazuh管理器
让配置生效:
systemctl restart wazuh-manager
3. 验证配置更新
调用API确认customA已允许远程执行:
curl -k -X GET "https://192.168.1.76:55000/manager/configuration/analysis/command" -H "Authorization: Bearer $TOKEN"
返回结果中customA应包含"remote_allowed": true字段。
4. 重新测试API命令
再次执行你的curl命令,代理端应该会触发customA命令。
额外排查点
- 查看Windows代理的
active-response.log(路径:C:\Program Files (x86)\ossec-agent\logs\active-response.log),检查是否有命令执行失败或被拒绝的日志信息。 - 确认
launcher.cmd和custom_remove.py存放在代理端的C:\Program Files (x86)\ossec-agent\active-response\bin\目录下,且Wazuh代理服务账户有执行权限。 - 检查代理的
ossec.log,搜索customA关键词,查看命令接收、执行的详细日志,定位潜在问题。
内容的提问来源于stack exchange,提问作者user13105993
相关产品推荐
相关产品推荐

