You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Wazuh API执行远程命令无响应问题求助

问题诊断与解决方案

核心原因

你的customA命令未配置允许远程执行的参数,导致Windows代理接收到API发送的命令后拒绝执行。虽然触发规则时命令能正常运行,是因为规则触发的主动响应受active-response块中的location配置控制,而API远程执行需要命令本身显式允许远程调用。

修复步骤

1. 修改管理器命令配置

编辑Wazuh管理器的/var/ossec/etc/ossec.conf,在customA的command块中添加<remote_allowed>yes</remote_allowed>参数:

<command>
  <name>customA</name>
  <executable>launcher.cmd</executable>
  <extra_args>custom_remove.py</extra_args>
  <remote_allowed>yes</remote_allowed>
</command>

2. 重启Wazuh管理器

让配置生效:

systemctl restart wazuh-manager

3. 验证配置更新

调用API确认customA已允许远程执行:

curl -k -X GET "https://192.168.1.76:55000/manager/configuration/analysis/command" -H "Authorization: Bearer $TOKEN"

返回结果中customA应包含"remote_allowed": true字段。

4. 重新测试API命令

再次执行你的curl命令,代理端应该会触发customA命令。

额外排查点

  • 查看Windows代理的active-response.log(路径:C:\Program Files (x86)\ossec-agent\logs\active-response.log),检查是否有命令执行失败或被拒绝的日志信息。
  • 确认launcher.cmd和custom_remove.py存放在代理端的C:\Program Files (x86)\ossec-agent\active-response\bin\目录下,且Wazuh代理服务账户有执行权限。
  • 检查代理的ossec.log,搜索customA关键词,查看命令接收、执行的详细日志,定位潜在问题。

内容的提问来源于stack exchange,提问作者user13105993

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 12:50:24