如何通过SaltStack结合Grains修改OSSEC(Wazuh) Agent的<config-profile>?
Alright, let's figure out how to make this work. You want to take the ossec-profiles list from your SaltStack Grains (like profile1, profile2) and append those to the existing <config-profile> entry in ossec.conf—here are two reliable ways to pull this off:
Method 1: Directly Modify the File with
file.replace This approach is great if you just need to tweak an existing config file without rewriting the whole thing. Create a Salt state (e.g., ossec/update_profiles.sls) with this content:
update_ossec_config_profiles: file.replace: - name: /etc/ossec/ossec.conf # Adjust path to match your OSSEC install - pattern: '<config-profile>(.*)</config-profile>' - repl: '<config-profile>\1, {{ grains.get('ossec-profiles', [])|join(', ') }}</config-profile>' - prereq: - pkg: ossec-hids # Ensure OSSEC is installed first
Breakdown:
- The regex pattern captures all existing profiles inside the
<config-profile>tag using(.*). - The replacement inserts the original captured content (
\1) followed by a comma-separated string of your Grain values. We usegrains.getwith an empty list fallback so the state won't break if the Grain isn't set. - Run
salt 'your-minion' state.sls ossec/update_profiles test=Truefirst to preview changes—always test before applying to production!
Method 2: Manage the Config with a Jinja Template (Recommended)
For long-term maintainability, using a Jinja template is the way to go. You'll version-control the base config and dynamically inject Grain values where needed.
- First, create a template file at
salt://ossec/templates/ossec.conf.j2:
<!-- Keep all your existing OSSEC config here --> <config-profile>centos, centos7{% if grains.get('ossec-profiles') %}, {{ grains.get('ossec-profiles')|join(', ') }}{% endif %}</config-profile> <!-- Rest of your OSSEC config -->
- Then create a state to deploy this template (e.g.,
ossec/deploy_config.sls):
deploy_ossec_config: file.managed: - name: /etc/ossec/ossec.conf - source: salt://ossec/templates/ossec.conf.j2 - template: jinja - require: - pkg: ossec-hids
Breakdown:
- The Jinja conditional checks if the
ossec-profilesGrain exists. If it does, appends the comma-separated list to the default profiles. - This keeps your base config clean and static, while letting Salt handle the dynamic parts. It's easier to update defaults later or add other dynamic values if needed.
Quick Tips
- If your existing
<config-profile>line has extra whitespace (like spaces around commas), adjust the regex in Method 1 to'<config-profile>\s*(.*?)\s*</config-profile>'to ignore leading/trailing spaces. - Make sure your
ossec-profilesGrain is always a list (not a single string) to avoid formatting issues. You can enforce this in your custom Grain definition if needed.
内容的提问来源于stack exchange,提问作者Marcello Percoco
相关产品推荐
相关产品推荐

