You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过SaltStack结合Grains修改OSSEC(Wazuh) Agent的<config-profile>?

Alright, let's figure out how to make this work. You want to take the ossec-profiles list from your SaltStack Grains (like profile1, profile2) and append those to the existing <config-profile> entry in ossec.conf—here are two reliable ways to pull this off:


Method 1: Directly Modify the File with file.replace

This approach is great if you just need to tweak an existing config file without rewriting the whole thing. Create a Salt state (e.g., ossec/update_profiles.sls) with this content:

update_ossec_config_profiles:
  file.replace:
    - name: /etc/ossec/ossec.conf  # Adjust path to match your OSSEC install
    - pattern: '<config-profile>(.*)</config-profile>'
    - repl: '<config-profile>\1, {{ grains.get('ossec-profiles', [])|join(', ') }}</config-profile>'
    - prereq:
        - pkg: ossec-hids  # Ensure OSSEC is installed first

Breakdown:

  • The regex pattern captures all existing profiles inside the <config-profile> tag using (.*).
  • The replacement inserts the original captured content (\1) followed by a comma-separated string of your Grain values. We use grains.get with an empty list fallback so the state won't break if the Grain isn't set.
  • Run salt 'your-minion' state.sls ossec/update_profiles test=True first to preview changes—always test before applying to production!

For long-term maintainability, using a Jinja template is the way to go. You'll version-control the base config and dynamically inject Grain values where needed.

  1. First, create a template file at salt://ossec/templates/ossec.conf.j2:
<!-- Keep all your existing OSSEC config here -->
<config-profile>centos, centos7{% if grains.get('ossec-profiles') %}, {{ grains.get('ossec-profiles')|join(', ') }}{% endif %}</config-profile>
<!-- Rest of your OSSEC config -->
  1. Then create a state to deploy this template (e.g., ossec/deploy_config.sls):
deploy_ossec_config:
  file.managed:
    - name: /etc/ossec/ossec.conf
    - source: salt://ossec/templates/ossec.conf.j2
    - template: jinja
    - require:
        - pkg: ossec-hids

Breakdown:

  • The Jinja conditional checks if the ossec-profiles Grain exists. If it does, appends the comma-separated list to the default profiles.
  • This keeps your base config clean and static, while letting Salt handle the dynamic parts. It's easier to update defaults later or add other dynamic values if needed.

Quick Tips
  • If your existing <config-profile> line has extra whitespace (like spaces around commas), adjust the regex in Method 1 to '<config-profile>\s*(.*?)\s*</config-profile>' to ignore leading/trailing spaces.
  • Make sure your ossec-profiles Grain is always a list (not a single string) to avoid formatting issues. You can enforce this in your custom Grain definition if needed.

内容的提问来源于stack exchange,提问作者Marcello Percoco

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 09:15:52