You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wazuh与VirusTotal集成报错:integrations目录文件未找到

Wazuh与VirusTotal集成故障排查思路
  • 检查文件权限
    确认Wazuh运行用户(默认是ossec)对/var/ossec/integrations/下的两个文件拥有读和执行权限:

    ls -l /var/ossec/integrations/virustotal*
    

    若权限不符,执行以下命令修正:

    chown ossec:ossec /var/ossec/integrations/virustotal*
    chmod 750 /var/ossec/integrations/virustotal*
    
  • 验证ossec.conf配置路径
    检查集成配置中的<command>字段是否使用了正确的绝对路径,示例正确配置:

    <integration>
        <name>virustotal</name>
        <api_key>YOUR_VT_API_KEY</api_key>
        <group>syscheck</group>
        <alert_format>json</alert_format>
        <command>/var/ossec/integrations/virustotal</command>
    </integration>
    

    避免仅写virustotal,确保路径无拼写错误。

  • 检查脚本shebang与Python环境
    查看virustotal.py开头的shebang行,确认指向系统中存在的Python解释器:

    head -n 1 /var/ossec/integrations/virustotal.py
    

    若路径错误,替换为系统实际Python路径(可通过which python3获取),例如:

    #!/usr/bin/env python3
    

    同时确认脚本依赖的requests库已安装:

    python3 -c "import requests"
    

    若报错,执行pip3 install requests安装依赖。

  • 排查安全模块限制
    检查SELinux或AppArmor是否阻止Wazuh访问集成脚本:

    • SELinux:执行getenforce查看状态,若为Enforcing,临时关闭测试:
      setenforce 0
      
      若故障恢复,需添加SELinux允许规则。
    • AppArmor:查看Wazuh相关配置文件,确认未限制/var/ossec/integrations/目录访问。
  • 重启Wazuh服务并验证
    修改配置或权限后,重启Wazuh管理器:

    systemctl restart wazuh-manager
    

    查看日志确认报错是否消失:

    tail -f /var/ossec/logs/ossec.log
    

内容的提问来源于stack exchange,提问作者Yogi Valentino

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.11 23:12:07