Distributed deployment

Certificates creation and deployment

Use the pre-existing root CA keys to generate the certificate for the new node, so the certificates of the existing nodes remain valid. Perform the steps below on one of the existing Wazuh indexer nodes.

Note

If the pre-existing root CA keys have been deleted or you can't access them, create new certificates for all nodes instead. Reference every node of your deployment in /root/config.yml. Run bash wazuh-certs-tool-5.0.0-beta5.sh -A, and redeploy the certificates on every existing node before continuing, as shown in the All-in-one deployment > Certificates creation subsection.

  1. Create a config.yml file in the /root directory to add the new Wazuh indexer node:

    # touch /root/config.yml
    
  2. Edit the /root/config.yml file to include only the node name and IP address of the new node:

    nodes:
      # Wazuh indexer nodes
      indexer:
        - name: <NEW_WAZUH_INDEXER_NODE_NAME>
          ip: "<NEW_WAZUH_INDEXER_IP>"
    
  3. Extract the certificate archive to obtain the root CA keys.

    • If the certificate archive is wazuh-certificates.tar, use this command:

      # mkdir wazuh-install-files && tar -xf ./wazuh-certificates.tar -C wazuh-install-files
      
    • If the certificate archive is wazuh-install-files.tar, use this command:

      # tar -xf ./wazuh-install-files.tar
      
  4. Download and run the certificates tool to create the certificate for the new indexer node using the pre-existing root CA keys. The tool refuses to run when a wazuh-certificates directory already exists beside it, which is the case on the node where the original certificates were created. Rename any existing directory first so that the original certificates are kept.

    # curl -sO https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/installation-assistant/wazuh-certs-tool-5.0.0-beta5.sh
    # [ -d wazuh-certificates ] && mv wazuh-certificates wazuh-certificates.$(date +%Y%m%d%H%M%S).bak
    # bash wazuh-certs-tool-5.0.0-beta5.sh -A wazuh-install-files/root-ca.pem wazuh-install-files/root-ca.key
    
  5. Copy the newly created certificates to the wazuh-install-files folder, making sure not to replace the existing admin certificates:

    # cp wazuh-certificates/<NEW_WAZUH_INDEXER_NODE_NAME>* wazuh-install-files
    
  6. Compress the certificates that the new node requires, taken from the complete set assembled in wazuh-install-files, and copy the archive to the new Wazuh indexer node. You can use the scp utility to copy the compressed file securely:

    # tar -cvf ./wazuh-certificates-<NEW_WAZUH_INDEXER_NODE_NAME>.tar -C ./wazuh-install-files/ ./<NEW_WAZUH_INDEXER_NODE_NAME>.pem ./<NEW_WAZUH_INDEXER_NODE_NAME>-key.pem ./admin.pem ./admin-key.pem ./root-ca.pem
    # scp ./wazuh-certificates-<NEW_WAZUH_INDEXER_NODE_NAME>.tar <TARGET_USERNAME>@<TARGET_IP>:
    

    Note

    The new archive is named after the new node so that the original wazuh-certificates.tar is not overwritten. That archive holds the root CA key, which is required to sign the certificate of every node added later. Keep it, or the wazuh-install-files directory, in secure storage.

Configuring existing components to connect with the new node

  1. Edit the configuration file at /etc/wazuh-indexer/opensearch.yml on all existing Wazuh indexer nodes. Add the <NEW_WAZUH_INDEXER_IP> to the discovery.seed_hosts block, and the <NEW_WAZUH_INDEXER_NODE_NAME> to CN in plugins.security.nodes_dn block.

    network.host: "<EXISTING_WAZUH_INDEXER_IP>"
    node.name: "<EXISTING_WAZUH_INDEXER_NODE_NAME>"
    cluster.name: "wazuh-cluster"
    
    cluster.initial_cluster_manager_nodes:
      - "<EXISTING_WAZUH_INDEXER_NODE_NAME>"
    
    discovery.seed_hosts:
      - "<EXISTING_WAZUH_INDEXER_IP>"
      - "<NEW_WAZUH_INDEXER_IP>"
    
    plugins.security.nodes_dn:
      - "CN=<EXISTING_WAZUH_INDEXER_NODE_NAME>,OU=Wazuh,O=Wazuh,L=California,C=US"
      - "CN=<NEW_WAZUH_INDEXER_NODE_NAME>,OU=Wazuh,O=Wazuh,L=California,C=US"
    

    Note

    The cluster.initial_cluster_manager_nodes setting is only used the first time an indexer cluster starts. For consistency, keep it aligned with the list across all Wazuh indexer nodes. Still, the settings that allow the new node to join a running cluster are discovery.seed_hosts and plugins.security.nodes_dn.

  2. Restart the existing Wazuh indexer nodes one at a time to apply the changes. Restarting the nodes one by one keeps the cluster available while the change is applied:

    # systemctl restart wazuh-indexer
    
  3. Edit the <indexer> block of the Wazuh manager configuration file /var/wazuh-manager/etc/wazuh-manager.conf to add the new Wazuh indexer node, then restart the Wazuh manager:

    <hosts>
      <host>https://<EXISTING_WAZUH_INDEXER_IP>:9200</host>
      <host>https://<NEW_WAZUH_INDEXER_IP>:9200</host>
    </hosts>
    
    # systemctl restart wazuh-manager
    
  4. Edit the Wazuh dashboard configuration file /etc/wazuh-dashboard/opensearch_dashboards.yml to include the new Wazuh indexer node, then restart the Wazuh dashboard:

    opensearch.hosts: ["https://<EXISTING_WAZUH_INDEXER_IP>:9200", "https://<NEW_WAZUH_INDEXER_IP>:9200"]
    
    # systemctl restart wazuh-dashboard
    

Having completed the distributed deployment steps, proceed to the New Wazuh indexer node step.