sca

This section covers the configuration for the Security Configuration Assessment module.

Settings to run Security Configuration Assessment scans.

Options

Main options

Scheduling options

enabled

Enables the module.

Default value

yes

Allowed values

yes, no

policies

Between <policy> tags, in this section it can be included policy files to run assessments.

Default value

n/a

Allowed values

Any YAML policy file

Attributes

enabled

Offers the possibility to disable a policy when it has been enabled previously.

Note

Since Wazuh v3.10.0, although this section is missing, the Wazuh Agent will run scans for every policy (.yaml or .yml files) present in their ruleset folder.

Note

Since Wazuh v4.2.0, when a policy is defined by a relative path, this path is relative to the Wazuh installation directory. If the policy is located outside the installation directory, a full path can be used.

Example

<policies>
  <policy>etc/shared/cis_debian10.yml</policy>
  <policy>/path/to/my/policy.yml</policy>
</policies>

max_eps

Maximum number of events per second the SCA module sends.

Default value

50

Allowed values

Integer from 0 to 1000000

synchronization

Settings for synchronizing the SCA results database with the Wazuh manager.

<synchronization>
  <enabled>yes</enabled>
  <interval>5m</interval>
  <integrity_interval>24h</integrity_interval>
</synchronization>

Option

Description

Default

Allowed values

enabled

Enables periodic synchronization.

yes

yes, no

interval

Time between synchronizations.

5m (300 seconds)

Positive time value with optional suffix s, m, h or d. 0 is not allowed.

integrity_interval

Time between integrity checks of the synchronized data.

24h (86400 seconds)

Non-negative time value with optional suffix s, m, h or d.

skip_nfs

Deprecated since version 5.0.0: This option has no effect in Wazuh 5.0. The SCA module still accepts it so configurations from Wazuh 4.x agents don't fail, and logs a deprecation warning when it finds it.

scan_on_start

The SCA module will perform the scan immediately when started.

Default value

yes

Allowed values

yes, no

interval

The interval between module executions.

Default value

1d (86400 seconds)

Allowed values

A positive number with an optional suffix: s (seconds), m (minutes), h (hours) or d (days). A number without a suffix is in seconds.

day, wday, time

Deprecated since version 5.0.0: These scheduling options have no effect in Wazuh 5.0. The SCA module runs on interval only. It still accepts them so configurations from Wazuh 4.x agents don't fail, and logs a deprecation warning when it finds one.

Sample configuration

<sca>
  <enabled>yes</enabled>
  <scan_on_start>yes</scan_on_start>
  <policies>
    <policy>etc/shared/cis_debian10.yml</policy>
    <policy enabled="no">ruleset/sca/cis_debian9.yml</policy>
    <policy>/my/custom/policy/path/my_policy.yaml</policy>
  </policies>
</sca>