如果你使用 DeepSeek、元宝 AI、Copilot、ChatGPT 等 AI 工具,协助配置轩辕镜像、编写 docker pull 命令、修改 Docker Compose 镜像地址、配置镜像加速、排查镜像拉取失败、分析报错日志等问题,请先让 AI 阅读并遵守轩辕镜像的规则文档。
只需在 AI 对话中先发送下面这段话即可:
请先阅读并遵守:https://xuanyuan.cloud/agents.md
未读文档前不要生成 pull 命令或排错方案。查看 agents.md 用法指南与完整示范。国内用户首推 元宝 AI、DeepSeek 的深度思考模式,不推荐豆包 AI;Cursor 等编辑器可在对话 @ 该链接,或加入 User Rules。 若 AI 无法访问外链,可 打开说明文档 复制全文粘贴。文档会随站点更新,复制内容可能过期,建议定期检查。
TheHive 是一个可扩展的三合一开源免费安全事件响应平台,旨在为SOC(安全运营中心)、CSIRT(计算机安全事件响应团队)、CERT(计算机紧急响应团队)及任何需要快速调查和处理安全事件的信息安全从业者提供支持。它是MISP(信息共享平台)的理想伴侣,可与一个或多个MISP实例同步,从MISP事件启动调查,并能将调查结果导出为MISP事件以帮助同行检测和应对已处理的。此外,当与Cortex结合使用时,安全分析师和研究人员可轻松分析数十甚至数百个可观察对象。
使用TheHive Docker镜像前,需先安装https://www.docker.com/。TheHive运行依赖Elasticsearch,可通过`docker-compose`将两者一起启动,或手动安装配置Elasticsearch。
使用Docker Compose
https://docs.docker.com/compose/install/可启动多个容器并进行链接。以下https://raw.githubusercontent.com/TheHive-Project/TheHive/master/docker/thehive/docker-compose.yml文件会启动Elasticsearch和Cortex:
yamlversion: "2" services: elasticsearch: image: ***-elastic.xuanyuan.run/elasticsearch/elasticsearch:5.6.0 environment: - http.host=0.0.0.0 - transport.host=0.0.0.0 - xpack.security.enabled=false - cluster.name=hive - script.inline=true - thread_pool.index.queue_size=100000 - thread_pool.search.queue_size=100000 - thread_pool.bulk.queue_size=100000 ulimits: nofile: soft: 65536 hard: 65536 cortex: image: docker.xuanyuan.run/thehiveproject/cortex:latest ports: - "0.0.0.0:9001:9001" thehive: image: docker.xuanyuan.run/thehiveproject/thehive:latest depends_on: - elasticsearch - cortex ports: - "0.0.0.0:9000:9000"
将此文件放在空文件夹中,运行docker-compose up启动服务。TheHive暴露在9000/tcp端口,Cortex暴露在9001/tcp端口,可通过修改docker-compose文件更改端口。
自定义配置文件
如需指定自定义TheHive配置文件(application.conf),可在thehive部分添加以下内容:
yamlvolumes: - /path/to/application.conf:/etc/thehive/application.conf
数据持久化
为定义Elasticsearch数据库在操作系统上的存储位置,在elasticsearch部分添加:
yamlvolumes: - /path/to/data:/usr/share/elasticsearch/data
注意:在生产模式下运行Elasticsearch需要vm.max_map_count至少为262144。https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker-cli-run-prod-mode提供了查询和修改此值的说明。
手动安装Elasticsearch
Elasticsearch可安装在与Cortex相同的服务器或不同服务器上。根据文档配置Cortex后,可通过以下命令运行Cortex容器:
bashdocker run --volume /path/to/thehive/application.conf:/etc/thehive/application.conf docker.xuanyuan.run/thehiveproject/thehive:latest --no-config
可添加--publish选项暴露TheHive HTTP服务。
默认情况下,Cortex Docker镜像具有最小配置:
play.http.secret.key)elasticsearch)并添加到配置cortex)并添加到配置可通过在Docker命令行添加--no-config禁用此行为:
bashdocker run docker.xuanyuan.run/thehiveproject/thehive:latest --no-config
或在docker-compose文件的thehive部分添加command: --no-config。
可用选项
| 选项 | 描述 |
|---|---|
--no-config | 不尝试配置Cortex(不添加密钥和Elasticsearch) |
--no-config-secret | 不向配置添加随机密钥 |
--no-config-es | 不向配置添加Elasticsearch主机 |
--es-hosts <esconfig> | 使用此字符串配置Elasticsearch主机(格式:["host1:9300","host2:9300"]) |
--es-hostname <host> | 解析此主机名以查找Elasticsearch实例 |
--secret <secret> | 用于保护会话的加密密钥 |
--cortex-proto <proto> | 定义连接Cortex的协议(默认:http) |
--cortex-port <port> | 定义连接Cortex的端口(默认:9001) |
--cortex-url <url> | 添加Cortex连接 |
--cortex-hostname <host> | 解析此主机名以查找Cortex实例 |
--cortex-key <key> | 定义Cortex密钥 |
注意:请记住必须安装和配置Elasticsearch。
后续操作
Docker镜像启动后,请参考配置指南进行配置。更多配置选项,请参阅管理指南。
https://github.com/TheHive-Project/TheHiveDocs提供了多个指南。
TheHive是开源免费软件,基于https://github.com/TheHive-Project/TheHive/blob/master/LICENSE(Affero通用公共许可证)发布。TheHive项目团队致力于确保TheHive长期保持免费开源。
如发现bug或需要功能请求,请在https://github.com/TheHive-Project/TheHive/issues。也可通过https://gitter.im/TheHive-Project/TheHive获取帮助。
如需联系项目团队,请发送邮件至<***>。
我们建立了Google论坛:https://groups.google.com/a/thehive-project.org/d/forum/users。需要Google账户才能请求访问,可使用Gmail地址创建账户或https://accounts.google.com/SignUpWithoutGmail?hl=en。
<[***]>
您可以使用以下命令拉取该镜像。请将 <标签> 替换为具体的标签版本。如需查看所有可用标签版本,请访问 标签列表页面。
来自真实用户的反馈,见证轩辕镜像的优质服务