This is the documentation for Wazuh 3.9. Check out the docs for the latest version of Wazuh!

Linux and Unix agents

Open a session in your Linux/Unix agent host as root user. After that, you can register the Agent using agent-auth:

  1. Copy the newly created certificate (.cert file) and its key (.key file) to the /var/ossec/etc folder and run the agent-auth program. For example, if the manager’s IP address is 192.168.1.2:

    # cp sslagent.cert sslagent.key /var/ossec/etc
    # /var/ossec/bin/agent-auth -m 192.168.1.2 -x /var/ossec/etc/sslagent.cert -k /var/ossec/etc/sslagent.key
    
  2. Edit the Wazuh agent configuration to add the Wazuh server IP address.

In the file /var/ossec/etc/ossec.conf, in the <client><server> section, change the MANAGER_IP value to the Wazuh server address:

<client>
  <server>
    <address>MANAGER_IP</address>
    ...
  </server>
</client>
  1. Start the agent.
  1. For Systemd:
# systemctl start wazuh-agent
  1. For SysV Init:
# service wazuh-agent start
  1. Other cases:
# /var/ossec/bin/ossec-control start