anti_tampering
The <anti_tampering> section configures protection against unauthorized uninstallation of the Wazuh agent package on Linux. When enabled, uninstalling the package requires validation through the Wazuh manager API.
Options
package_uninstallation
Enables or disables the validation requirement for a user to uninstall the Wazuh agent package.
Default value |
no |
Allowed values |
yes, no |
Configuration example
<!-- Enables validation requirement to uninstall Wazuh agent package -->
<anti_tampering>
<package_uninstallation>yes</package_uninstallation>
</anti_tampering>
Wazuh manager API connection data
When package uninstallation protection is enabled, provide the Wazuh manager API connection details through environment variables.
Environment variables |
Description |
Required/Optional |
|---|---|---|
|
Authentication token used for the Wazuh manager API request. |
Either |
|
Wazuh manager API username and password to generate a token. Format: |
Either |
|
Enable SSL verification with the Wazuh manager API certificate. Format: |
Optional - |
|
Host and port where the Wazuh manager API is installed. Format: |
Required |
You can create a file such as /$(WAZUH_DIR)/etc/uninstall_validation.env to export the environment variables. For example:
#!/bin/sh
export VALIDATION_LOGIN="wazuh:wazuh"
export VALIDATION_HOST="192.168.0.3:55000"
export VALIDATION_SSL_VERIFY="false"
Alternatively, use an existing API token instead of username and password credentials:
#!/bin/sh
export VALIDATION_TOKEN="<API_TOKEN>"
export VALIDATION_HOST="<WAZUH_MANAGER_IP>:55000"
export VALIDATION_SSL_VERIFY="true"