Variables reference
Set a variable in the playbook's vars: section, in the inventory, or with -e on the ansible-playbook command line. A value in the inventory does not override a variable that the playbook's vars: section already sets, such as wazuh_enrollment_token in wazuh-agent.yml. Change it in the playbook, or pass it with -e. -e name=value passes a string, so pass a list in JSON form, for example -e '{"wazuh_manager_ips": ["<AIO_PUBLIC_IP>"]}'.
General variables
These variables are defined in /etc/ansible/roles/wazuh-ansible/roles/vars/main.yml and are automatically loaded by every role.
Variable |
Default |
Description |
|---|---|---|
|
|
Parsed JSON object read from |
|
|
The full Wazuh version string (e.g., |
|
|
The major and minor version components only (e.g., |
|
|
The major version string in X.x format (e.g., |
|
|
The package revision number is appended to package filenames. Increment the value when a new package revision is released for the same version. |
|
|
The release stage of the current version (e.g., |
|
|
Path on the control node to the directory that holds the deployment configuration files, such as |
|
|
This is the filename of the artifact URLs YAML file that is downloaded by the |
Package-urls
These variables are defined in /etc/ansible/roles/wazuh-ansible/roles/package-urls/defaults/main.yml and control where the artifact URL definitions file is retrieved.
Variable |
Default |
Description |
|---|---|---|
|
|
Determines which package source to use when downloading the artifact URL definitions file. Accepted values are |
|
|
The URL of the artifact URL definitions file, without the |
|
|
The URL of the artifact URL definitions file, without the |
Wazuh credentials
These variables are defined in /etc/ansible/roles/wazuh-ansible/roles/wazuh-credentials/defaults/main.yml.
Variable |
Default |
Description |
|---|---|---|
|
|
Directory on the Ansible control node where the role keeps the deployment passwords, one file per key. Back up this directory. It is the only record of the passwords. |
|
|
Passwords to use instead of generated ones, keyed by |
|
|
Maximum number of seconds a host waits for a certificate issued on the Ansible control node to become valid, when the host clock is behind the control node. Beyond it, the run stops and asks you to synchronize the clocks. |
Wazuh indexer
These variables are defined in /etc/ansible/roles/wazuh-ansible/roles/wazuh-indexer/defaults/main.yml.
Variable |
Default |
Description |
|---|---|---|
|
|
When set to |
|
|
When set to
|
|
instances:
aio_node:
name: indexer
ip: "{{ hostvars[inventory_hostname].private_ip }}"
role: aio
|
Defines every node of the deployment: Wazuh indexer, Wazuh manager, and Wazuh dashboard nodes. The role uses it to generate the certificates and to configure the Wazuh indexer cluster.
|
|
|
Defines the path on the target node where the Wazuh indexer package file will be downloaded before installation. |
|
|
This is the base filename of the Wazuh indexer package to download and install. |
|
|
Additional IP addresses, such as a public IP address, to add to the Wazuh manager certificates in an all-in-one deployment. Use it only with |
|
|
IP addresses or DNS names to add to the agent listener certificate ( |
|
|
Directory on the Ansible control node where the Wazuh certificates tool keeps the root CA of the deployment and its private key. Every directory in the path must be owned by root and not writable by other users. The playbook prints this directory on every run. Back it up. |
|
Empty |
JVM heap size of the Wazuh indexer, with a unit, for example |
For example, to add a public IP address to the Wazuh manager certificates of an all-in-one deployment, add wazuh_manager_ips to the vars section of the play in wazuh-aio.yml. Keep the two-space indentation of that section:
vars:
single_node: true
wazuh_manager_ips:
- "<AIO_PUBLIC_IP>"
For an address the whole cluster shares, add agent_san to the vars of the Configure Wazuh Indexer cluster play in wazuh-distributed.yml, next to instances. Keep the two-space indentation of that section:
vars:
agent_san: ["<SHARED_ADDRESS>"]
Wazuh manager
These variables are defined in /etc/ansible/roles/wazuh-ansible/roles/wazuh-manager/defaults/main.yml.
Variable |
Default |
Description |
|---|---|---|
|
|
When set to |
|
|
Defines the role of the Wazuh manager node within the cluster. Accepted values are |
|
|
The logical name assigned to this manager node. It is used in the manager configuration file to identify the node within the cluster. In a cluster, it also names the certificate files the role copies to the node, so it must match the |
|
wazuh_indexer_hosts:
- host: "{{ hostvars[inventory_hostname].private_ip }}"
port: 9200
|
The list of Wazuh indexer hosts that this manager node will connect to. Each entry specifies a host address and the port to use for the connection. |
|
|
The path on the target node where the Wazuh manager package file will be downloaded before installation. |
|
|
The base filename of the Wazuh manager package to download and install. |
|
|
This is the filesystem path where the Wazuh manager is installed on the target node. |
Wazuh dashboard
These variables are defined in /etc/ansible/roles/wazuh-ansible/roles/wazuh-dashboard/defaults/main.yml.
Variable |
Default |
Description |
|---|---|---|
|
|
The logical name assigned to the Wazuh dashboard node. It is used to identify the node in configuration and certificate files. In a cluster, it must match the |
|
|
Defines the IP address or hostname of the Wazuh manager master node. The Wazuh dashboard uses this address to configure the Wazuh manager URL in |
|
indexer_cluster_nodes:
- "{{ hostvars[inventory_hostname].private_ip }}"
|
Defines the list of IP addresses or hostnames of the Wazuh indexer nodes. The Wazuh dashboard uses this list to configure the |
|
|
Defines the path on the target node where the Wazuh dashboard package file will be downloaded before installation. |
|
|
The base filename of the Wazuh dashboard package to download and install. |
Wazuh agent
These variables are defined in /etc/ansible/roles/wazuh-ansible/roles/wazuh-agent/defaults/main.yml.
Variable |
Default |
Description |
|---|---|---|
|
|
Defines the path on the Linux or macOS target node where the Wazuh agent package file will be downloaded before installation. |
|
|
Defines the path on the Windows target node where the Wazuh agent package file will be downloaded before installation. |
|
|
The base filename of the Wazuh agent package to download and install. |
|
|
The enrollment token generated on the Wazuh manager. The role passes it to the Wazuh agent installer as |
|
Empty |
An optional setting that defines the Wazuh agent TLS verification mode, passed to the agent installer as |