Uninstalling the Wazuh agent

This section describes how to uninstall Wazuh agents installed across the different operating systems below:

Note

After you uninstall a Wazuh agent, remove it from the Wazuh manager using the Wazuh dashboard or the Wazuh manager API, as Remove agents describes. This stops it from showing as disconnected, frees its name for reuse, and lets you reinstall it under the same name. Without this, or a new WAZUH_AGENT_NAME on reinstall, the manager refuses enrollment with "Duplicate name" until the old agent has been disconnected for one hour. Agents enrolled without WAZUH_AGENT_NAME, and agents enrolled from the Windows GUI, use the host name.

If no other agent will use the enrollment token, revoke it on the Wazuh manager master node with /var/wazuh-manager/bin/wazuh-manager-authd --revoke-enrollment-token <TOKEN_ID>. To find the token ID, run /var/wazuh-manager/bin/wazuh-manager-authd --list-enrollment-tokens.

To enroll an agent again instead of uninstalling it, see Re-enrolling a Wazuh agent.

Uninstalling a Linux Wazuh agent

Run the following commands to uninstall a Linux agent.

Note

If anti-tampering is enabled on the agent, the package manager stops the removal with ERROR: Validation host not provided. Uninstallation cannot be continued. Set up the validation first, as Uninstalling an agent with anti-tampering enabled describes, and then follow these steps.

  1. Disable the Wazuh agent service. To find the endpoint's service manager, run ps -p 1 -o comm=. If it prints systemd, use the Systemd tab. On a systemd host, the SysV commands either fail or silently do nothing.

    # systemctl disable wazuh-agent
    # systemctl daemon-reload
    
  2. Remove the Wazuh agent installation:

    # apt-get remove wazuh-agent
    

    apt-get remove keeps the agent configuration, its key, and the re-enrollment secret in /var/ossec/etc/*.save, the Wazuh manager CA in /var/ossec/etc/certs/root-ca.pem.save, and the wazuh user. To remove them too, run the following command:

    # apt-get remove --purge wazuh-agent
    
  3. Remove the Wazuh repository and its key:

    # rm -f /etc/apt/sources.list.d/wazuh.list /usr/share/keyrings/wazuh.gpg /usr/share/keyrings/wazuh.gpg~
    # apt-get clean
    # apt-get update
    

The Wazuh agent is now removed from your Linux endpoint. Remove it from the Wazuh manager too, as the note at the start of this section describes.

Uninstalling a Windows Wazuh agent

Follow these steps in an elevated session to uninstall the Wazuh agent from your Windows endpoint. Replace <MSI_PATH> with the path to the Windows installer that installed or last upgraded the Wazuh agent.

  1. Remove the Wazuh agent installation:

    • Using CMD:

      > start /wait msiexec.exe /x "<MSI_PATH>" /qn
      
    • Using PowerShell:

      > Start-Process msiexec.exe -ArgumentList '/x "<MSI_PATH>" /qn' -Wait
      

    If you no longer have the installer, uninstall Wazuh Agent from Settings > Apps > Installed apps, or run the Uninstall shortcut in the Start menu folder OSSEC, then continue with step 2. To check the removal, run Get-Service WazuhSvc: it reports that no service was found.

  2. Remove the Wazuh agent installation folder. After the removal, the folder still holds the agent key in client.keys.save.

    • Using CMD:

      > rmdir /s /q "C:\Program Files (x86)\ossec-agent"
      
    • Using PowerShell:

      > Remove-Item -Path "C:\Program Files (x86)\ossec-agent" -Recurse -Force
      

    If the command reports that the folder is in use, wait until Get-Process wazuh-agent -ErrorAction SilentlyContinue prints nothing, then run it again.

The Wazuh agent is now removed from your Windows endpoint.

Remove the agent from the Wazuh manager too, as the note at the start of this section describes.

Uninstalling a macOS Wazuh agent

Follow these steps to uninstall the Wazuh agent from your macOS endpoint.

  1. Stop the Wazuh agent service:

    # launchctl bootout system /Library/LaunchDaemons/com.wazuh.agent.plist
    
  2. Remove the /Library/Ossec/ folder:

    # /bin/rm -r /Library/Ossec
    
  3. Remove the launch daemon and the startup items:

    # /bin/rm -f /Library/LaunchDaemons/com.wazuh.agent.plist
    # /bin/rm -rf /Library/StartupItems/WAZUH
    
  4. Remove the Wazuh user and group:

    # /usr/bin/dscl . -delete "/Users/wazuh"
    # /usr/bin/dscl . -delete "/Groups/wazuh"
    
  5. Remove the package receipts from pkgutil:

    # /usr/sbin/pkgutil --forget com.wazuh.pkg.wazuh-agent
    # /usr/sbin/pkgutil --forget com.wazuh.pkg.wazuh-agent-etc
    

    If the second command prints a "No receipt" error, you can ignore it.

  6. Check that no Wazuh receipt remains. The following command prints nothing:

    # pkgutil --pkgs | grep -i wazuh
    

The Wazuh agent is now removed from your macOS endpoint.

Remove the agent from the Wazuh manager too, as the note at the start of this section describes.