Uninstalling the Wazuh central components
Uninstalling deletes the components' data and configuration, including indexed alerts and certificates, and asks no confirmation. It can also delete the root CA private key in /etc/wazuh/ca, which you need to add nodes or renew certificates. Back up anything you want to keep first, /etc/wazuh/ca included.
You can remove the Wazuh central components in two ways. Use only one. The installation assistant removes every Wazuh central component on the host at once. The package manager removes one component at a time, as described in Uninstall one component with the package manager.
Uninstall all central components with the installation assistant
Follow these steps to uninstall the Wazuh central components with the installation assistant. Back up /etc/wazuh/ca first, as described at the start of this section.
If you no longer have the Wazuh installation assistant script, download it:
# curl -sO https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/installation-assistant/wazuh-install-5.0.0-rc1.sh
Run the Wazuh installation assistant with the option
-uor--uninstallas follows:# bash wazuh-install-5.0.0-rc1.sh --uninstall
This removes the Wazuh indexer, the Wazuh manager, and the Wazuh dashboard packages that are installed on the host, and their data. It leaves the
wazuh-indexeruser and group on every host that had the Wazuh indexer.On every host that had the Wazuh indexer, remove its user and the Java performance data directory it leaves in
/tmp:# userdel wazuh-indexer # rm -rf /tmp/hsperfdata_wazuh-indexer
On a host with the Wazuh indexer and without the Wazuh dashboard,
/etc/wazuhalso remains. It can holdcredentials.envand, on the host where you created the certificates (the first Wazuh indexer node, or the host where you ran--generate-config-files), the root CA private key inca/. Once you have the backup described at the start of this section, remove the directory:# rm -rf /etc/wazuh
Confirm the removal:
# rpm -qa 'wazuh-*'
# dpkg -l 'wazuh-*'
No Wazuh central component package is listed.
The
wazuh-install-files.tarholds the passwords and every node's private key. Remove it along with/var/log/wazuh-install.log, the assistant script, and the other generated files in your working directory:# rm -rf /var/log/wazuh-install.log ./wazuh-install-5.0.0-rc1.sh ./artifact_urls_5.0.0-rc1.yaml ./wazuh-install-files.tar ./wazuh-install-packages
If you installed the components step by step, also remove the Wazuh repository as described in Removing the Wazuh repository.
Uninstall one component with the package manager
Remove the components in any order. Removing the last Wazuh central component on a host can delete the root CA private key in /etc/wazuh/ca, which you need to add nodes or renew certificates. On the host that holds /etc/wazuh/ca/root-ca.key, copy the directory to a safe place before you start:
# cp -a /etc/wazuh/ca <BACKUP_DIRECTORY>/
Replace <BACKUP_DIRECTORY> with a directory outside /etc/wazuh, preferably on another host.
Uninstalling the Wazuh dashboard
Run the following commands to uninstall the Wazuh dashboard:
Remove the Wazuh dashboard installation:
# systemctl disable --now wazuh-dashboard # apt-get remove --purge wazuh-dashboard -y
# systemctl disable --now wazuh-dashboard # yum remove wazuh-dashboard -y # rm -rf /var/lib/wazuh-dashboard/ # rm -rf /usr/share/wazuh-dashboard/ # rm -rf /etc/wazuh-dashboard/
# systemctl disable --now wazuh-dashboard # dnf remove wazuh-dashboard -y # rm -rf /var/lib/wazuh-dashboard/ # rm -rf /usr/share/wazuh-dashboard/ # rm -rf /etc/wazuh-dashboard/
Uninstalling the Wazuh manager
Run the following commands to uninstall the Wazuh manager:
Remove the Wazuh manager installation:
# systemctl disable --now wazuh-manager # apt-get remove --purge wazuh-manager -y # rm -rf /var/wazuh-manager/
# systemctl disable --now wazuh-manager # yum remove wazuh-manager -y # rm -rf /var/wazuh-manager/
# systemctl disable --now wazuh-manager # dnf remove wazuh-manager -y # rm -rf /var/wazuh-manager/
Uninstalling the Wazuh indexer
Run the following commands to uninstall the Wazuh indexer:
Remove the Wazuh indexer installation:
# systemctl disable --now wazuh-indexer # apt-get remove --purge wazuh-indexer -y # rm -rf /var/lib/wazuh-indexer/ /usr/share/wazuh-indexer/ /etc/wazuh-indexer/ /var/log/wazuh-indexer/ # rm -rf /etc/systemd/system/wazuh-indexer.service.d/ # systemctl daemon-reload # userdel wazuh-indexer # rm -rf /tmp/hsperfdata_wazuh-indexer
dpkgmay warn that some directories are not empty. Therm -rfcommand removes them.# systemctl disable --now wazuh-indexer # yum remove wazuh-indexer -y # rm -rf /var/lib/wazuh-indexer/ /usr/share/wazuh-indexer/ /etc/wazuh-indexer/ /var/log/wazuh-indexer/ # rm -rf /etc/systemd/system/wazuh-indexer.service.d/ # systemctl daemon-reload # userdel wazuh-indexer # rm -rf /tmp/hsperfdata_wazuh-indexer
# systemctl disable --now wazuh-indexer # dnf remove wazuh-indexer -y # rm -rf /var/lib/wazuh-indexer/ /usr/share/wazuh-indexer/ /etc/wazuh-indexer/ /var/log/wazuh-indexer/ # rm -rf /etc/systemd/system/wazuh-indexer.service.d/ # systemctl daemon-reload # userdel wazuh-indexer # rm -rf /tmp/hsperfdata_wazuh-indexer
Removing the Wazuh repository
After you remove the last Wazuh central component from a host installed with the step-by-step method, and no Wazuh agent runs on it, remove the Wazuh repository, its key, and the cached packages:
# rm -f /etc/apt/sources.list.d/wazuh.list /usr/share/keyrings/wazuh.gpg /usr/share/keyrings/wazuh.gpg~
# apt-get clean
# apt-get update
# rm -f /etc/yum.repos.d/wazuh.repo
# rpm -e gpg-pubkey-29111145
# yum clean all
# rm -f /etc/yum.repos.d/wazuh.repo
# rpm -e gpg-pubkey-29111145
# dnf clean all
After you remove every Wazuh central component from the host, check that none is left. On RPM-based systems, run rpm -qa 'wazuh-*'. On Debian-based systems, run dpkg -l 'wazuh-*'. No Wazuh central component package is listed.