Uninstalling the Wazuh central components

Uninstalling deletes the components' data and configuration, including indexed alerts and certificates, and asks no confirmation. It can also delete the root CA private key in /etc/wazuh/ca, which you need to add nodes or renew certificates. Back up anything you want to keep first, /etc/wazuh/ca included.

You can remove the Wazuh central components in two ways. Use only one. The installation assistant removes every Wazuh central component on the host at once. The package manager removes one component at a time, as described in Uninstall one component with the package manager.

Uninstall all central components with the installation assistant

Follow these steps to uninstall the Wazuh central components with the installation assistant. Back up /etc/wazuh/ca first, as described at the start of this section.

  1. If you no longer have the Wazuh installation assistant script, download it:

    # curl -sO https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/installation-assistant/wazuh-install-5.0.0-rc1.sh
    
  2. Run the Wazuh installation assistant with the option -u or --uninstall as follows:

    # bash wazuh-install-5.0.0-rc1.sh --uninstall
    

    This removes the Wazuh indexer, the Wazuh manager, and the Wazuh dashboard packages that are installed on the host, and their data. It leaves the wazuh-indexer user and group on every host that had the Wazuh indexer.

  3. On every host that had the Wazuh indexer, remove its user and the Java performance data directory it leaves in /tmp:

    # userdel wazuh-indexer
    # rm -rf /tmp/hsperfdata_wazuh-indexer
    
  4. On a host with the Wazuh indexer and without the Wazuh dashboard, /etc/wazuh also remains. It can hold credentials.env and, on the host where you created the certificates (the first Wazuh indexer node, or the host where you ran --generate-config-files), the root CA private key in ca/. Once you have the backup described at the start of this section, remove the directory:

    # rm -rf /etc/wazuh
    
  5. Confirm the removal:

    # rpm -qa 'wazuh-*'
    

    No Wazuh central component package is listed.

  6. The wazuh-install-files.tar holds the passwords and every node's private key. Remove it along with /var/log/wazuh-install.log, the assistant script, and the other generated files in your working directory:

    # rm -rf /var/log/wazuh-install.log ./wazuh-install-5.0.0-rc1.sh ./artifact_urls_5.0.0-rc1.yaml ./wazuh-install-files.tar ./wazuh-install-packages
    

If you installed the components step by step, also remove the Wazuh repository as described in Removing the Wazuh repository.

Uninstall one component with the package manager

Remove the components in any order. Removing the last Wazuh central component on a host can delete the root CA private key in /etc/wazuh/ca, which you need to add nodes or renew certificates. On the host that holds /etc/wazuh/ca/root-ca.key, copy the directory to a safe place before you start:

# cp -a /etc/wazuh/ca <BACKUP_DIRECTORY>/

Replace <BACKUP_DIRECTORY> with a directory outside /etc/wazuh, preferably on another host.

Uninstalling the Wazuh dashboard

Run the following commands to uninstall the Wazuh dashboard:

  1. Remove the Wazuh dashboard installation:

    # systemctl disable --now wazuh-dashboard
    # apt-get remove --purge wazuh-dashboard -y
    

Uninstalling the Wazuh manager

Run the following commands to uninstall the Wazuh manager:

  1. Remove the Wazuh manager installation:

    # systemctl disable --now wazuh-manager
    # apt-get remove --purge wazuh-manager -y
    # rm -rf /var/wazuh-manager/
    

Uninstalling the Wazuh indexer

Run the following commands to uninstall the Wazuh indexer:

  1. Remove the Wazuh indexer installation:

    # systemctl disable --now wazuh-indexer
    # apt-get remove --purge wazuh-indexer -y
    # rm -rf /var/lib/wazuh-indexer/ /usr/share/wazuh-indexer/ /etc/wazuh-indexer/ /var/log/wazuh-indexer/
    # rm -rf /etc/systemd/system/wazuh-indexer.service.d/
    # systemctl daemon-reload
    # userdel wazuh-indexer
    # rm -rf /tmp/hsperfdata_wazuh-indexer
    

    dpkg may warn that some directories are not empty. The rm -rf command removes them.

Removing the shared directory

The Wazuh central components share the /etc/wazuh/ directory. While they are installed, credentials.env holds the generated passwords and ca/ holds the root CA and its private key. Removing a component's package takes its own passwords out of credentials.env. What happens to the rest depends on the last component to leave the host. The Wazuh manager or the Wazuh dashboard, as the last one, deletes the whole directory, ca/root-ca.key included. The Wazuh indexer never deletes credentials.env, so the directory remains. As the last one, it deletes the root CA files in ca/ if no other component's password is left in credentials.env. If you already removed credentials.env, as Securing your Wazuh installation recommends, it leaves ca/ as it is.

On the host that holds ca/root-ca.key, back up /etc/wazuh/ca before you uninstall the last Wazuh central component. You need the key to add nodes or renew certificates.

After you uninstall the last Wazuh central component on a host, check whether the directory remains with ls /etc/wazuh. If it is still there, remove it:

# rm -rf /etc/wazuh

Note

Don't run this command while a Wazuh central component is still installed on the host. Each component checks this directory every time it starts, and on the host where you created the certificates (the first Wazuh indexer node, or the host where you ran --generate-config-files), /etc/wazuh/ca holds the root CA private key you need to add nodes or renew certificates.

Removing the Wazuh repository

After you remove the last Wazuh central component from a host installed with the step-by-step method, and no Wazuh agent runs on it, remove the Wazuh repository, its key, and the cached packages:

# rm -f /etc/apt/sources.list.d/wazuh.list /usr/share/keyrings/wazuh.gpg /usr/share/keyrings/wazuh.gpg~
# apt-get clean
# apt-get update

After you remove every Wazuh central component from the host, check that none is left. On RPM-based systems, run rpm -qa 'wazuh-*'. On Debian-based systems, run dpkg -l 'wazuh-*'. No Wazuh central component package is listed.