Deployment variables
Deployment variables configure the Wazuh agent while its package is installed. The enrollment token (WAZUH_ENROLLMENT_TOKEN) is the only variable that registers the Wazuh agent with the Wazuh manager. It carries the Wazuh manager address, the enrollment credential, and the pin of the certificate authority (CA) that the Wazuh agent trusts. The other variables set Wazuh agent options in the ossec.conf file.
The Wazuh agent packages for Linux, macOS, and Windows read the same variables. They are applied only during installation. Select your operating system to see how to pass them:
Variable |
Description |
Default |
|---|---|---|
|
The enrollment token created on the Wazuh manager with |
None. Without a token, the Wazuh agent is installed but not enrolled. |
|
Sets the Wazuh agent name ( |
The hostname of the endpoint |
|
Assigns the Wazuh agent to one or more groups at enrollment, separated by commas
( |
|
|
Sets how the Wazuh agent verifies the Wazuh manager certificate
( |
Not set. Token installations use
|
|
Sets the interval, in seconds, between keep-alive messages to the Wazuh manager
( |
|
|
Sets the time, in seconds, the Wazuh agent waits after enrolling before
connecting ( |
|
Note
Create the token with the address the Wazuh agents use to reach the Wazuh manager. See the Wazuh manager identity verification section for how to create tokens and for the --embed-ca option.