Arctic Wolf Agent Installation on a Single Endpoint

Updated Jul 31, 2023

Arctic Wolf Agent installation on a single endpoint

Arctic Wolf® Agent is an endpoint security management tool that functions as a component of the following solutions:

You can install a single instance of Arctic Wolf Agent on Windows, macOS, or Linux.

Tip: To perform a bulk installation of Agent, see Agent installation options

Requirements

Supported operating systems

System requirements

Networking requirements

Download the Agent installer

  1. In the Arctic Wolf Portal, click Accounts > Downloads.

  2. Under Endpoint Agent, select the desired Operating System option.

  3. Click Download Agent.

  4. Extract the Arctic Wolf Agent .zip contents into the same folder. These contents vary depending on operating system, including:

    • Windows — The .msi file and the customer.json file.
    • macOS — The .pkg file and the customer.json file.
    • Linux — The arcticwolfagent_<version>.<deb|rpm> package file and the customer.json file.

    Caution:

    • Do not make any edits to the customer.json file. Editing this file causes installation errors.
    • Do not save the Agent installer or customer.json to publicly accessible storage. customer.json should be kept confidential.

Install Agent on Windows or macOS

  1. Right-click the installation file for your operating system:

    • Windows — .msi
    • macOS — .pkg
  2. Click Run to run the installation.

  3. Follow the prompts to proceed with the installation.

  4. Contact your Arctic Wolf Customer Success Manager or your Concierge Security® Team to confirm that Agent data is reaching Arctic Wolf.

Install Agent on Linux

  1. Run the command appropriate for your operating system:

    • Ubuntu:

      sudo DEBIAN_FRONTEND=noninteractive AWN_CUSTOMER_JSON=/tmp/customer.json apt install ./arcticwolfagent_<version>.deb
    • Redhat, CentOS, or Amazon Linux:

      sudo AWN_CUSTOMER_JSON=/tmp/customer.json yum install arcticwolfagent_<version>.rpm

    Note: Ensure that the customer.json path is specified correctly. If you receive any errors pertaining to the customer.json file, see Troubleshooting Arctic Wolf Agent on Linux.

  2. Contact your Arctic Wolf Customer Success Manager or your Concierge Security® Team to confirm that Agent data is reaching Arctic Wolf.

Uninstall an individual Agent client

Note: When Arctic Wolf Agent is uninstalled, devices and associated risks are removed from the Arctic Wolf Portal and Risk Dashboard.

Uninstall Agent on Windows

  1. Open Control Panel and click Programs and Features.

  2. Locate the Agent application in the list.

  3. Click on the application in the list, and then click Uninstall.

  4. Follow the prompts to proceed with the uninstallation.

Uninstall Agent on macOS

  1. Open the terminal.
  2. Run this command to uninstall Agent:
    sudo ~/Library/ArcticWolfNetworks/Agent/uninstall.sh

Uninstall Agent on Linux

  1. Run the appropriate command for your operating system:

    • Ubuntu:

      sudo apt remove arcticwolfagent
    • RedHat, CentOS, or Amazon Linux:

      sudo yum remove arcticwolfagent
  2. (Optional) If you are not reinstalling Agent, remove the /var/arcticwolfnetworks/agent folder from your device.

Agent deactivation

You can deactivate Agents by removing them from the Endpoints table in the Arctic Wolf Portal. We recommend uninstalling Agents before deactivating them. If you deactivate an Agent that is still installed on a system, the endpoint reappears in the Endpoints table the next time that it is Online.

Deactivating an endpoint does not delete existing data from Arctic Wolf internal databases.

Contained Agent deactivation

You are not required to deactivate Agents if they are contained. We recommend keeping Agents in the Endpoints table until the containment incident is resolved.

You can remove contained endpoints from the Endpoints table once the incident is resolved and the Agent is uninstalled from the device.

Tip: You can only remove endpoints that have not checked in for 72 hours.

Automatic Agent deactivation and activation

Any devices that were not Online for 90 days are automatically removed from the Endpoints table. The endpoint automatically reappears in the table the next time that Agent detects it as Online.

Deactivate an Agent

If you are a Managed Risk (MR) customer, you can deactivate devices in the Arctic Wolf Portal. If you cannot access the Arctic Wolf Portal, contact your Concierge Security Team (CST).

Note: You cannot make these changes in the Risk Dashboard.

  1. Confirm that the Agent is uninstalled from the device.

  2. On the Arctic Wolf Portal, click Endpoint Status.

  3. In the Endpoints table, click Remove offline endpoint on the appropriate device.

    Tip: You can only remove devices that are Offline. The Agent only identifies devices as Offline if the Agent did not check in with them for 72 hours.

  4. In the dialog, click Remove Endpoint.

    Note: If you accidentally remove an endpoint, the endpoint automatically reappears in the table the next time that Agent detects it as Online.