Self-registering agent

Agent self-registration omits manually acquiring token information from NOM UI as described in Manually registering agent. Instead, minimal configuration of the NOM server is provided to allow the agent to connect and register itself. Authorization is granted through mutual authentication.

A self-registering agent is useful in an automated environment such as a Kubernetes cluster of Neo4j instances where instances are dynamically created and managed.

Run agent

To run a self-registering agent, an additional command line option is provided as -s, short for --self-register.

Running as a service

To run an agent in service mode means that the agent process runs in the background and monitors the instance. The agent lifecycle is handled by the operating system service manager. Best practice is to run an agent in service mode.

Linux (systemd)

Service installation

agent service -s install

Setting arguments

Run the following to edit the service:

systemctl edit neo4j-ops-manager-agent.service

Set environment variables by either setting Environment or EnvironmentFile options. For example, using the Environment options, the override file can look like this:

Environment="CONFIG_SERVER_GRPC_ADDRESS=<server grpc address>"
Environment="CONFIG_SERVER_HTTP_ADDRESS=<server http address>"
Environment="CONFIG_INSTANCE_1_NAME=<instance name>"
Environment="CONFIG_INSTANCE_1_BOLT_URI=<bolt uri of the local instance>"
Environment="CONFIG_INSTANCE_1_BOLT_USERNAME=<local instance user name>"
Environment="CONFIG_INSTANCE_1_BOLT_PASSWORD=<local instance password>"
Environment="CONFIG_INSTANCE_1_QUERY_LOG_PORT=<an available port>"
Environment="CONFIG_INSTANCE_1_LOG_CONFIG_PATH=<path to server-logs.xml>"
Environment="CONFIG_TLS_CLIENT_CERT=<path to agent TLS cert>"
Environment="CONFIG_TLS_CLIENT_KEY=<path to agent TLS key>"

Please refer to the full list of options here.

Starting and stopping

To start the service:

systemctl start neo4j-ops-manager-agent.service

To stop the service:

systemctl stop neo4j-ops-manager-agent.service

Logs are available, using journalctl, via

journalctl -u neo4j-ops-manager-agent


Setting arguments

  • Open registry editor and navigate to HKLM\SYSTEM\CurrentControlSet\Services\neo4j-ops-manager-agent.

  • Create a key of type REG_MULTI_SZ named Environment and add your environment variables, each on a separate line, for example:

    CONFIG_SERVER_GRPC_ADDRESS=<server grpc address>
    CONFIG_SERVER_HTTP_ADDRESS=<server http address>
    CONFIG_INSTANCE_1_NAME=<instance name>
    CONFIG_INSTANCE_1_BOLT_URI=<bolt uri of the local instance>
    CONFIG_INSTANCE_1_BOLT_USERNAME=<local instance user name>
    CONFIG_INSTANCE_1_BOLT_PASSWORD=<local instance password>
    CONFIG_INSTANCE_1_QUERY_LOG_PORT=<an available port>
    CONFIG_INSTANCE_1_LOG_CONFIG_PATH=<path to server-logs.xml>
    CONFIG_TLS_CLIENT_CERT=<path to agent TLS cert>
    CONFIG_TLS_CLIENT_KEY=<path to agent TLS key>

Starting and stopping

To start the service:

agent service -s start

To uninstall the service:

agent service -s uninstall

Running as a console application

All configuration values for the agent should be set as environment variables before starting the agent.

agent console -s


agent console --self-register

Verify agent setup

Ensure agent has contacted NOM server, is online and is reporting DBMS(s) correctly.

  1. Return to Agents listing in global settings.

  2. Find self-registered agent in list.

    • If the agent is not in the list then go back to where the agent is running and check the logs. It may be that the server address is configured incorrectly or the TLS certificates are not correctly specified.

  3. Upon successful registration, the agent status changes to Offline until the agent receives token information and re-connects to NOM server.

  4. Wait for agent status to change to Online indicating that the agent has successfully re-connected to the NOM server. This can take a few minutes.

    agent approved online
  5. If the agent status is not Online then check for errors in server logs and agent logs respectively.

  6. Hover over the newly added agent and select "View Configuration" from the menu on the right to show agent configuration. Check configuration is as expected.

  7. Navigate to the home page (if this agent is the first to manage an instance in a DBMS, it may take a few minutes for the DBMS to appear).

  8. Select the Alerts tab and make sure that there are no alerts for any of the DBMSs managed by the new agent.

Agent configuration reference

Registration configuration

Variable Description Example


Server GRPC Address



Server HTTP address ( should include protocol scheme )



PEM encoded trusted CA list ()


Since agent-server communication needs to be encrypted, you need to configure the agent so that it trusts the server’s certificates. The file that contains the trusted certificate list (PEM encoded) can be specified through the CONFIG_TLS_TRUSTED_CERTS environment variable. Most operating systems default to the system-wide trusted certificates, but this is not the case on Windows. For this reason, you must set this environment variable on Windows.

Optional configuration to be used to specify the location for agent config file:

Variable Description Example Default


Persistent path to a file on Neo4j instance host


NEO4J_CONF if set or conf folder under NEO4J_HOME if set, else .nom folder in user home directory.

Agent config location must be of persistent type.

Agent meta-data can be optionally specified using these configuration parameters:

Variable Description Example


Optional name for agent to easily differentiate among self-registered agents



Optional description for agent to easily differentiate among self-registered agents

An agent to monitor home db

It’s recommended to set agent name and description if multiple agents are being self-registered on similar hosts as it would lead to confusion with similarly named agents appearing in UI.

Configuration for mutual authentication

The NOM server immediately authorizes an agent that registers using a trusted certificate.

The following configuration is required to enable mutual authentication:

Variable Description Example


PEM encoded Agent certificate for mutual TLS



PEM encoded Agent key for mutual TLS


In addition to the above configuration, the NOM server also needs to be configured to trust the agent certificates as described here. The client certificate set by CONFIG_TLS_CLIENT_CERT should be part of the GRPC_SERVER_SECURITY_TRUST_CERT_COLLECTION file.

Self-signed certificates for agents in test and demo environments can be generated as documented here. One agent certificate which is not tied to host IPs of agents can be used to configure multiple agents which will reduce the number of agent certificates to maintain.

Agent logging configuration

The following environment variables specify start configuration for the agent:

Variable Description Example


Log level (debug,info,warn,error)



Path to the log file


Monitored instance configuration

The following environment variables need to be set to allow the agent to access the instance.

If there is more than one DBMS being monitored by the same agent, repeat and enumerate the configuration of each DBMS by replacing the digit 1 below with 2, 3, and so on, for each instance. For example, name the first DBMS with CONFIG_INSTANCE_1_NAME, and the second with CONFIG_INSTANCE_2_NAME, and so on.

Variable Description Example


Name of first instance



Bolt URI for first instance with bolt or bolt+s protocol

bolt://localhost:7687 or bolt+s://localhost:7687 or bolt+ssc://localhost:7687, depending on the local database setup


Bolt username for first instance



Bolt password for first instance


The instance name that you specify for CONFIG_INSTANCE_n_NAME will be used to identify your instance in NOM. For this reason, it is important that you specify unique names across your cluster.

Query log collection configuration

Variable Description Example


Port for connecting the agent to the Neo4j log4j appender. If not set, the query log collection feature is treated as disabled.



Path to the instance log4j config file. If set, appends the appropriate log appender automatically (including the port specified above).



Minimum duration in milliseconds for a query to be logged (optional)



Enable filter for errors under the minimum duration in milliseconds (optional)



Disable the string literal obfuscation in queries (optional)



Collect and show queries coming from the NOM agent (optional)


Agents are supposed to monitor only local instances and should not be configured to connect to remote instances.

Refer to Neo4j instance requirements to ensure that all instances meet the requirements to be managed by NOM.