Just like the server installation most of the agent OSSEC processes chroot themselves to /var/ossec. Unlike the server version, an agent installation does not store as many logs. The main logs are /var/ossec/logs/ossec.log and /var/ossec/logs/active-responses.log if you are using active response. Be sure to allow ample space for these log files.
In the following steps actions performed on the agent will be in the red putty windows, and actions on the server will be in the black backgrounded windows.
Refer to managing_agents for instructions on adding an agent to an OSSEC server.