You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/linux-whatsnew.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ ms.author: deniseb
6
6
author: denisebmsft
7
7
ms.reviewer: kumasumit, gopkr
8
8
ms.localizationpriority: medium
9
-
ms.date: 09/20/2024
9
+
ms.date: 10/11/2024
10
10
manager: deniseb
11
11
audience: ITPro
12
12
ms.collection:
@@ -25,8 +25,8 @@ search.appverid: met150
25
25
26
26
**Applies to:**
27
27
28
-
-[Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
29
-
-[Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
28
+
- Microsoft Defender for Servers
29
+
- Microsoft Defender XDR
30
30
31
31
This article is updated frequently to let you know what's new in the latest releases of Microsoft Defender for Endpoint on Linux.
32
32
@@ -36,9 +36,9 @@ This article is updated frequently to let you know what's new in the latest rele
36
36
> [!IMPORTANT]
37
37
> Starting with version `101.2408.0000`, Microsoft defender for Endpoint for Linux no longer supports the Auditd event provider. We're transitioning completely to the more efficient eBPF technology. This change allows for better performance, reduced resource consumption, and overall improved stability. eBPF support has been available since August 2023 and is fully integrated into all updates of Defender for Endpoint on Linux (version `101.23082.0006` and later). We strongly encourage you to adopt the eBPF build, as it provides significant enhancements over Auditd. If eBPF is not supported on your machines, or if there are specific requirements to remain on Auditd, you have the following options:
38
38
>
39
-
> 1.Continue to use Defender for Endpoint on Linux build `101.24072.0000` with Auditd. This build will continue to be supported for several months, so you have time to plan and execute your migration to eBPF.
39
+
> 1.Continue to use Defender for Endpoint on Linux build `101.24072.0000` with Auditd. This build will continue to be supported for several months, so you have time to plan and execute your migration to eBPF.
40
40
>
41
-
> 2.If you are on versions later than `101.24072.0000`, Defender for Endpoint on Linux relies on `netlink` as a backup supplementary event provider. In the event of a fallback, all process operations continue to flow seamlessly.
41
+
> 2.If you are on versions later than `101.24072.0000`, Defender for Endpoint on Linux relies on `netlink` as a backup supplementary event provider. In the event of a fallback, all process operations continue to flow seamlessly.
42
42
>
43
43
> Review your current Defender for Endpoint on Linux deployment, and begin planning your migration to the eBPF-supported build. For more information on eBPF and how it works, see [Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux](/defender-endpoint/linux-support-ebpf).
0 commit comments