Skip to content

Commit 3ecfc66

Browse files
authored
Update linux-support-rhel.md
No Talpa - it was only for RHEL 6. Auditd also is removed now
1 parent 1e34e38 commit 3ecfc66

File tree

1 file changed

+0
-53
lines changed

1 file changed

+0
-53
lines changed

defender-endpoint/linux-support-rhel.md

Lines changed: 0 additions & 53 deletions
Original file line numberDiff line numberDiff line change
@@ -71,58 +71,6 @@ Use the following command to get the kernel version:
7171
```bash
7272
uname -r
7373
```
74-
## Check if mdatp audisp process is running
75-
The expected output is that the process is running.
76-
77-
Use the following command to check:
78-
79-
```bash
80-
pidof mdatp_audisp_plugin
81-
```
82-
83-
## Check TALPA modules
84-
There should be nine modules loaded.
85-
86-
Use the following command to check:
87-
88-
```bash
89-
lsmod | grep talpa
90-
```
91-
92-
Expected output: Enabled
93-
94-
```bash
95-
talpa_pedconnector 878 0
96-
97-
talpa_pedevice 5189 2 talpa_pedconnector
98-
99-
talpa_vfshook 32300 1
100-
101-
talpa_vcdevice 4947 1
102-
103-
talpa_syscall 9127 0
104-
105-
talpa_core 90699 4 talpa_vfshook,talpa_vcdevice,talpa_syscall
106-
107-
talpa_linux 29424 5 talpa_vfshook,talpa_vcdevice,talpa_syscall,talpa_core
108-
109-
talpa_syscallhookprobe 882 0
110-
111-
talpa_syscallhook 14987 2 talpa_vfshook,talpa_syscallhookprobe
112-
```
113-
114-
115-
```bash
116-
lsmod | grep talpa | wc -l
117-
```
118-
119-
Expected output: 9
120-
121-
## Check TALPA status
122-
123-
```bash
124-
cat /proc/sys/talpa/interceptors/VFSHookInterceptor/status
125-
```
12674

12775
Debug log files (apart from the 'mdatp diagnostic create' bundle)
12876

@@ -133,7 +81,6 @@ Debug log files (apart from the 'mdatp diagnostic create' bundle)
13381

13482
semanage fcontext -l > selinux.log
13583
```
136-
13784

13885
Performance and Memory
13986

0 commit comments

Comments
 (0)