Skip to content

Commit b96487e

Browse files
committed
Update microsoft-defender-endpoint-linux.md
1 parent f55f4e9 commit b96487e

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

defender-endpoint/microsoft-defender-endpoint-linux.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -95,7 +95,7 @@ Microsoft Defender for Endpoint for Linux includes anti-malware and endpoint det
9595
> Support for Microsoft Defender for Endpoint on Linux for ARM64-based Linux devices is now in preview. For more information, see [Microsoft Defender for Endpoint on Linux for ARM64-based devices (preview)](mde-linux-arm.md).
9696
9797
> [!NOTE]
98-
> Distributions and versions that aren't explicitly listed are unsupported (even if they are derived from the officially supported distributions).
98+
> Distributions and versions that aren't explicitly listed are unsupported (even if they're derived from the officially supported distributions).
9999
> After a new package version is released, support for the previous two versions is reduced to technical support only. Versions older than that which are listed in this section are provided for technical upgrade support only.
100100
> Currently, Rocky and Alma distributions aren't supported in Microsoft Defender Vulnerability Management.
101101
> Microsoft Defender for Endpoint for all other supported distributions and versions is kernel-version agnostic. The minimal requirement for the kernel version to be `3.10.0-327` or later.
@@ -126,7 +126,7 @@ Microsoft Defender for Endpoint for Linux includes anti-malware and endpoint det
126126

127127
> [!NOTE]
128128
> Starting with version `101.24082.0004`, Defender for Endpoint on Linux no longer supports the `Auditd` event provider. We're transitioning completely to the more efficient eBPF technology.
129-
> If eBPF is not supported on your machines, or if there are specific requirements to remain on Auditd, and your machines are using Defender for Endpoint on Linux version `101.24072.0001` or lower, then Audit framework (`auditd`) must be enabled on your system.
129+
> If eBPF isn't supported on your machines, or if there are specific requirements to remain on Auditd, and your machines are using Defender for Endpoint on Linux version `101.24072.0001` or lower, then Audit framework (`auditd`) must be enabled on your system.
130130
> If you're using Auditd, then system events captured by rules added to `/etc/audit/rules.d/` adds to `audit.log`(s) and might affect host auditing and upstream collection. Events added by Microsoft Defender for Endpoint on Linux are tagged with the `mdatp` key.
131131
132132
- /opt/microsoft/mdatp/sbin/wdavdaemon requires executable permission. For more information, see "Ensure that the daemon has executable permission" in [Troubleshoot installation issues for Microsoft Defender for Endpoint on Linux](linux-support-install.md).

0 commit comments

Comments
 (0)