Regarding new video "Collecting Endpoint Logs with Elastic Agent", when we edit the "endpoints initial" agent policy, is agent installer in Security onion "Downloads" section updated? #12461
-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU12 RAM32 Storage for /400 GB Storage for /nsm400 GB Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI want to update initial installer in Downloads section of Security onion to ignore some less important event IDs for Windows machines. I know how to do that, but when I save that changes to "endpoints-initial" agent policy, will the changes reflect in the installer available in the Security Onion Downloads section? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
The elastic agent will pull updates from the fleet server. So there is no need to update the elastic agent installer. When you deploy your elastic agents and then update the policy for those agents you will see their status change to 'updating' eventually returning back to 'healthy' once the policy has been updated. |
Beta Was this translation helpful? Give feedback.
The elastic agent will pull updates from the fleet server. So there is no need to update the elastic agent installer. When you deploy your elastic agents and then update the policy for those agents you will see their status change to 'updating' eventually returning back to 'healthy' once the policy has been updated.