FortiEDR
FortiEDR automates the protection against advanced threats, pre and post-execution, with real time orchestrated incident response functionality.
amoreno
Staff
Staff
Article Id 425027
Description This article describes the new behavior for the .nslo content file of FortiEDR Linux Collector version 5.1.14 and above versions. In environments where proxy configuration is enabled in FortiEDR Central Manager, it might cause an issue downloading the different Linux distributions' installation files.
Scope FortiEDR Central Manager, FortiEDR Linux collector.
Solution

Following the release of FortiEDR version 5.1.14 for Linux, an intentional change was introduced to minimize the size of the .nslo content file due to limitations of FortiEDR Central Manager. There are no negative side effects on the normal workflow, except for a two-hour delay before content loading begins.

 

Before version 5.1.14, the .nslo content file contained all the installation files for the various Linux distributions, making it quite large.

 

Starting with version 5.1.14, .nslo content files are smaller thanks to compression, and FortiEDR Central Manager will download the installation files for different Linux distributions from a Google Cloud bucket.

 

This new feature is only introduced for the FortiEDR Linux Collector .nslo installation file. The .nslo content files for Windows and macOS continue to behave as before.

 

Due to this new feature, if FortiEDR Central Manager has a proxy configured, mostly in on-premises FortiEDR deployments, there is a limitation on downloading installation files.

 

Similar errors can be found when analyzing FortiEDR Central Manager:

 

ERROR 1449 [pool-12-thread-1] --- c.e.w.s.persistence.RemoteShellService : Failed pulling remote shell Windows x64 updates from GCP bucket.

com.google.cloud.storage.StorageException: Error getting access token for service account: oauth2.googleapis.com

 

Starting from FortiEDR Central Manager build 6.2.6.0097 and running the latest patch, proxy limitations have been addressed.

 

As a workaround for previous FortiEDR Central Manager versions, raise a new ticket with TAC support asking for the required installation files.

 

Notes: