FortiSIEM Discussions
KarlH
Contributor II

6.7.9 Supervisor to push a 4.30 WindowsLogAgent - Process stops to soon

Hello.

 

Need more help please.. thank you as per usual

 

on 6.7.9 Supervisor

Dir

/opt/phoenix/WinAgentUpgrade/        shows these two files

/opt/phoenix/cache/installedimages/windowsagent/FSMLogAgent.exe
/opt/phoenix/WinAgentUpgrade/FSMLogAgent.exe
[root@orgsiem01 ~]# ls -al /opt/phoenix/WinAgentUpgrade/
total 12716
drwxrwxr-x 2 root admin 51 Mar 19 12:31 .
drwxr-xr-x 24 root root 4096 Mar 20 10:15 ..
-rw-rw-r-- 1 root admin 729488 Mar 19 12:31 AutoUpdate.exe
-rw-rw-r-- 1 root admin 12283104 Mar 19 12:31 FSMLogAgent.exe

 

am I missing a xml file or dont we use that here?

I need details for

What are the owner  permissions are  in terms of chown and chmod. 

When I hit the download button  in agent health inside the SIEM GUI  it comes back within 1 or 2 sec.  way to fast.   What might be the issue ?

I need to remotely upgrade agents from 4.1 to 4.3 ?  

Is there anything on the endpoint hosting the agent I should check ? 

 

I found when I could not push a collector upgrade to the collector the /opt/upgrade dir did not have proper permissions or wasn’t even created.

 

Will the agent upgrade  manage that?

 

Thank you in advance!

Karl Henning, Security Engineer, CISSP
Karl Henning, Security Engineer, CISSP
0 REPLIES 0