Operating systems
| Platform | Architectures | Install as |
|---|---|---|
| Windows 10 and 11 | x64 | Windows service |
| Windows Server 2016, 2019, 2022 and later | x64 | Windows service |
| Linux with systemd, kernel 5.8 or later recommended | amd64, arm64 | systemd unit |
Hosts on other operating systems, including macOS, send their logs by syslog or Beats and are searched and detected on like any other source.
Support tiers
The support tier sets the capabilities available on each operating system version. It is reported per host on the Hosts page.
| Tier | Platforms | What you get |
|---|---|---|
| A | Windows 10 1809 and later, Windows Server 2019 and later; Linux kernel 5.8 and later | Collection, all response actions, isolation, application control, triage, self-update. |
| B | Windows 10 1507 to 1803, Windows Server 2016; Linux with older kernels | Collection, response, isolation, triage and self-update, with a core telemetry set and core application control options. |
| C | Earlier Windows releases | Log forwarding by syslog or Beats, with search and detection. |
Prerequisites on the host
- Local administrator (Windows) or root (Linux) to install.
- Outbound HTTPS to the gateway hostname and outbound TLS to the ingest hostname.
- For the fullest Windows coverage, Sysmon with the recommended configuration from the installer bundle.
- For the fullest Linux coverage, auditd with the recommended rules from the installer bundle.
Virtual machines and templates
Install the agent after the machine has been cloned from a template, or run the enrolment step after cloning. Because the fleet identifier is issued by the server at enrolment, a template that already enrolled would hand every clone the same identity.