Supported platforms

Operating systems and versions the agent runs on, and the support tier each one gets.

Operating systems

PlatformArchitecturesInstall as
Windows 10 and 11x64Windows service
Windows Server 2016, 2019, 2022 and laterx64Windows service
Linux with systemd, kernel 5.8 or later recommendedamd64, arm64systemd unit

Hosts on other operating systems, including macOS, send their logs by syslog or Beats and are searched and detected on like any other source.

Support tiers

The support tier sets the capabilities available on each operating system version. It is reported per host on the Hosts page.

TierPlatformsWhat you get
AWindows 10 1809 and later, Windows Server 2019 and later; Linux kernel 5.8 and laterCollection, all response actions, isolation, application control, triage, self-update.
BWindows 10 1507 to 1803, Windows Server 2016; Linux with older kernelsCollection, response, isolation, triage and self-update, with a core telemetry set and core application control options.
CEarlier Windows releasesLog forwarding by syslog or Beats, with search and detection.

Prerequisites on the host

  • Local administrator (Windows) or root (Linux) to install.
  • Outbound HTTPS to the gateway hostname and outbound TLS to the ingest hostname.
  • For the fullest Windows coverage, Sysmon with the recommended configuration from the installer bundle.
  • For the fullest Linux coverage, auditd with the recommended rules from the installer bundle.

Virtual machines and templates

Install the agent after the machine has been cloned from a template, or run the enrolment step after cloning. Because the fleet identifier is issued by the server at enrolment, a template that already enrolled would hand every clone the same identity.