Logo
Resources
Documentation Portal Ideas Portal guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal guardsix Academy License Portal
Sign in
  1. guardsix Service Desk
  2. Products Hub
  3. AgentX

AgentXKB

Avatar Prasuna Dahal
April 22, 2026 07:28
Follow
AgentXKB comprises knowledge base components including compiled normalizers, dashboards and search templates. It offers compiled normalizers for both Linux and Windows systems, along with dashboards for monitoring and compliance purposes such as Endpoint Compliance, File Integrity Management and Security Configuration Assessment. The search templates for AgentX and Browser Extension Investigation make it a comprehensive solution for security monitoring and analysis.

Release Details

Version: v1.6.0
Release date: April 22, 2026
Supported On: Logpoint v7.1.0 and later
SHA 256: bdf822ed84bb74f5d95d2817d12c01ff8fbbb4926d836afbe11c4a0b389eb85a
Download

Bug Fixes

PLUG-17658
When onboarding OSQuery logs with AgentX, some OSQuery events were parsed inconsistently for the same event type.
PLUG-17387
In AgentX Windows and AgentX Unix logs, raw log entries containing non-ASCII characters were displayed as escaped Unicode sequences.
PLUG-17369
File path values in AgentX Unix logs were captured incorrectly, with missing leading / characters or additional escaped sequences.

Past Releases

AgentXKB v1.5.1 ▾
Version: 1.5.1
Release date: January 9, 2026
Supported On: Logpoint v7.1.0 and later
SHA 256: 91abfec7fdb2197242c78e80d466cee723475cb2240bba1117d4a6c23c48ed8b
Download

Enhancement

Minor bug fixes and enhancements.

AgentXKB v1.5.0 ▾
Version: v1.5.0
Release date: August 15, 2025
Supported On: Logpoint v7.1.0 and later
SHA 256: 6827e22e0bc2952b11e607640c3ad79e07eaeb45c0c6ab116ec2603d1f073c0a
Download

Enhancement

PLUG-15965

AgentXWindowsCompiledNormalizer now supports normalization of SMS Passcode logs.

Bug Fixes

PLUG-13229
Raw logs were displayed in search results because AgentXUnixCompiledNormalizer did not normalize Unix logs.
PLUG-15771
The Caller Computer Name field in Windows Event ID 4740 was not normalized as Workstation, preventing alerts from being triggered.
PLUG-16411
AgentX did not apply the date and time configured in CNDP to Windows logs, resulting in incorrect timestamps.
PLUG-16536
AgentXWindowsCompiledNormalizer did not display search results due to an incorrect double quote in the value of the Reason field.
AgentXKB v1.4.2 ▾
Version: v1.4.2
Release date: December 2, 2024
Supported On: Logpoint v7.1.0 and later
SHA 256: df6d32345afcbe62f640b1c4649bbdc4271997656a74454381691bc6d9709a72
Download

Enhancements

KB-24371, KB-23336
The mapping of the following fields is updated:

 

  • eventdata{product Name} to product 
  • eventdata{product Version} to product_version
  • eventdata_new_value to new_value
  • eventdata_old_value to old_value

The event id for these fields is 5007 and the normalizer is "AgentXWindowsCompiledNormalizer". 

 

KB-24576
The fields eventdata_access_granted and eventdata_access_removed are now mapped to the privilege field.
KB-24615

The taxonomy of normalized fields is updated for AgentX Windows Security Audit.

  • eventdata_new_target_user_name → new_user

  • eventdata_old_target_user_name → target_user

  • eventdata_home_directory → home_directory

  • eventdata_home_path → home_path

  • eventdata_profile_path → path

  • eventdata_script_path → script_path

  • eventdata_user_parameters → parameter

  • eventdata_user_workstations → workstation

PLUG-13149 , KB-24600

The taxonomy of normalized fields is updated for AgentXWindowsCompiledNormalizer.

  • eventdata_nASIPv4Address → nas_ipv4_address

  • eventdata_clientIPAddress → client_address

  • eventdata_nASPortType → nas_port_type

  • eventdata_eAPType → eap_type

  • eventdata_nASIdentifier → nas_identifier

  • eventdata_nASPort → nas_port

  • log_file_cleared_client_process_id → process_id

  • log_file_cleared_client_process_start_key → process_start_key

  • log_file_cleared_subject_logon_id -> logon_id

Bug Fixes

KB-23336
In event_id 5007, “//” in paths was not parsed properly.
KB-23905
The fields user, user_id and caller_user_id were not properly normalized by AgentXUnixCompiledNormalizer.
KB-24539
For event_id 7000, eventdata fields were not normalized, resulting in the event source name not being collected.
KB-24612
For event_id 4656, file related events didn’t have labels, resulting in collecting logs without human-readable values.
KB-22296
In Oracle DB (Windows), specific fields like user, action, RETCODE, and OBJName were not normalized.
KB-21548
 Event logs from MS Exchange were not normalized correctly.
KB-21548
 Logs from Ubuntu were not normalized correctly.
PLUG-13223
When the UNIX template was improperly configured, AgentX UNIX logs were not normalized.

Support

If you have any questions or require assistance, create a support ticket.

Comments

Article is closed for comments.

Related articles

  • AgentX Server
  • AgentX Windows Installer
  • Logpoint Agent (Centralized)
  • Universal Normalizer
Was this article helpful?
0 out of 0 found this helpful
Privacy policy    EULA    Terms of service   
Copyright © , guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.