AgentX Windows Installer
Windows Installer is a lightweight application designed to install AgentX for Windows-based systems that enables the forwarding of logs and telemetry toward Logpoint. It has the ability to gather low-level system information from osquery, interrogate endpoints and perform additional investigation and response.
Release Details
Enhancement
AgentX Windows Installer now uses Wazuh version 4.14.4. This upgrade improves stability and performance, includes the latest security and vulnerability fixes, and provides access to newer Wazuh capabilities for a more secure and reliable customer experience.
Past Releases
Windows Installer v1.7.0 ▾
Enhancement
Windows Installer v1.5.0 ▾
Bug Fixes
CVE-2023-42463, CVE-2023-50260, CVE-2022-40497
Key Information:
- Don't change the Osquery path while installing AgentX Client as it causes a path not recognized error and interrupts installation. Go here to learn more about this issue.
- AgentX Client installation may occasionally pause and display a command prompt. In this case, press Enter to continue the installation.
- AgentX no longer provides active support and maintenance for AgentX Windows Installer versions older than v1.2.2.
Windows Installer v1.4.2 ▾
Enhancement
AgentX has added the default_minimal_windows template, which allows you to collect the following logs from Windows:
- System
- Application
- Security
- active-response
- osquery
Bug Fixes
Key Information:
- AgentX Cluster can only be configured on a Distributed Logpoint set up using an IP address.
- When using AgentX, keep the IP address as the Logpoint server alias in System Settings. Don’t modify it. If you do, an "AgentX server is down" error is triggered when adding a device in AgentX.
If there are multiple network interfaces, AgentX configuration is applied only to the primary interface. To implement the configuration on the secondary interface, your network administrator must configure it within your routing protocol.
- Downgrading AgentX Server from v1.4.2 to v1.2.0 after installing AgentX Manager v1.4.5 may cause log loss and is not recommended. If a downgrade is necessary, contact support.
- If you are using AgentX in distributed mode, then upgrading it from previous versions to v1.4.5 will break the connection between all nodes in the distributed architecture, stopping log transmission across the entire setup. The workaround can be found here.
- AgentX Manager v1.2.1 is not compatible with AgentX Server v1.4.2. Go to version compatibility matrix for more information.
- When upgrading the AgentX Server, please note that the new version may take some time to reflect due to its file size exceeding 500MB
- The installation of Windows Installer v1.4.2 might take more than one minute.
- Find the known issues for AgentX here.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.