sekoia enpoint agent revamp - #3154
Conversation
Updated the Sekoia.io Endpoint Agent documentation for clarity and consistency. Adjusted headings, improved descriptions, and corrected formatting issues.
Removed shared content placeholders and added new references for events and detection rules.
|
NB: Preview is KO beacause some links are not working yet: |
|
|
||
| If you contact Sekoia support, include the following information: | ||
|
|
||
| 1. The full stack trace from the failed setup request, along with your machine configuration. |
There was a problem hiding this comment.
Should we suggest a PCAP or it's better to stay vague with the full stack trace ?
|
|
||
| 1. The full stack trace from the failed setup request, along with your machine configuration. | ||
| 2. The agent log file. | ||
|
|
There was a problem hiding this comment.
- The OS and OS version the agent is installed on
|
|
||
| * Whether the intake key is still valid. | ||
| * Whether the community's subscription is still active. | ||
|
|
There was a problem hiding this comment.
one other very common error is when auditd is not stopped (only for linux) then they don't manage to start the agent
https://github.com/SEKOIA-IO/documentation/pull/3154/changes#diff-e750b7ed9375122fbdb08d5d8943132db596574db2996bdf125d77e8274727b6R43
pbivic
left a comment
There was a problem hiding this comment.
I leaved comments on the troubleshoot part
|
Preview is not working :/ the documentation needs to be fixed |
@mchupeau-sk I know cf : #3154 (comment) ;) |
| - Install: integration/categories/endpoint/install_sekoia_endpoint_agent.md | ||
| - Configure: integration/categories/endpoint/configure_sekoia_endpoint_agent.md | ||
| - Update and uninstall: integration/categories/endpoint/update_uninstall_sekoia_endpoint_agent.md | ||
| - Reduce event volume: integration/categories/endpoint/reduce_event_volume_endpoint_agent.md |
There was a problem hiding this comment.
Page reduce_event_volume_endpoint_agent is unavailable
if it's in another PR, you should add it afterwards
|
Thanks for the PR! :) |
Full revamp of the endpoint article mostly slicing to respect diataxis and make it more readable/actionnable