Skip to content

sekoia enpoint agent revamp - #3154

Open
alexane-bougeardbebin-sekoia wants to merge 12 commits into
mainfrom
sekoia-endpoint-agent-revamp
Open

sekoia enpoint agent revamp#3154
alexane-bougeardbebin-sekoia wants to merge 12 commits into
mainfrom
sekoia-endpoint-agent-revamp

Conversation

@alexane-bougeardbebin-sekoia

@alexane-bougeardbebin-sekoia alexane-bougeardbebin-sekoia commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Full revamp of the endpoint article mostly slicing to respect diataxis and make it more readable/actionnable

Updated the Sekoia.io Endpoint Agent documentation for clarity and consistency. Adjusted headings, improved descriptions, and corrected formatting issues.
Removed shared content placeholders and added new references for events and detection rules.
@alexane-bougeardbebin-sekoia alexane-bougeardbebin-sekoia changed the title Add files via upload sekoia enpoint agent revamp Aug 4, 2026
@alexane-bougeardbebin-sekoia

alexane-bougeardbebin-sekoia commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

NB: Preview is KO beacause some links are not working yet: /integration/categories/endpoint/reduce_event_volume_endpoint_agent.md = part of the optimization rule PR


If you contact Sekoia support, include the following information:

1. The full stack trace from the failed setup request, along with your machine configuration.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we suggest a PCAP or it's better to stay vague with the full stack trace ?


1. The full stack trace from the failed setup request, along with your machine configuration.
2. The agent log file.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  1. The OS and OS version the agent is installed on


* Whether the intake key is still valid.
* Whether the community's subscription is still active.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

one other very common error is when auditd is not stopped (only for linux) then they don't manage to start the agent
https://github.com/SEKOIA-IO/documentation/pull/3154/changes#diff-e750b7ed9375122fbdb08d5d8943132db596574db2996bdf125d77e8274727b6R43

@pbivic pbivic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I leaved comments on the troubleshoot part

@mchupeau-sk

Copy link
Copy Markdown
Contributor

Preview is not working :/ the documentation needs to be fixed

@alexane-bougeardbebin-sekoia

Copy link
Copy Markdown
Contributor Author

Preview is not working :/ the documentation needs to be fixed

@mchupeau-sk I know cf : #3154 (comment) ;)

Comment thread mkdocs.yml
- Install: integration/categories/endpoint/install_sekoia_endpoint_agent.md
- Configure: integration/categories/endpoint/configure_sekoia_endpoint_agent.md
- Update and uninstall: integration/categories/endpoint/update_uninstall_sekoia_endpoint_agent.md
- Reduce event volume: integration/categories/endpoint/reduce_event_volume_endpoint_agent.md

@goudyj goudyj Aug 7, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Page reduce_event_volume_endpoint_agent is unavailable
if it's in another PR, you should add it afterwards

@goudyj

goudyj commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Thanks for the PR! :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants