Install Arctic Wolf Agent on a single Linux endpoint
You can install Arctic Wolf® Agent on a single Linux endpoint using the command line.
-
Agent is designed to maintain a minimal footprint on all systems, but Arctic Wolf recommends some OS requirements. Arctic Wolf cannot guarantee functionality on virtual machine (VM) environments if resources do not meet recommended levels.
-
Agent is not supported on Linux ARM-based systems. Only x64 platforms are supported.
To install Agent on multiple Linux endpoints, see Install Arctic Wolf Agent on multiple Linux endpoints.
These resources are required:
- To correctly view Agent risks in the Unified Portal, Linux Agent version 2024.02.84 or later is required
-
Administrator permissions or the ability to do administrator or root level functions
- A supported Linux distribution. For more information, see Agent support for Linux.
-
The minimum system resources. For more information, see Agent hardware requirements.
- Routing using IPv4 or IPv6
Note: IPv4 or IPv6 must be enabled to ensure containment functions as expected.
These actions are required:
- If the Linux distribution is Debian, make sure that
sudois installed on the root account. -
Make sure outbound access is available for ports 443 and 1514.
Configure your environment firewall
Configure your firewall to allow traffic to Agent DNS hostnames.
Add Agent processes to the allowlist
If you install Agent and an antivirus, endpoint scanner, Endpoint Detection and Response (EDR) solution, Unified Threat Management (UTM) solution, or similar software, add Agent processes to the allowlist in those applications to maintain stable CPU and memory utilization: