Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issues with installing & running CEF collector on Linux machine #563

Closed
lancepreston opened this issue Apr 2, 2020 · 4 comments
Closed
Assignees

Comments

@lancepreston
Copy link

Describe the bug
Installation is semi-successful, in that many packages are installed, but receive several errors indicating "no such file" or "permission denied". Installation completes with "Omsagent restarted successfully" and "Installation completed", and returns a successful return code of 0 (zero).

To Reproduce
Steps to reproduce the behavior:

  1. execute installation command:
    # wget https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/CEF/cef_installer.py&&sudo python cef_installer.py <workspace id> <secret key>

  2. errors produced
    image

  3. yet those directories are created with appropriate ownership and permissions:
    image

  4. services do not start successfully following install
    image

Expected behavior
Log agent installed successfully & sending syslog messages to Azure

Additional context
Red Hat Enterprise Linux Server release 7.7
have applied CIS benchmark: CIS_Red_Hat_Enterprise_Linux_7_v2.1.0 (level 1)

*See attached text file containing full installation output and errors
CEF Installer errors.txt

@preetikr
Copy link
Contributor

preetikr commented Apr 2, 2020

@lancepreston - Please file a support ticket with the repro you have for getting unblocked on this issue. Refer to https://azure.microsoft.com/en-us/support/options/ for filing a support ticket.

@lancepreston
Copy link
Author

Support ticket #120032424003253 was opened on 3/24/20

@preetikr
Copy link
Contributor

preetikr commented Apr 2, 2020

Thanks @lancepreston - We'll investigate this and get back.

@morshabi
Copy link
Contributor

Hi, this issue was answered via direct ICM to the Azure Sentinel team. To summarize the response, OMSAgent doesn't support hardening with CIS. We are working on fixing the issue with CIS but we don't have ETA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants