You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The uninstall command for the Elastic Agent performs an action at the end of the installation process that spawns a cmd.exe that uses ping to wait 2 seconds and then delete the C:\Program Files\Elastic\Agent directory. This is done because uninstall is being executed from that directory and it cannot delete the directory that it is executing from (Windows does not allow it).
This type of process execution on Windows triggers a Cloud IOC alert. We should determine if its possible for this removal to be performed differently that doesn't trigger this type of alert.
Version: All
Operating System: Windows
The text was updated successfully, but these errors were encountered:
The
uninstall
command for the Elastic Agent performs an action at the end of the installation process that spawns acmd.exe
that uses ping to wait 2 seconds and then delete theC:\Program Files\Elastic\Agent
directory. This is done becauseuninstall
is being executed from that directory and it cannot delete the directory that it is executing from (Windows does not allow it).See the code here: https://github.com/elastic/elastic-agent/blob/main/internal/pkg/agent/install/uninstall.go#L143
This type of process execution on Windows triggers a Cloud IOC alert. We should determine if its possible for this removal to be performed differently that doesn't trigger this type of alert.
The text was updated successfully, but these errors were encountered: