This document describes an incompatibility between Cisco Secure Endpoint Linux connector versions 1.12.4 and earlier and Red Hat Enterprise Linux, CentOS, and Oracle Linux 7.8 (RHCK). On these platforms, the connector can appear to operate normally but does not detect File Rename and Network Events. Upgrade to connector version 1.12.5 or later to restore full event detection.
This issue applies to the following connector versions, operating systems, and kernel versions:
The affected connector versions are:
The affected operating systems are:
The affected kernel versions are:
On Red Hat Enterprise Linux, CentOS, and Oracle Linux 7.8 with kernel version 3.10.0-1127.el7.x86_64 or later, Cisco Secure Endpoint Linux connector versions 1.12.4 and earlier do not detect File Rename and Network Events.
Use the following symptoms to confirm the issue:
sudo cat /var/log/messages | grep "kernel: ampnetworkflow: <info> _msg_send_offset: peer disconnected"
Complete the following steps to confirm the issue, upgrade the connector, and confirm the fix:
From a terminal window, run the command uname -r.
uname -r The command returns 3.10.0-1127.el7.x86_64 or a later kernel version. If the command returns this version or later, continue to the next step.
sudo cat /var/log/messages | grep "kernel: ampnetworkflow: <info> _msg_send_offset: peer disconnected" Open the Cisco Secure Endpoint Linux Connector OS Compatibility documentation
Open the Cisco Secure Endpoint Linux Connector User Guide
| Revision | Publish Date | Comments |
|---|---|---|
2.0 |
17-Feb-2022
|
Added note on support for Oracle UEK |
1.0 |
15-May-2020
|
Initial Release |