Workload security
Monitor a Linux host with Runtime Security
Register a runtime agent, install it on Linux, verify process/file/network telemetry, and investigate runtime findings.
Reviewed
Before you start
The current runtime agent supports Linux amd64 and arm64. Have permission to install the agent and access the generated credential.
Register the runtime agent
Open Runtime Security → Add Runtime Security Agent. Enter Agent Name, optionally Environment and Hostname, then select the Cloud Account used to attribute findings. Choose Linux and the host architecture.
Store the credential and install
Copy Agent Credential when it is shown. Follow the generated Install instructions on the target host. Replace the credential placeholder with your one-time value and use the deployment’s API URL. The app also provides Docker and build-from-source alternatives for appropriate environments.
Verify heartbeat and event delivery
Use Check status and logs. Look for connected: heartbeat accepted and sent-event messages. In Agent Detail, review Last Seen, Agent Version, Last Event, and Recent Events.
Investigate runtime findings
Use Investigate findings or the agent’s Findings view. Review the event context and resource identity before deciding whether activity is expected. Threat Intelligence can provide context for correlated URL and IP indicators.
Manage the agent lifecycle
Credential rotation immediately invalidates the current credential until the agent is updated and restarted. Revoking an agent permanently prevents that agent from authenticating; its events, findings, and audit trail remain. Read the confirmation before revoking.
Where you are now
A Linux agent reports runtime telemetry and you can connect runtime findings to the host and event context.
WHEN SOMETHING LOOKS OFF
A few things to check
No process telemetry
Check the agent was registered for Runtime Security. A credential cannot grant a capability absent from its registration.
Windows or macOS host
The current interface states these host operating systems are not supported by the runtime agent.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.