You’ll need to install a Cloud Agent that’s been activated for EDR on each asset you want to monitor for suspicious activity.
If you are new EDR customer, you must first download and install the default EDR key. For more information, see Download Cloud Agent.
If you are an existing customer, you can either:
- Select the existing activation key and upgrade the associated agents for EDR. For more information, see Upgrade existing Agents.
- Install new Cloud Agent and activate the agent for EDR. For more information see, Install Cloud Agent.
Note: You must upgrade to Cloud Agent version 4.1 and above to utilize all the EDR functionality.
From the EDR welcome page, click Download Cloud Agent.
Click on Windows.exe from the Download and Install Cloud Agent page.
From the Installation Instructions page, download the agent installer and copy it to the host machine.
Copy and run the Installation Command on the Host.
After you have successfully downloaded and installed the Default installation key and want to install more activation keys, see Install Cloud Agent.
From EDR welcome page, click Configure Agents for EDR.
On the Configure Agents for EDR window, you can:
- Select the existing activation key and upgrade the associated agents for EDR.
- Install new Cloud Agent and activate the agent for EDR.
From the Configure Agents for EDR window, select one or multiple Activation Key and click Upgrade
On the confirmation window, click Upgrade to initiate the process. All the agents associated with the activation key will be upgraded and enabled for EDR.
Our revolutionary cloud platform gives you continuous security updates through the cloud using lightweight cloud agents. Go to the Cloud Agent (CA) app to install agents and activate them for EDR. It's possible to activate existing agents for EDR with other capabilities like VM and PC.
1. From the Configure Agents for EDR window, click Manage Cloud Agent Keys. You will be re-directed to the Cloud Agent app. |
|
2. Click Agent Management > Activation Keys > New Key. Give it a title and provision for the EDR application and click Generate. As you see you can provision the same key for any of the other applications in your account. |
|
4. Click on Install Instructions against Windows (.exe). |
|
5. Review the installation requirements and click Download. You'll run the installer on each host from an elevated command prompt, or use a systems management tool or Windows group policy. Your agents should start connecting to our cloud platform. |
|
6. Activate your agents for EDR. Go to the Agents tab and choose an agent and "Activate for FIM or EDR or PM or SA" from the Quick Actions menu. (Bulk activation is supported using the Actions menu). |
|
7. Enable EDR in a CA configuration profile. Toggle Enable EDR module for this profile to ON. This is required for EDR data collection. Configure what EDR artifacts are transmitted to the Qualys Cloud Platform. Defaults are provided as shown, so this step is optional. You can configure values for max event log size, payload threshold time, and maximum disk usage for EDR data. Toggle a configuration setting to ON before you using it. You must set at least one configuration setting to ON if you have enabled EDR for this profile.
You're ready! Select EDR from the app picker, navigate to your Dashboard and start investigating and remediating EDR incidents and events.
|