Skip to main content
This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone product separate from Palo Alto Networks Cortex XCOR.
This feature isn’t available to all Palo Alto Networks Telemetry Pipeline users. For more information, contact Cortex XCOR Support.
In Palo Alto Networks Telemetry Pipeline, you can use fleets to manage instances of Core Agent. Use this guide to install Core Agent on RHEL-based Linux distributions.

Supported environments

Core Agent supports the following RHEL-based distributions and architectures:

Dependencies

For RHEL-based installations, Core Agent has the following general dependencies:
  • libc
  • libsasl
  • libsystemd
  • libyaml
  • OpenSSL
  • zlib
To retrieve a list of specific dependencies for your environment, run the following command:
Replace PACKAGE with the name of the Core Agent package.

Single line install

Palo Alto Networks Telemetry Pipeline provides a basic installation script that’s compatible with most Linux environments. This script always installs the most recent version of Core Agent.
However, for secure deployments, Palo Alto Networks Telemetry Pipeline recommends following the full instruction procedures for your Linux environment.

Mirrors for old CentOS versions

Because CentOS 6, CentOS 7, and CentOS 8 have reached end-of-life, their default yum repositories are unavailable. To install Core Agent on any of these distributions, you must configure an appropriate mirror. For example:

Verify signatures

Core Agent packages are signed with calyptia.key. You can use rpm to verify these signatures.
Replace PACKAGE with the name of the Core Agent package.

Configure yum

Palo Alto Networks Telemetry Pipeline provides the calyptia-fluent-bit package through a yum repository. To add the repository reference to your environment, add a new file in /etc/yum.repos.d/ with the following content:
Replace DISTRO with either amazonlinux or package-centos, and replace VERSION with the relevant version number.
As a security best practice, enable gpgcheck and repo_gpgcheck. Cortex XCOR signs all repository metadata and packages.

Install

After you’ve configured your repository, follow these steps.
  1. Run the following command to install Core Agent:
  2. Run the following command to instruct systemd to enable the Core Agent service:
  3. Perform a status check to confirm Core Agent is active. The status check should return output similar to the following:
    The default configuration of Core Agent is to collect metrics of CPU usage and send those metrics to stdout. You can see this outgoing data in your /var/log/messages file.

Support for StartLimitIntervalSec in RHEL 7

In Core Agent version 25.1.5 or later, the Core Agent systemd file doesn’t include the StartLimitIntervalSec configuration in RHEL 7 due to incompatibility with systemd 219. RHEL versions that use systemd 230 or later are unaffected by this change.