ZeroLock® Agent Installation: Download Installer

In the Default and Air Gapped environments a ZeroLock Agent (ZA) can be installed using the Self-Extracting installer or the Tar installer.  However, for the ESXi environment, there is only the VIB (vSphere Installation Bundle) signed Component Installer option.    

Advanced Settings 

Regardless of the installation method, there are settings that must be made prior to installing any agent. These Advanced Settings vary depending on the environment you are using and the agent version you intend to install. 

On selecting an environment, the appropriate scripts are automatically included. For this example, select the Default environment and ensure that the Deploy – Default screen is visible prior to proceeding with agent installation. 

For instruction on installing an agent in an ESXi environment use this link:  ZeroLock® Agent: Signed Component Installation on ESXi  

Default Environment

A screenshot of a computer

Description automatically generated

  • Self-Extracting Installer 
    • Click Install-ZeroLock-<version number>.sh (Insert the agent version number) to download the installer file, then copy it to the target endpoint(s). 
    • Using the Copy Install Instructions button for complete installation instructions. 
    • In a terminal session, cd to the location of the installer file (Download folder) then execute the following command to install: bash install-zerolock-<version number>.sh.

 A screen shot of a computer

Description automatically generated

  • Tar Installation 
    • If you prefer to use the Tar installer method, the steps are the same as with the self-extracting option but, when you open a terminal and SSH to the client, the tgz script will be pasted into the command line. 

Validating Agent Installation 

To validate the installation process, select the Endpoints tab on the main menu. The new endpoint will be listed; the green dot in the status column indicates a successfully installed agent on the endpoint system. 

Agent Log 

There are two (2) ZA logs, Tyr and Baldur.  Tyr provides communication to the ZeroLock Management Console (ZMC) and Baldur is the behavior analysis engine that provides detection, response, and telemetry (data) to Tyr.    

Since the focus is on validating agent installation and communication with the ZMC, we will only show the Tyr logs.    

To locate the ZeroLock Agent’s Tyr logs, login to the endpoint then use commands:   

    •  To see the Tyr directory: cd /opt/zerolock/zerolock-tyr   
    • To see the Tyr.log: ls -la


    • To read the log: cat tyr.log
      A screenshot of a computer

Description automatically generated

 

For more information, please see: 

Uninstalling a ZeroLock® Agent 

Updating a ZeroLock® Agent 

ValiCyber support page