- Have Capsule8 Console version 4.4.1 or later.
- The Package Cloud token should be set in the Console Configuration with the
- Console 4.4.1: To use "Quick Install", enable Console control of the Capsule8 Sensor with the
console.policy_config_enabledsetting. This setting defaults to true in Console version 4.5.0 and later.
- Console 4.5.0 and later: If you require the "Quick Install" dialog to install a specific sensor version, configure
- Non-admin users require the "Add New Resources" permission.
Quick Install Supported Distributions:
The Quick Install dialog does not support all Linux distributions. Users who need to install the sensor on unsupported distributions should manually install the sensor according to the relevant instructions and use the "Manual Install" dialog described below to obtain an initial sensor configuration. The following is a list of distributions supported by Quick Install:
- Amazon Linux 2
- CentOS 7
- CentOS 8
- Debian 8 (jessie)
- Debian 9 (stretch)
- Debian 10 (buster)
- Ubuntu 16.04 (Xenial)
- Ubuntu 18.04 (Bionic)
- Ubuntu 20.04 (Focal)
After the installation, the user will be prompted with this dialog:
You may select either Manual Install or Quick Install to set up the sensor from the Console UI. For supported distributions, Capsule8 recommends using Quick Install.
Once you have hosts connected, this dialog no longer appears on login. In Console 4.5.0 and later, users may re-open this dialog to install additional sensors by navigating to Resources and clicking Add Resource.
Quick Installation of Sensors from Console UI
Follow the Quick Install guide to install the Capsule8 Sensor.
Press Finish to complete the installation. As of Console 4.5.0, you will see a walkthrough of the Console's alert handling functionality.
Manual Installation of Sensors from Console UI
If Manual Install is selected, user will be presented with the below step
The configuration here may be copy/pasted into your
/etc/capsule8/capsule8-sensor.yaml to add a new Sensor to this instance of the Console. As of Console 4.6.0, this configuration always includes a webhook
alert_output block. Consoles already configured with S3/SQS additionally include a commented-out S3
alert_output block. Users who prefer to transport alerts via S3 may uncomment and edit this block. See Getting Started: Exporting Alerts to learn about additional alert output configurations.