Monitor

Getting started

Using Monitor

Network and troubleshooting

Your account

Project

Install on Linux

The Linux probe is two shell scripts. It runs once an hour on each machine from a systemd timer, reads how the machine is set up, and sends what it found to the collector.

It does not change anything on the machine.

What you need

Install it on one machine

  1. In the portal, open Add a machine and download probe-linux.tar.gz from the Linux section. The page shows which version it is, and its SHA-256.
  2. Copy it to the machine, into a new, empty folder, and run the commands shown on Add a machine. They look like this, with your own code at the end:

    tar xzf probe-linux.tar.gz && cd probe-linux sha256sum -c SHA256SUMS sudo ./bobcloud-monitor-install.sh --enrol-code <your code>

    The second line checks each file against the list inside the download: every line should end OK. There is no one-line curl ... | sh install, on purpose: you see what you run before you run it as root.

  3. The installer's last lines say where the machine stands. A new machine says PENDING: it appears under Waiting, and starts reporting once you approve it there (Approve a machine). A machine installed again after it was approved says APPROVED, and reports at its next hourly run.

To send its first report straight away rather than waiting for the hour:

sudo systemctl start bobcloud-monitor-agent.service sudo tail -n 20 /var/log/bobcloud-monitor/agent.log

Install it across an estate

Copy the same folder to each machine with your configuration management or RMM, and run the same install command as root. Every machine enrols with the same code and waits for you to approve it.

The enrolment code in your RMM policy expires after seven days, exactly as for Windows: once it has expired, no machine can enrol until an owner makes a new one on Waiting, and a machine that runs the install with an expired or replaced code will not enrol. Put the new code in the policy before each rollout.

Update it

Run the installer again, the same way, from a new folder holding the current download. It updates the probe in place: the machine keeps its identity and its history.

Or let the probe update itself: see Enable automatic updates.

Remove it

sudo ./bobcloud-monitor-install.sh --uninstall

This removes the timer and its service, the probe, its credentials, its own folders and its log. The machine stays in the portal until you revoke it, or until it has been quiet for 30 days.

What it installs, and what to allow in security software: see What to tell your EDR.

Next: Approve a machine