Logstail
Skip to Content

Unix Agent

Use the Linux or Unix agent to monitor Linux-based systems and collect logs, metrics, network packets, and security events.

Linux and Unix Requirements

Before installing the Linux or Unix agent, confirm that the system has:

Python 3.6 or newer
Terminal access
Root or administrator privileges
Network access to the Logstail platform or on-premise Logstail endpoint
The Logstail Token
The SIEM Enterprise Key if SIEM functionality is required

Download and Run the Linux or Unix Agent

Install Python 3 if it is not already installed.

Then download the Logstail Agent using the command shown in the Logstail Agent dialog.

Logstail Agent Download

Configure the Unix Agent

Available Collector Actions

The Linux or Unix agent provides actions for installing, checking, configuring, restarting, or removing collectors.

Use these actions to manage the collector lifecycle, validate collector health, and control which modules collect data from the endpoint.

Install

Installs the selected collector on the system and enables it. Before installing a collector, make sure the Logstail Client Token has been copied from your Logstail account. You can find the token in My Account → Account. The token is used to connect the collector to the Logstail Platform.

Status

Prints the current status of the selected collector. If the status is OK or RUNNING, the collector is active and ready. If the collector is not running, review the configuration first. If the issue cannot be resolved, contact Logstail Support.

Show modules

Prints all available modules for the selected collector and shows whether each module is enabled or disabled. Use this action before enabling or disabling modules so you can confirm which modules are available.

Enable module

Enables a module on the selected collector. Before enabling a module, run Show modules to review the available modules and their current status. Some modules require extra configuration before they can collect data correctly.

After enabling a module:

If the dashboard is empty, review the module configuration and confirm that data is being shipped to Logstail.

Disable module

Disables an already enabled module. After disabling a module, data related to that module will no longer be collected or shipped to the Logstail Platform. Use this action when a module is no longer needed or should be removed from the endpoint collection scope.

Restart Collector

Restarts the selected collector. Use this action when the collector configuration was changed manually, a module was enabled or disabled, data is not being shipped, the collector status does not look healthy, or a configuration change needs to be applied. After restarting, check the collector status and verify data in Logstail.

Uninstall

Uninstalls the selected collector from the system. After uninstalling a collector, any data related to that collector will stop being shipped to the Logstail Platform. Use this action only when the collector is no longer required on the endpoint.

Logs Collector

The Logs Collector gathers log files, parses them, and forwards the data to Logstail. Use this collector when you want to centralize and analyze logs from systems, applications, or services in dashboards, reports, or workflows.

Metrics Collector

The Metrics Collector collects system and service metrics from the endpoint. Use this collector to monitor performance, resource usage and overall infrastructure health across servers, containers, and applications.

Packets Collector

The Packets Collector captures network traffic and extracts metadata from protocols such as HTTP, DNS, and TCP. Use this collector for network visibility, troubleshooting, and security investigations at the endpoint level.

SIEM Collector

The SIEM Collector enables real-time threat detection, log analysis, and incident response. Use this collector when the endpoint should perform security monitoring, detect vulnerabilities, and send SIEM telemetry to Logstail.

Linux and Unix Collectors and Modules

Linux and Unix collectors gather logs, metrics, packets, and security events from the endpoint.

Verify Data Collection

After installing the agent and collectors, verify that endpoint data is flowing into Logstail.

If data does not appear, check:

Agent status
Collector status
Token configuration
SIEM Enterprise Key configuration
Network connectivity
Firewall rules
Host or server IP settings for on-premise deployments
Module configuration
Collector restart status

Security Best Practices

Use approved systems

Install the agent only on approved systems.

Limit admin privileges

Use administrator or root privileges only when required.

Protect credentials

Keep tokens and enterprise keys protected.

Avoid credential sharing

Do not share credentials in tickets, screenshots, or public channels.

Use least privilege

Use the lowest required permissions for module credentials.

Restart after changes

Restart collectors after configuration changes.

Validate data flow

Validate that data is flowing after every new collector installation.

Verify host settings

For on-premise deployments, verify the correct host or server IP before entering credentials.

Clean up unused components

Remove unused collectors or modules when they are no longer needed.

PageDescription
AgentsConfirm that the Linux or Unix endpoint appears in the agent inventory and check agent health, status, version, and last seen time.
DiscoverValidate that Linux or Unix logs, metrics, network packets, and SIEM telemetry are arriving.
DashboardsReview collected Linux or Unix data through visual dashboards.
Pre-Built DashboardsAdd dashboards related to Linux logs, metrics, packets, SIEM telemetry, or enabled modules.
AlertsReview alerts generated from Linux or Unix telemetry and SIEM detections.
CasesGroup related Linux or Unix alerts into investigation cases.
MonitorsCreate detection rules that evaluate Linux or Unix data and generate alerts.
PlaybooksAutomate response actions for Linux or Unix-related alerts and incidents.