Submit a ticketCall us

Get a crash course on Network Monitoring delivered right to your inbox
This free 7-day email course provides a primer to the philosophy, theory, and fundamental concepts involved in IT monitoring. Lessons will explain not only how to perform various monitoring tasks, but why and when you should use them. Sign up now.

Home > Success Center > Server & Application Monitor (SAM) > SAM 6.4 Administrator Guide > Monitor with Orion agents in SAM > What kind of credentials do I need to install a Linux agent for SAM

What kind of credentials do I need to install a Linux agent for SAM

Updated: 3-9-2017

Agents installed on Linux-based computers may use three different credential sets to install and configure the agent. During this process, a service account is also created to run the agent service.

You need sufficient privileges to be able to do the following to install and configure the agent:

  • open a SSH connection remotely
  • SFTP or SCP
  • install software
  • create a user
  • create a group

Credentials are used to install and configure the agent and are not used at any other time. You may remove the credentials from the credential store once the agent is deployed.

SSH credentials

Agents require a credential set that allows the user to open an SSH session from a remote computer. This can be provided as either a user name and password or as a certificate.

Verify the credentials by opening an SSH connection to the remote computer.

For Linux-based computers, you may need to include another set of credentials to use su or sudo for package installation. You can add these credentials selecting the Include Credentials with Elevated Privileges.

Certificate credentials

You can use any certificate-based credential that is supported by SSH. Upload a private key file or paste the private key in PEM format.

Credentials with elevated privileges

To install the package, you need credentials with administrator or root-level privileges. Depending on your network security policies, some Linux-based computers do not allow user accounts to connect remotely and install software. If this applies to the computer you want to monitor, you can select Include Credentials with Elevated Privileges and enter credentials that have the correct privileges. Most Linux distributions require the user's password when using sudo. Other distributions, such as SUSE, may require the root password. Depending on your Linux distribution, enter the required credential for the Include Credentials with Elevated Privileges to install the package.

When this is selected, we connect to the Linux-based computer using the provided SSH credentials and then switch users to the account with elevate privileges to install and configure the agent.

Verify your privileges by opening an SSH connection to the remote computer, switching to the elevated credentials, and entering sudo -l.

SNMP credentials

Select Include SNMP Credentials in order to collect SNMP data to use in Hardware Health, Asset Inventory, and SNMP component monitor information. This is required if SNMP v3 is installed. The agent software detects if you have SNMP installed on the computer and attempts to use your established SNMP credentials. No data is collected if the agent does not have the correct SNMP credentials.

Service account privileges

When the agent software is installed, we create a service account (SWIAgent), and add it to its own group.

This account does not have remote access privileges and cannot be used to log in to the computer.

The service account is used to run the swiagentd service. When updating the agent, a second service runs (swiagentd.update) for the duration of the update.

The service account and group are removed when the agent is deleted from the node.

For SAM users, if you do not enter credentials or select Inherit from node, the monitor executes the script under the agent credentials (SWIAgent). These credentials may not have the elevated permissions required for executing scripts.

Last modified
13:36, 10 Mar 2017