Logon Tracker is an optional module available for Endpoint Security 5.3.0 and later with xAgent 35 and later. It is installed using your Endpoint Security Web UI. The module installer package .cms file is downloaded from the FireEye Market and then installed on your Endpoint Security Web UI. Initially, the module is disabled by default and must be enabled before using it.
After the module is installed successfully, it is displayed on the Modules menu. The configuration properties for the module appear on the Endpoint Module Administration Module Configuration page.
Note
In the previous versions of Logon Tracker (v0.4.x), some databases became corrupted. The current version of Logon Tracker attempts to migrate the data from these databases. However, in some cases an upgrade is not possible. In this situation, the system will roll back to the previous version. The only solution is to then uninstall the existing version and install the new version.
Upgrades from 0.4.x and 0.5.X can take over an hour to migrate large existing event databases.
Upgrades from 1.0.x and 1.1.x may cause the agent to become unresponsive and require a manual service restart on older versions of Linux. It is recommended to first remove Logon Tracker from the endpoint policy for Linux agents, which will uninstall the module. Then upgrade the server and finally re-add Logon Tracker to the endpoint policy.