<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DAT signatures of Windows and Linux in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206811#M8275</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;There are two different things when we speak about AM:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Engine version. Looks like&amp;nbsp;3.90.0&lt;/LI&gt;
&lt;LI&gt;Signature version. Looks like&amp;nbsp;6.06 16/01/2024. This is DB which is released roughly once per month and gets small updates several times per day. Linux client also reports version as a timestamp (e.g. 202402220810)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Engine version is pretty much common for Windows and Linux.&amp;nbsp;However, there might be some time gaps when engine is updated on one platform and remains on the other.&lt;/P&gt;
&lt;P&gt;Signatures are the same for both platforms.&lt;/P&gt;
&lt;P&gt;To see if Linux agent runs the latest signatures, run 'sudo cpla am info' on the machine:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;user@host &amp;gt; sudo cpla am info&lt;BR /&gt;CPLA version: 1.13.3&lt;BR /&gt;Anti-Malware version: 3.90.0 / 6.06 16/01/2024 (90995083 signatures)&lt;BR /&gt;Signature version: 202402220810&lt;BR /&gt;Policy name: Default Anti Malware policy&lt;BR /&gt;Policy version: 0&lt;/P&gt;
&lt;P&gt;In the example above signature version is&amp;nbsp;202402220810, which reflects the current date.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2024 11:07:39 GMT</pubDate>
    <dc:creator>Alex_G</dc:creator>
    <dc:date>2024-02-22T11:07:39Z</dc:date>
    <item>
      <title>DAT signatures of Windows and Linux</title>
      <link>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206799#M8274</link>
      <description>&lt;P&gt;The estate has both Windows and Linux machines installed with Checkpoint EDR, recently I noticed a very different anti-malware version for a few of my Linux machines &lt;STRONG&gt;3.89.0/ 6.05 28/11/2023.&amp;nbsp;&lt;/STRONG&gt;The main concern is that these Linux devices are fetching the Windows DAT signature and are not updating to the latest version.&lt;/P&gt;&lt;P&gt;Can anyone help me understand what exactly is happening here, why a Linux machine is using a Windows DAT signature, and the possible reasons behind this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;********&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/104118"&gt;@SayoojDinan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 08:48:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206799#M8274</guid>
      <dc:creator>SayoojDinan</dc:creator>
      <dc:date>2024-02-22T08:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: DAT signatures of Windows and Linux</title>
      <link>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206811#M8275</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;There are two different things when we speak about AM:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Engine version. Looks like&amp;nbsp;3.90.0&lt;/LI&gt;
&lt;LI&gt;Signature version. Looks like&amp;nbsp;6.06 16/01/2024. This is DB which is released roughly once per month and gets small updates several times per day. Linux client also reports version as a timestamp (e.g. 202402220810)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Engine version is pretty much common for Windows and Linux.&amp;nbsp;However, there might be some time gaps when engine is updated on one platform and remains on the other.&lt;/P&gt;
&lt;P&gt;Signatures are the same for both platforms.&lt;/P&gt;
&lt;P&gt;To see if Linux agent runs the latest signatures, run 'sudo cpla am info' on the machine:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;user@host &amp;gt; sudo cpla am info&lt;BR /&gt;CPLA version: 1.13.3&lt;BR /&gt;Anti-Malware version: 3.90.0 / 6.06 16/01/2024 (90995083 signatures)&lt;BR /&gt;Signature version: 202402220810&lt;BR /&gt;Policy name: Default Anti Malware policy&lt;BR /&gt;Policy version: 0&lt;/P&gt;
&lt;P&gt;In the example above signature version is&amp;nbsp;202402220810, which reflects the current date.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 11:07:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206811#M8275</guid>
      <dc:creator>Alex_G</dc:creator>
      <dc:date>2024-02-22T11:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: DAT signatures of Windows and Linux</title>
      <link>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206812#M8276</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107492"&gt;@Alex_G&lt;/a&gt;&amp;nbsp;Thanks for your reply.&lt;/P&gt;&lt;P&gt;My DAT signature shows &lt;STRONG&gt;202312060548,&amp;nbsp;&lt;/STRONG&gt;this is quite a concern. How do I resolve this, also my endpoints are connected to the MGMT server and the agent version is 1.13.3.&lt;/P&gt;&lt;P&gt;********&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/104118" target="_blank"&gt;@SayoojDinan&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 11:22:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206812#M8276</guid>
      <dc:creator>SayoojDinan</dc:creator>
      <dc:date>2024-02-22T11:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: DAT signatures of Windows and Linux</title>
      <link>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206816#M8277</link>
      <description>&lt;P&gt;Management server allows to configure update source for AM. Here is a quick test that you can do:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Restart the client by running "sudo systemctl restart cpla". Check the version in 5 mins&lt;/LI&gt;
&lt;LI&gt;Ensure that you are able to see SPS_VERSION in output of `curl &lt;A href="https://teadv.checkpoint.com/Sophos-stg/version.txt`" target="_blank"&gt;https://teadv.checkpoint.com/Sophos-stg/version.txt`&lt;/A&gt;This should be available if the client is configured to use external server.&amp;nbsp; Updates from management server is in our roadmap. If you use proxy in your environment, it should be configured at the time of installation or by editing /etc/checkpoint/cpla/env and restarting the service&lt;/LI&gt;
&lt;LI&gt;Ensure that client is configured to use external update server.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope this will resolve the issue. if it doesn't, I would proceed with a support ticket&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 11:45:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/DAT-signatures-of-Windows-and-Linux/m-p/206816#M8277</guid>
      <dc:creator>Alex_G</dc:creator>
      <dc:date>2024-02-22T11:45:00Z</dc:date>
    </item>
  </channel>
</rss>

