IBM Support

QRadar EDR (formerly ReaQta): Installing and uninstalling macOS agents

Question & Answer


Question

What are some common aspects that you need to know about installing and uninstalling QRadar EDR agent for macOS?

Answer

System Requirements for QRadar EDR Agent on macOS

To know more about the system requirements, follow this IBM document.
QRadar EDR Agent system requirements
 

How to install QRadar EDR Agent on MacOS

  1. Download the agent distribution package for MacOS from QRadar EDR dashboard:
    1. Log in to the QRadar EDR Dashboard.
    2. Click Administration Tab > Update Manager.
      image-20220323131526-1
    3. Click the Hive Package for MacOS, which opens up the Agent Distribution Details pane. Then, click the Installer Download tab.
      image-20231020101636-3
      image-20231020101804-4
    4. Click the Download, which downloads a .pkg file.
      image-20231020102017-5
  2. Double-click the .pkg file and click Continue.
    image-20231020102542-7
  3. You will see the Software License Agreement. Click Continue.
    image-20231020102948-9
  4. Click Agree after you read, understood, and agree on the License Agreement.
    image-20231020103128-10
  5. Ensure that you have the necessary space that is required for the installation. Click Install to proceed with the installation.
    image-20231020103255-11
  6. You need the user password or TouchID (if applicable) to proceed with the installation.
    image-20231020103418-12
  7. You might be prompted to allow the Installer.app to access the Folder where you run the .pkg file from. Click OK to continue.
  8. After the agent installation is done, you will be prompted to input the backend URL and gids to register the agent to the backend server. Click OK after you input the correct parameters.
    image-20231020103705-13
  9. You will see the message box that indicates that the system extension is blocked. Click Open System Settings.
    image-20231020103819-14
  10. Under Privacy & Security, Security Section, you should see the message that indicates that “IBM Security ReaQta.app” was blocked from loading. Click Allow.
    image-20231020103920-15
  11. You need the user password or TouchID (if applicable) to proceed.
    image-20231020104041-16
  12. Under Privacy & Security, Full Disk Access Section, ensure that keeperi and ReaQta-Hive-ES-Extension is enabled. If they are disabled, enable them.
    image-20231020104135-17
  13. If keeperi is not shown on the list, proceed to include it from the path “/Library/IBM Security ReaQta/keeperi”, then enable it.
  14. Go to the package installation window and click Close to complete the installation.
  15. Log in to the QRadar EDR Dashboard, click the Endpoints tab, verify that the newly installed endpoint is registered and online.
    image-20231020104634-19

How to uninstall QRadar EDR Agent on MacOS

There are two methods to uninstall the Hive agent. You can select any according to your convenience.
Method 1: Uninstall from QRadar EDR dashboard UI
  1. In the QRadar EDR Dashboard, go to the Endpoint tab. Click the target endpoint where you want to uninstall the agent.
  2. Click the View Endpoint at the lower right corner.
  3. Click uninstall.
    image-20220323150946-1
  4. Verify the /Library/IBM Security ReaQta directory is removed. If not, then proceed with steps in method 2.
     
Note: If the agent is not communicating with the server, uninstall from QRadar EDR dashboard is not successful.
 
Method 2: Uninstall from Mac
  1. Open the terminal and run the following command:
    sudo /Library/IBM\ Security\ ReaQta/uninstall.sh
  2. Verify the /Library/IBM Security ReaQta directory is removed.

If there is any issues during installation, what information do you need to provide to the support

  1. Specify the Endpoint name and link to the Dashboard.
  2. Specify the MacOS version, QRadar EDR dashboard version, and Agent distribution version.
  3. Provide the install.log to support from following location.
    /var/log/install.log
  4. Open console.app and filter by "keeperi"  and "ibm" as shown in the following screenshot and send the logs to the support.
    image-20231020110605-1

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSVOEH","label":"IBM Security ReaQta"},"ARM Category":[{"code":"a8m3p000000hBSRAA2","label":"Agent-\u003EInstallation-\u003EmacOS"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Product Synonym

ReaQta

Document Information

Modified date:
24 October 2023

UID

ibm16565683