IBM Support

QRadar EDR : Outdated agent warning

Question & Answer


Question

A warning "There is a breaking change of outdated agents (n), please update them to the latest version." may appear on the QRadar EDR dashboard's Endpoints tab. What does this warning mean?
 
outdated_agent

Answer

This warning appears whenever there are outdated agents installed on 'n' number of endpoints and a higher version agent distribution(installable) package is available in the Update Manager section under Administration tab. It can also appear when an endpoint is broken or if the endpoint cannot update the agent version to the Hive server. 

To resolve this, locate the endpoints that have the "Outdated Agent" warnings like this:

image-20231204181547-1

Once such endpoints are located, you can update the agents on those endpoints or uninstall the current version and install the latest version on such endpoints.

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSOO77","label":"IBM Security QRadar EDR"},"ARM Category":[{"code":"a8m3p0000000rbnAAA","label":"Support-\u003EAdministration Task"}],"ARM Case Number":"TS014806509","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
06 December 2023

UID

ibm17087543