Skip to content

CentOS Stream

Install the Sensor from Endura’s signed RPM repository on CentOS Stream.

Prerequisites

  • CentOS Stream 10
  • Root or sudo access and systemd
  • A supported kernel with BTF at /sys/kernel/btf/vmlinux
  • At least 1 GB of available memory
  • An Endura license key
  • Team Server URL and Sensor token for centralized management

Install

curl -sSf https://repo.endurasecurity.com/install/endura-sensor/testing.sh | sudo -E sh
endura version
sudo systemctl status endura-sensor

The installer configures Endura’s signed RPM repository, installs endura-sensor, and creates the systemd service. DNF verifies the package signature during installation and update.

Configure

Edit /opt/endura/sensor/environ and set:

ENDURA_LICENSE_KEY=your_license_key
ENDURA_TEAM_SERVER=https://team-server.example.com
ENDURA_SENSOR_TOKEN=your_sensor_token

Create the token under Sensors in Team Server, then protect the file:

sudo chown root:root /opt/endura/sensor/environ
sudo chmod 600 /opt/endura/sensor/environ

See Configuration for optional variables.

Start and Verify

sudo systemctl enable --now endura-sensor
sudo systemctl status endura-sensor
endura sensor status
endura license verify

Confirm the Sensor and deployment appear in Team Server when centrally managed.

Operate the Service

sudo systemctl restart endura-sensor
sudo systemctl stop endura-sensor
sudo journalctl -u endura-sensor -f
sudo endura sensor hooks

Update

sudo dnf upgrade endura-sensor
endura version
sudo systemctl status endura-sensor

The package restarts a Sensor that was running before the update and leaves a stopped Sensor stopped. Review Team Server Compatibility before a major update.

Uninstall

sudo dnf remove endura-sensor

Back up and remove /opt/endura/sensor or /var/log/endura separately only if their configuration and logs are no longer needed.

Troubleshooting

Service Does Not Start

sudo systemctl status endura-sensor --full
sudo journalctl -u endura-sensor -n 100
test -r /sys/kernel/btf/vmlinux && echo "BTF available"
uname -r

Check the first startup error, license, file permissions, kernel support, and SELinux denials from sudo ausearch -m AVC -ts recent.

Team Server Is Offline

curl -v https://team-server.example.com/_readiness
getent hosts team-server.example.com

Confirm outbound TCP 443 and certificate trust. See Team Server Compatibility for an incompatible state.

Package or Kernel Changed

sudo dnf repolist
sudo dnf info endura-sensor
sudo endura sensor hooks

CentOS Stream updates its kernel frequently. Recheck hook coverage after kernel changes.