Knowledge Base

Armor Agent & Subagent Statuses

Overview


Armor Agent and sub-agent health status change during the various steps of installation & uninstallation. These statuses are reflected in the following diagrams:

Armor Agent


Screenshot 2023-05-31 at 5.35.18 PM.png
  1. State: Screenshot 2025-10-14 at 11.47.30 a.m.-20251014-174738.png

    • Message: N/A

    • Description: After installation, if the Armor Agent is functioning correctly and sending regular heartbeats, the state is marked as "OK."

  2. State: image-20251017-172659.png

    • Message: The Armor Agent has not sent a heartbeat in the past 4 hours.

    • Description: If the Armor Agent fails to send a heartbeat within a 4-hour window, the state changes to "Needs Attention."

  3. Action for State: image-20251017-172659.png

    • Turn VM Off: If the VM is turned off, the process should turn it back on.

    • Turn VM On: Once the VM is turned on, the process reverts to checking the "State: OK."

This process ensures continuous monitoring and timely attention if the Armor Agent fails to send a heartbeat, indicating potential issues with the VM or the agent itself.

File Logging/Windows Event Logging



Screenshot 2023-05-31 at 5.35.35 PM.png
  1. State: Screenshot 2025-10-14 at 11.52.18 a.m.-20251014-175229.png

    • Message: Disabled - The customer opted out of this service.

    • Description: After installation, if the customer has opted out of the logging service, the state is marked as "N/A" with a message indicating the customer’s decision. Logging services are not installed in this case.

  2. State: Screenshot 2025-10-14 at 11.47.30 a.m.-20251014-174738.png

    • Message: No message.

    • Description: If the Armor Agent and logging services (if opted in) are functioning correctly, the state is marked as "OK" with no additional messages.

  3. State: image-20251017-172659.png

    • Message: Armor has not received a log from the filebeat/winlogbeat service in the past 4 hours.

    • Description: If the logging services (filebeat/winlogbeat) fail to send a log within a 4-hour window, the state changes to "Needs Attention."

  4. Actions for State Changes:

    • Logging Install: If the logging service is to be enabled, this action leads to the state being marked as "OK."

    • Logging Uninstall: If the logging service is to be disabled, this action leads to the state being marked as "N/A."

    • Turn VM Off: If the VM is turned off while in the "Needs Attention" state, the next step is to turn the VM back on.

    • Turn VM On: Once the VM is turned back on, the process reverts to checking the "State: OK."

Vulnerability Scanning



Screenshot 2023-05-31 at 5.35.51 PM.png


  • State: Screenshot 2025-10-14 at 11.52.18 a.m.-20251014-175229.png

    • Message: Disabled - The customer opted out of this service.

    • Description: After installation, if the customer has opted out of the vulnerability scanning service, the state is marked as "N/A" with a message indicating the customer’s decision. Vulnerability scanning services are not installed in this case.

  • State: Screenshot 2025-10-14 at 11.47.30 a.m.-20251014-174738.png

    • Message: No message.

    • Description: If the Armor Agent and vulnerability scanning services (if opted in) are functioning correctly, the state is marked as "OK" with no additional messages.

  • State: image-20251017-172659.png

    • Message: Asset not found in last scan. Check the KB for remediation steps.

    • Description: If the vulnerability scanning service fails to detect the asset during the last scan, the state changes to "Needs Attention."

  • Actions for State Changes:

    • Vuln Install: If the vulnerability scanning service is to be enabled, this action leads to the state being marked as "OK."

    • Vuln Uninstall: If the vulnerability scanning service is to be disabled, this action leads to the state being marked as "N/A."

    • Turn VM Off: If the VM is turned off while in the "Needs Attention" state, the next step is to turn the VM back on.

    • Turn VM On: Once the VM is turned back on, the process reverts to checking the "State: OK."

Trend Sub-Agent


File Integrity Malware Service

  1. State: Screenshot 2025-10-14 at 11.52.18 a.m.-20251014-175229.png

    • Message: Malware Protection is not installed or configured.

    • Description: You will see "Malware Protection is not installed or configured" if FIM has not yet been installed or configured.

      • If FIM fails to complete the installation, a tooltip appears to redirect to the Armor KB page for installation instructions and troubleshooting.

  2. State: Screenshot 2025-10-14 at 11.47.30 a.m.-20251014-174738.png

    • Message: No message.

    • Description: If the FIM (if opted in) sub-agent is functioning correctly, the state is marked as "OK" with no additional messages.

  3. State: image-20251017-172659.png

    • Message: FIM has not provided a heartbeat in the past 4 hours.

      • Description: If the FIM service fails to send a heartbeat within a 4-hour window, the state changes to "Needs Attention."

  4. Actions for State Changes:

    • Trend Install: If the Trend Micro service is to be enabled, this action leads to the state being marked as "OK."

    • Trend Uninstall: If the Trend Micro service is to be disabled, this action leads to the state being marked as "N/A."

    • FIM On: If FIM is turned on and functioning correctly, the state is marked as "OK."

    • FIM Off: If FIM is turned off, it leads to the state being marked as "N/A."

    • FIM On Failure: If there is a failure in turning on the FIM, it leads to "Bad Install Health."

    • Turn VM Off: If the VM is turned off while in the "Needs Attention" state, the next step is to turn the VM back on.

    • Turn VM On: Once the VM is turned back on, the process reverts to checking the "State: OK."

  5. Bad Install Health: If the installation process encounters issues, it leads to a state marked as "Bad Install Health."

Notification Updates in Nexus:

  • Before Change: Customers saw a notification in Nexus indicating "Disabled - Customer Opted Out" even if they had a failed Trend install or Trend failed to complete installation.

  • After Change:

    • The notification has been updated to reflect more specific statuses:

      • "Malware Protection is not installed or configured" if Trend has not yet been installed or configured.

      • "Trend has failed to complete the installation" with a tooltip redirecting to the Armor KB page for installation instructions and troubleshooting.

      • Any issue during installation that impacts the sub-agent's ability to register.

      • "Customer has disabled/opted out of the service."

    • If the customer has installed and uninstalled the sub-agent, the status will reflect the above changes accordingly.

Intrusion Detection Service

image2023-6-16_14-46-55.png


Malware Protection Service

image2023-6-16_14-47-31.png

VM Overview


After Armor Agent installation and before any sub-agent installation

cb29e74d-3501-491f-8b13-60682c37e84c.png


Successful install of Trend, logging, and vulnerability scanning subagents

2bf7f275-b8a0-4164-96fe-894277bfe326.png

After turning AV and FIM on and IPS Detect

6348ad41-7ef6-40d7-8257-6098cb3dfd69.png


After AV, FIM, and IPS has been turned off

e9ba69d4-30f4-4447-835d-7fceb7a0fe32.png


After uninstalling subagents

9c357d20-b575-4fb0-9f13-18f777f787de.png

After reinstalling sub-agents

1794262e-0405-4639-88f2-c51266038e13.png

After 16 hours of turning off the VM

782c276e-3216-443c-bd1d-c553d3d4b29f.png


After more than 24 hours of turning off the VM

3bc77b2b-17ac-459f-9535-b4e2c5b70325.png

Module Command Failure


Successfully install of Trend and "FIM On" command fails

3.png
Screenshot 2023-06-22 at 9.33.00 AM.png

Successfully install of Trend and "AV On" command fails

2.png
Screenshot 2023-06-22 at 9.33.30 AM.png


Successfully install of Trend and "IPS Detect" command fails

1.png
Screenshot 2023-06-22 at 9.33.00 AM.png