OnboardingThreatsabre agentLegacy
Alpine Linux Deployment Guide
Legacy manual installation guide for the ThreatSabre Agent on Alpine Linux with OpenRC. For current installations, use the automated install script.
These instructions are for legacy agent installations. Please refer to the Installation Guide for the current recommended approach.
Prerequisites
- Alpine Linux (tested on 3.18+)
- Root access
- Network connectivity to download the agent
- GNU Standard C++ Library (apk add libstdc++)
1. Create Directory Structure
mkdir -p /opt/threatsabre-agent
mkdir -p /etc/threatsabre-agent
mkdir -p /var/log/threatsabre-agent2. Download and Install the Agent Binary
# Download the agent
wget -O /tmp/ts-agent-alpine.gz https://files.threatsabre.com/ts-agent/tsagent-0.0.7-linux-x64-musl.gz
# Extract to installation directory
gunzip -c /tmp/ts-agent-alpine.gz > /opt/threatsabre-agent/threatsabre-agent
# Set executable permissions
chmod 755 /opt/threatsabre-agent/threatsabre-agent
# Clean up
rm /tmp/ts-agent-alpine.gz3. Create Configuration File
cat > /etc/threatsabre-agent/agent.conf << 'EOF'
# ThreatSabre Agent Configuration
AGENT_TOKEN=your_agent_token_here
CONTROLLER_HOST=https://api.threatsabre.com
LOG_LEVEL=info
EOF
# Secure the config file
chmod 600 /etc/threatsabre-agent/agent.conf
chown root:root /etc/threatsabre-agent/agent.confConfiguration Options
| Variable | Description | Required |
|---|---|---|
AGENT_TOKEN | Authentication token for the controller | Yes |
CONTROLLER_HOST | URL of the ThreatSabre controller | Yes |
LOG_LEVEL | Logging verbosity: error, info, or debug | No (default: info) |
4. Create OpenRC Init Script
cat > /etc/init.d/threatsabre-agent << 'EOF'
#!/sbin/openrc-run
name="ThreatSabre Agent"
description="ThreatSabre Security Agent"
command="/opt/threatsabre-agent/threatsabre-agent"
command_background="yes"
pidfile="/run/${RC_SVCNAME}.pid"
output_log="/var/log/threatsabre-agent/agent.log"
error_log="/var/log/threatsabre-agent/agent.log"
depend() {
need net
after firewall
}
start_pre() {
# Load environment variables from config
if [ -f /etc/threatsabre-agent/agent.conf ]; then
set -a
. /etc/threatsabre-agent/agent.conf
set +a
else
eerror "Configuration file not found: /etc/threatsabre-agent/agent.conf"
return 1
fi
# Ensure log directory exists
checkpath --directory --mode 0755 /var/log/threatsabre-agent
}
EOF
chmod 755 /etc/init.d/threatsabre-agent5. Enable and Start the Service
# Add to default runlevel (starts on boot)
rc-update add threatsabre-agent default
# Start the service now
rc-service threatsabre-agent start
# Check status
rc-service threatsabre-agent statusService Management
| Command | Description |
|---|---|
rc-service threatsabre-agent start | Start the agent |
rc-service threatsabre-agent stop | Stop the agent |
rc-service threatsabre-agent restart | Restart the agent |
rc-service threatsabre-agent status | Check agent status |
rc-update add threatsabre-agent default | Enable on boot |
rc-update del threatsabre-agent default | Disable on boot |
Logging
| Command | Description |
|---|---|
sudo tail -f /var/log/threatsabre-agent/agent.log | View live agent logs |
Ubuntu Deployment Guide
Legacy manual installation guide for the ThreatSabre Agent on Ubuntu with systemd. For current installations, use the automated install script.
Obtaining API credentials
Create read-only API administrators on FortiGate, FortiManager, or FortiManager Cloud so the ThreatSabre Agent can collect telemetry securely.