Fortinet white logo
Fortinet white logo

FortiDLP Agent Deployment Guide

Resolving FortiDLP Agent deployment issues

Resolving FortiDLP Agent deployment issues

Error messages, causes, and resolutions
Output Possible cause Resolution

Error: could not connect to agent: dial unix /var/run/jazz-agent.sock:connect:connection refused

The Agent has not started up.

Wait at least 30 seconds and then reattempt enrollment. If you are scripting the enrollment, ensure you have a sleep command in the script. You can view an example script in Bulk deploying the FortiDLP Agent to macOS.

Error: could not connect to agent: [...] The Agent service is not running. Start the Agent service.
Error: open %FILENAME%: %REASON% The enrollment bundle is not at the specified location or you are not running as an administrator or root user. Verify the location of the enrollment bundle and ensure you are running as an administrator or root user.

Error: could not enroll agent: [...] invalid bundle file

or

Error: could not enroll agent: [...] incomplete bundle

The enrollment bundle is invalid or damaged. Ensure you are running as an administrator or root user and generate a new enrollment bundle.
Error: no enrollment data found The information provided was neither a valid enrollment code nor the name of an enrollment bundle. Verify the enrollment code or name of the enrollment bundle.
Error: enrollment failed: failed to request certificate: Unauthenticated The enrollment bundle has expired, been revoked, or is invalid. Generate a new enrollment bundle or code.
Error: gave up waiting for enrollment to complete The enrollment process took longer than expected, most likely due to a communication error between the FortiDLP Agent and the FortiDLP Infrastructure. Monitor the Agent logs for information. Restart the Agent service. Contact Fortinet Support.
Error: enrollment failed: %REASON% The enrollment failed for the specified reason. Contact Fortinet Support.
Panic: open /proc/jazz/files: no such file or directory The FortiDLP Agent started running before the kernel module loaded. Reboot the device.
Note

You can access the FortiDLP Agent logs as follows:

  • On Windows, go to C:\ProgramData\Jazz Networks\Agent\logs.
  • On macOS, open a command-line interface and run
    log show --info --predicate='subsystem beginswith "uk.ava.reveal"'.
  • On Linux, open a command-line interface and run journalctl -u jazz-agent -b.

Resolving FortiDLP Agent deployment issues

Resolving FortiDLP Agent deployment issues

Error messages, causes, and resolutions
Output Possible cause Resolution

Error: could not connect to agent: dial unix /var/run/jazz-agent.sock:connect:connection refused

The Agent has not started up.

Wait at least 30 seconds and then reattempt enrollment. If you are scripting the enrollment, ensure you have a sleep command in the script. You can view an example script in Bulk deploying the FortiDLP Agent to macOS.

Error: could not connect to agent: [...] The Agent service is not running. Start the Agent service.
Error: open %FILENAME%: %REASON% The enrollment bundle is not at the specified location or you are not running as an administrator or root user. Verify the location of the enrollment bundle and ensure you are running as an administrator or root user.

Error: could not enroll agent: [...] invalid bundle file

or

Error: could not enroll agent: [...] incomplete bundle

The enrollment bundle is invalid or damaged. Ensure you are running as an administrator or root user and generate a new enrollment bundle.
Error: no enrollment data found The information provided was neither a valid enrollment code nor the name of an enrollment bundle. Verify the enrollment code or name of the enrollment bundle.
Error: enrollment failed: failed to request certificate: Unauthenticated The enrollment bundle has expired, been revoked, or is invalid. Generate a new enrollment bundle or code.
Error: gave up waiting for enrollment to complete The enrollment process took longer than expected, most likely due to a communication error between the FortiDLP Agent and the FortiDLP Infrastructure. Monitor the Agent logs for information. Restart the Agent service. Contact Fortinet Support.
Error: enrollment failed: %REASON% The enrollment failed for the specified reason. Contact Fortinet Support.
Panic: open /proc/jazz/files: no such file or directory The FortiDLP Agent started running before the kernel module loaded. Reboot the device.
Note

You can access the FortiDLP Agent logs as follows:

  • On Windows, go to C:\ProgramData\Jazz Networks\Agent\logs.
  • On macOS, open a command-line interface and run
    log show --info --predicate='subsystem beginswith "uk.ava.reveal"'.
  • On Linux, open a command-line interface and run journalctl -u jazz-agent -b.