Fortinet black logo

Administration Guide

Upgrading FortiEDR Components

Upgrading FortiEDR Components

If your FortiEDR Threat Hunting Repository, Central Manager, Aggregator or Core are deployed on your organization’s premises (on-premises), see to Appendix C – ON PREMISE DEPLOYMENTS

Upgrading the Collector

After a Collector has been installed in the system, you can upgrade it using one of the following methods:

You can use whichever method you prefer.

To upgrade the Collector manually (not via the user interface):

Windows
  1. Copy the FortiEDRCollectorInstallaler32_x.x.x.xxx.msi or FortiEDRCollectorInstallaler64_x.x.x.xxx.msi file (as appropriate) to the Collector machine. For example, FortiEDRCollectorInstallaler32_2.0.0.330.msi or FortiEDRCollectorInstallaler64_2.0.0.330.msi.
  2. Double-click the FortiEDRCollectorInstallaler32_x.x.x.xxx.msi or FortiEDRCollectorInstallaler64_x.x.x.xxx.msi file and follow the displayed instructions.
Linux
Note

You can only manually upgrade non-customized Linux Collectors. For custom Linux Collectors, you must first uninstall the current Collector and then install a new one, which requires reconfiguration.

To upgrade a non-customized Collector on Linux:
  1. Check the status of the Collector using the following command:
    /opt/FortiEDRCollector/control.sh --status

    The Collector should be stopped before running the upgrade command.

  2. If the status is not stopped, stop the Collector using the following command:
     /opt/FortiEDRCollector/control.sh --stop <registration password>

    For example:

    / opt/FortiEDRCollector/control.sh --stop 12345678
  3. Copy the installer file to the Collector machine (either FortiEDRCollectorInstaller_Linux_distribution-version_number.x86_64.rpm or FortiEDRCollectorInstaller_Ubuntuversion_number.deb).
  4. Upgrade the Collector using the following command:
    • CentOS/RHEL/Oracle/AMI:
      sudo yum install FortiEDRCollectorInstaller_Linux_distribution-version_number.x86_64.rpm
    • Ubuntu:
      Ubuntu: Run sudo apt install FortiEDRCollectorInstaller_Ubuntu-version_number.deb
    • SLES:
      zypper install FortiEDRCollectorInstaller_distribution-version_number.rpm
  5. Enter y when asked if you want to upgrade.
  6. After the upgrade is complete, start the Collector using the following command:
    /opt/FortiEDRCollector/control.sh --start

Upgrading FortiEDR Components

If your FortiEDR Threat Hunting Repository, Central Manager, Aggregator or Core are deployed on your organization’s premises (on-premises), see to Appendix C – ON PREMISE DEPLOYMENTS

Upgrading the Collector

After a Collector has been installed in the system, you can upgrade it using one of the following methods:

You can use whichever method you prefer.

To upgrade the Collector manually (not via the user interface):

Windows
  1. Copy the FortiEDRCollectorInstallaler32_x.x.x.xxx.msi or FortiEDRCollectorInstallaler64_x.x.x.xxx.msi file (as appropriate) to the Collector machine. For example, FortiEDRCollectorInstallaler32_2.0.0.330.msi or FortiEDRCollectorInstallaler64_2.0.0.330.msi.
  2. Double-click the FortiEDRCollectorInstallaler32_x.x.x.xxx.msi or FortiEDRCollectorInstallaler64_x.x.x.xxx.msi file and follow the displayed instructions.
Linux
Note

You can only manually upgrade non-customized Linux Collectors. For custom Linux Collectors, you must first uninstall the current Collector and then install a new one, which requires reconfiguration.

To upgrade a non-customized Collector on Linux:
  1. Check the status of the Collector using the following command:
    /opt/FortiEDRCollector/control.sh --status

    The Collector should be stopped before running the upgrade command.

  2. If the status is not stopped, stop the Collector using the following command:
     /opt/FortiEDRCollector/control.sh --stop <registration password>

    For example:

    / opt/FortiEDRCollector/control.sh --stop 12345678
  3. Copy the installer file to the Collector machine (either FortiEDRCollectorInstaller_Linux_distribution-version_number.x86_64.rpm or FortiEDRCollectorInstaller_Ubuntuversion_number.deb).
  4. Upgrade the Collector using the following command:
    • CentOS/RHEL/Oracle/AMI:
      sudo yum install FortiEDRCollectorInstaller_Linux_distribution-version_number.x86_64.rpm
    • Ubuntu:
      Ubuntu: Run sudo apt install FortiEDRCollectorInstaller_Ubuntu-version_number.deb
    • SLES:
      zypper install FortiEDRCollectorInstaller_distribution-version_number.rpm
  5. Enter y when asked if you want to upgrade.
  6. After the upgrade is complete, start the Collector using the following command:
    /opt/FortiEDRCollector/control.sh --start