> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md).

# Cortex XDR Agent for Linux Requirements

The Cortex XDR agent for Linux has the following requirements:

| Requirement               | Minimum Specification                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Processor                 | Processor 2.3 GHz dual-core processor                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| RAM                       | 4GB; 8GB recommended                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Hard disk space           | 10 GB                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Architecture              | <p>x86\_64 (x86 64bit)</p><p>For aarch64 (ARM 64 bit) see <a href="/spaces/fZ8QSMnkjnXpuOeuRcam/pages/72479cd74455d6c86eabac8558ed14256d63af0e">Cortex XDR Agent for Linux Requirements</a> for details.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Operating system versions | See the [Cortex XDR Agent Compatibility Matrix](/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Kernel version            | <p><strong>Kernel Mode</strong></p><p>On Linux endpoints, to perform malware analysis of Executable and Linkable Format (ELF) files and collect data for endpoint detection and response (EDR) and behavioral threat analysis, the Cortex XDR agent requires one of the Linux Kernels that are listed in <a href="/spaces/y29o8lwSBpbfPbvztsyt/pages/5owoDAWGuwzAovtOflFJ">supported Kernel Module Versions</a>.</p><p>If you deploy the Cortex XDR agent on a Linux server that is not running one of the kernel versions required for these additional protection capabilities, the agent will operate in asynchronous mode.</p><p><strong>User Space Mode</strong></p><p>User Space operation mode is supported from Cortex XDR agent version 7.7</p><p>User space operation mode requires Kubernetes node to run one of the supported operation systems with Kernel version 5.0 or later.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Software packages         | <ul><li>Verify that you have standard Unix programs installed.</li><li>ca-certificates</li><li>openssl 1.0.0 or a later release</li><li><p>Distributions with SELinux in enforcing or permissive mode:</p><ul><li>Red Hat Enterprise Linux 6, CentOS 6, and Oracle Linux 6—policycoreutils-python</li><li>Red Hat Enterprise Linux 7, CentOS 7, and Oracle Linux 7—policycoreutils-python and selinux-policy-devel</li><li>Red Hat Enterprise Linux 8/9, CentOS 8, Oracle Linux 8/9, Alma Linux 8/9 and Rocky Linux 8/9: policycoreutils-python-utils and selinux-policy-devel</li><li>Amazon Linux: policycoreutils-python and selinux-policy</li><li>Amazon Linux 2: policycoreutils-python and selinux-policy-devel</li><li>SUSE and OpenSuse: policycoreutils-python and selinux-policy-devel</li><li>Debian and Ubuntu—policycoreutils and selinux-policy-dev</li></ul></li><li>glibc—Required for exploit protection of containerized processes using the ROP Mitigation and Brute Force Protection modules. If glibc is not installed, the modules are disabled but all other exploit and malware protection functionality work as expected.</li><li><p>CentOS 6.10—Enable the dynamic CA instead of the legacy CA:</p><p>1. Enable the dynamic CA configuration: <code>update-ca-trust force-enable</code></p><p>2. Import the certificates: <code>cp XDR-certificate.crt /etc/pki/ca-trust/source/anchors/.</code></p><p>3. Rebuild the certificate database: <code>update-ca-trust extract</code></p></li></ul> |
| Networking                | <ul><li>Allow communication on the TCP port from the Cortex XDR agent to the server (the default is port 443).</li><li>Allow your Cortex management console and Cortex XDR agent to communicate with external and internal resources required for enforcing endpoint protection. Refer to the <em>Resources Required to Enable Access</em> section of your Cortex Admin Guide.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
