uberAgent

Changelog and Release Notes

Version 7.1

Release notes

  • Increased .NET version to 7.
  • Changed configuration file format to JSON.

Improvements

  • Log messages are written to stdout and a log file located in the %TEMP% (Windows) or /tmp (Linux) directory.
  • The fields SessionFgBrowserType, SessionFgBrowserType and SessionFgBrowserActiveTabHost of sourcetype uberAgent:Session:SessionDetail are now available on macOS, too.

New Sourcetypes

  • New sourcetype uberAgentESA:System:SecurityInventory with fields: SecurityInventoryCategory, SecurityInventoryName, SecurityInventoryScore, SecurityInventoryRiskScore, SecurityInventoryResultData, SecurityInventoryErrorCode, SecurityInventoryErrorMessage, SecurityInventoryScope, SecurityInventoryScopeEntity.

Updated Sourcetypes

  • Sourcetype [B287]: uberAgent:Process:ProcessStatistics has new field(s): ProcInputDelayMaxMs, ProcInputDelaySumMs and ProcInputDelayCount.
  • Sourcetype [B287]: uberAgent:Session:SessionDetail has new field(s): SessionInputDelayMaxMs, SessionInputDelaySumMs and SessionInputDelayCount.
  • Sourcetype [B751]: uberAgent:OnOffTransition:BootDetail2 has new field(s): UserLogonWaitDurationMs.
  • Sourcetype [B766]: uberAgentESA:Process:DnsQuery has new field(s): DnsRisk52Chars, DnsRisk27UniqueChars, DnsRiskEmptyResponse, DnsRiskTXTRecord, DnsRiskHighEntropy, DnsResponseStatus.

Version 7.0

Release notes

  • macOS client machines are now supported.

Improvements

  • Machines get their IP addresses once and they do not change.
  • Machines get their disk volumes only once and they do not change during their lifetime.
  • A random in-session process needs a long time to start.
  • Application UI delay events can now only be generated by processes started during a session.
  • WiFi data is now sent only for WiFi adapters.
  • BSODs are now sent less frequently.

New Sourcetypes

  • Sourcetype: new sourcetype uberAgent:CitrixSession:VirtualChannelDetail with fields: SessionGUID, SessionUser, VirtualChannelVendorName, VirtualChannelDataVolumeInputMB, VirtualChannelDataVolumeOutputMB.
  • Sourcetype: new sourcetype uberAgent:CitrixSession:SessionConfig with fields: SessionGUID, SessionUser, AudioActualPriority, AudioPolicyAllowMicrophoneRedirection, AudioPolicyAllowRedirection, AudioPolicyPriority, AudioPolicySoundQuality, CdmActualPriority, CdmVolumes, CdmPolicyAllowDriveRedirection, CdmPolicyPriority, CdmPolicyReadOnly, DisplayMode, ThinwireActualPriority, ThinwireColorDepth, ThinwireComponentEncoder, ThinwireHardwareEncodeInUse, ThinwireVideoCodecType, ThinwireColorspace, ThinwireVideoCodecUse, ThinwirePolicyFps, ThinwirePolicyPriority, ThinwirePolicyUseHardwareEncoding, ThinwirePolicyUseVideoCodec, ThinwirePolicyVisualQuality, FramehawkActualPriority, FramehawkPolicyPriority, D3DActualPriority, D3DPolicyAeroRedirection, D3DPolicyGraphicsQuality, D3DPolicyPriority, GraphicsActualPriority, GraphicsPolicyDisplayDegradeNotifyUser, GraphicsPolicyDisplayDegradePolicy, GraphicsPolicyPriority, NetworkConnectedVia, NetworkEdtMtu, NetworkPolicyAcceptSessionReliabilityConnections, NetworkPolicyICAListenerPortNumber, NetworkPolicySessionReliabilityPort, NetworkPolicySessionReliabilityTimeout, PrinterActualPriority, PrinterSessionPrinter, PrinterPolicyAllowRedirection, PrinterPolicyAutoCreateClientPrinters, PrinterPolicyPriority, USBActualPriority, USBPolicyAllowPNPRedirection, USBPolicyAllowUSBSupport, USBPolicyPriority.
  • Sourcetype: new sourcetype uberAgent:Process:ProcessStatistics with fields: ProcHandleCount, ProcThreadCount, ProcPriority, ProcPrivateMB, ProcVirtualSizeMB, ProcPageFaultsPS, ProcPageFileMB, ProcName, ProcID, ProcGUID, ProcUser and AppId.
  • Sourcetype: new sourcetype uberAgent:System:PerformanceCounter with fields: PerformanceCounterObject, PerformanceCounterInstance, PerformanceCounterName, PerformanceCounterValue.

Updated Sourcetypes

  • Sourcetype: uberAgent:Application:NetworkConnectFailure has new field(s): NetTargetSourcePort.
  • Sourcetype: uberAgent:System:MachineInventory has new field(s): HwHypervisorVendor.
  • Sourcetype: uberAgent:Session:SessionDetail has new field(s): SessionRoundTripTimeMs, SessionFps, SessionTransportProtocols.
  • Sourcetype: uberAgent:Citrix:Applications has new field(s): CustomerId.
  • Sourcetype: uberAgent:Citrix:Catalogs has new field(s): CustomerId.
  • Sourcetype: uberAgent:Citrix:DesktopGroups has new field(s): CustomerId.
  • Sourcetype: uberAgent:Citrix:Machines has new field(s): CustomerId.
  • Sourcetype: uberAgent:Citrix:PublishedDesktops has new field(s): CustomerId.
  • Sourcetype: replaced KV sourcetype uberAgent:PerformanceCounter:<TimerName> with CSV sourcetype uberAgent:System:PerformanceCounter.
  • Sourcetype: uberAgent:Application:ApplicationUsage has been removed (it was marked as deprecated as of version 6.1.1).

Version 6.2.0

Updated Sourcetypes

  • Sourcetype: uberAgent:Application:NetworkConnectFailure has new field(s): NetTargetSourcePort.
  • Sourcetype: uberAgent:Process:NetworkTargetPerformance has new field(s): NetTargetSourcePort.

Version 6.1.1.4416

Improvements

  • Improved number of sent events during session lifetime.
  • Improved values in Application Performance dashboard.

Bugfixes

  • Added chmod call to “StartEventgen.cmd”.

Version 6.1.1

Improvements

  • Added some more hardware models.
  • Added ModuleName and ExceptionCode to the sourcetype uberAgent:Application:Errors (applications crashes).
  • Generated outliers for Process DNS.

Updated Sourcetypes

  • Sourcetype: uberAgent:Process:ProcessStartup has new field(s): HashMD5, HashSHA1, HashSHA256, HashIMP, SignatureStatus, IsSignedByOSVendor, SignerName.
  • Sourcetype: uberAgent:Process:ProcessStartup: fields ProcHash and HashType have been removed.
  • Sourcetype: uberAgent:Process:ProcessStop has new field(s): HashMD5, HashSHA1, HashSHA256, HashIMP.
  • Sourcetype: uberAgent:Process:ProcessStop: fields ProcHash and HashType have been removed.
  • Sourcetype: uberAgent:Process:ProcessDetail has new field(s): SessionID.
  • Sourcetype: uberAgent:CitrixADC:AppliancePerformance has new field(s): CpuFan0Speed, CpuFan1Speed, SystemFanSpeed, Cpu0Temp, Cpu2Temp, InternalTemp, PowerSupply1Status, PowerSupply2Status, PowerSupply3Status, PowerSupply4Status, VoltageV33Main, ICAOnlySessions, ICAOnlyConnections, SmartAccessSessions, SmartAccessICAConnections, SSLSessions.
  • Sourcetype: uberAgent:CitrixADC:Gateway has new field(s): HSTS, HSTSMaxAge, HSTSInclSubdom, TLS13.
  • Sourcetype: uberAgent:CitrixADC:vServer has new field(s): HSTS, HSTSMaxAge, HSTSInclSubdom, TLS13.
  • Sourcetype: uberAgent:System:NetworkConfigInformation has new field(s): NetworkConfigWiFiSignalQuality, NetworkConfigWiFiType, NetworkConfigWiFiAuthentication.

New Sourcetypes

  • Sourcetype: new sourcetype uberAgentESA:Process:DnsQuery with fields: ProcName, ProcGUID, DnsRequest, DnsResponse, DnsResponseType and DnsEventCount.

Bugfixes

  • SMB paths had only one backslash.
Changelog and Release Notes