SonicWall Capture Client can be used to protect Linux endpoints across various flavors. Capture Client for Linux only offers the endpoint protection features delivered by the SentinelOne engine and does not support agent lifecycle management enforcement, content filtering and Capture ATP integration.
Capture Client for Linux does not run any additional processes beyond those required by the SentinelOne engine on Linux endpoints - hence any actions to upgrade the Linux endpoint using policies or device actions will not force an upgrade of the SentinelOne engine.
To upgrade agents on Linux enpoints, administrators must uninstall and reinstall the client for the specific tenants
To uninstall a Linux agent:
Login to the Capture Client portal and export the Devices list from Protect -> Devices
Copy the SentinelOne passphrase for the Linux endpoint
Login to the Linux endpoint as root (sudo will not be enough)
Run the following command on the Linux endpoint. Using the unquarantine flag will unquarantine any files still quarantined by the SentinelOne engine. Else such files will be deleted
sudo /opt/sentinelone/bin/sentinelctl control uninstall --passphrase "string" [--output] [--unquarantine]