In 220.127.116.11 Patch the kernel adaptation mappings for the agent version 18.104.22.168 are missing in the NetWitness Endpoint Database. This causes the agents to not receive new and future kernel encoding values from the NetWitness Endpoint Server and results in a driver error (0xe0010014). A fix is being created and will be made available shortly in an upcoming patch. In the meantime the workaround below will resolve this issue.
Agent version 22.214.171.124 on supported Microsoft Windows agent platform
When there are new Windows kernel updates available, the agent will encounter this error and the agent driver will be stopped causing the agent to function partially (user mode capability only). All capability provided by the Windows agent driver will fail to function: behavior and network tracking events, memory dump generation, module blocking, and network containment.
Execute below query on the NetWitness Endpoint Database (Primary and Secondary if it is multi-server environment) to correct the agent kernel adaptation mapping.
update [AgentVersionKernelAdaptMapping] set AgentVersion=4403 where VersionDescription='V126.96.36.199'
RSA NetWitness Platform page on RSA Link.loads, and more, visit the
RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.