> Source: [sk184247](https://support.checkpoint.com/results/sk/sk184247)

# sk184247 - CPLA Fails to Install Due to Audit in Immutable State

| Property | Value |
|----------|-------|
| Solution ID | sk184247 |
| Date Created | 2025-10-29 |
| Last Modified | 2025-11-02 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Linux |

## Symptoms

- * CPLA fails to install with error: Unable to run command \[cpla check-audit-compat\]: exit status 1
* Running `auditctl -s` returns `is_immutable=1`

## Cause

The Harmony Endpoint Linux security agent relies on the Audit system to monitor events and enforce policies. If the Audit subsystem is set to immutable, the agent cannot register or modify audit rules, which disables critical security features.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
