Environment
Symptoms
One or more sensors are marked Offline in the EDR console even though they are checking in regularly.
Cause
Time is not properly synced between the EDR server(s) and endpoints
Resolution
- Enable NTP across all server nodes and endpoints
- Ensure time is synced across devices
Additional Notes
- By default, Sensors will attempt to check into the EDR server every 1 minute.
- By default, the EDR server will mark a sensor as 'Offline' if the endpoint hasn't checked in for 5 minutes.
- If the time difference between devices is more than 5 minutes, then this issue will occur.
- This symptom will not prevent event telemetry from being uploaded to the EDR server
Related Content