Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: The Same Endpoint has Multiple Sensor Ids

EDR: The Same Endpoint has Multiple Sensor Ids

Environment

  • EDR Server: 7.8.0

Symptoms

  • In the Sensor section of the EDR console, a search for a given computer name results in multiple entries.  There should only be one.
  • Postgres sensor_registration table contains multiple entries for the same endpoint (hostname, mac address, etc) with different sensor IDs.

Cause

In some cases, EDR is not processing the incoming events properly, leaving the DNS_name field blank.  If VDI is enabled to check hostname + DNS_name, then an event with a blank DNS_name field is seen as a new sensor and registered.
 

Resolution

Until the sensor data processing is fixed, deselect the DNS_name option in the EDR console VDI settings.   ( User > Settings > VDI Settings > DNS Name )

Additional Notes

  • EDR was designed to assign one  sensor id per endpoint to uniquely identify that endpoint.
  • VDI was designed to allow virtual machines to roll back/forward to snapshots and still be identified as the same endpoint.

Related Content


Labels (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎11-27-2023
Views:
98
Contributors