<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duplicate endpoint entries observed in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509747#M2381</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191267"&gt;@MarvinC&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried creating a custom widget and I'm getting report of duplicate entries every day. But how do you remove the entries which are not needed?&lt;/P&gt;
&lt;P&gt;I have tried the "delete endpoint" option, it will remove the entry from the "All endpoints" but in the next day's report, it will reappear again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's the best solution to clean up all these unnecessary entries permanently?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jul 2022 04:15:20 GMT</pubDate>
    <dc:creator>MithunKT</dc:creator>
    <dc:date>2022-07-25T04:15:20Z</dc:date>
    <item>
      <title>Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509709#M2376</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have started noticing duplicate endpoint entries in the "All Endpoints" section.&lt;/P&gt;
&lt;P&gt;After checking all the fields we found that there are different endpoint_ids for the same endpoint name.&lt;BR /&gt;&lt;BR /&gt;What could be the reason behind the creation of these multiple/duplicate entries and how can we clean up these entries?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 06:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509709#M2376</guid>
      <dc:creator>MithunKT</dc:creator>
      <dc:date>2022-07-23T06:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509710#M2377</link>
      <description>&lt;P&gt;There could be various reasons for duplicate endpoints in XDR console.&lt;BR /&gt;How are the agents being deployed on endpoints.&lt;BR /&gt;Are the agents connected XDR server using any proxy server other than broker VM?&lt;BR /&gt;If yes, you need to make sure caching is disabled for XDR urls in proxy servers. This will help to make sure proper communication happening between agent and server.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 07:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509710#M2377</guid>
      <dc:creator>creddy</dc:creator>
      <dc:date>2022-07-23T07:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509730#M2378</link>
      <description>&lt;P&gt;We have a simmilar behaviour. One PC 32 bit WIN 10 4GB RAM is going out pf ressources. So it is reinstalled by its own couple of times. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 13:21:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509730#M2378</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-07-24T13:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509739#M2379</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi MithunKT again,&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;The duplication can be a part of another installation retry on the same endpoint (e.g. reimaging)&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;What I usually do is to create a widget in Cortex XDR with the dedup filter.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;| dedup hostname desc by last_seen&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;The dedup will deduplicate same hostname but will retain who reported latest in the Cortex XDR console.&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 25 Jul 2022 01:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509739#M2379</guid>
      <dc:creator>MarvinC</dc:creator>
      <dc:date>2022-07-25T01:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509747#M2381</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191267"&gt;@MarvinC&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried creating a custom widget and I'm getting report of duplicate entries every day. But how do you remove the entries which are not needed?&lt;/P&gt;
&lt;P&gt;I have tried the "delete endpoint" option, it will remove the entry from the "All endpoints" but in the next day's report, it will reappear again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's the best solution to clean up all these unnecessary entries permanently?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 04:15:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509747#M2381</guid>
      <dc:creator>MithunKT</dc:creator>
      <dc:date>2022-07-25T04:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509774#M2382</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192854"&gt;@creddy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no proxy server placed between agent and XDR tenant communication.&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;I too investigated from the user end to find out what actually is creating duplicate entries.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I found out the below reasons;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;1) whenever multiple users login to the same endpoint(Shared host) then duplicate entries are created.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2) whenever the same user connects from different IPs(VPN, office network) then duplicate entries are created for the same endpoint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I just wanted to understand&amp;nbsp;Is this the natural behavior of XDR creating duplicate entries for the same endpoint whenever user authority or IP changes? If so;&lt;BR /&gt;How licensing will be affected for these duplicate entries?&lt;BR /&gt;How do we clean up the unnecessary duplicates automatically?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 09:58:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509774#M2382</guid>
      <dc:creator>MithunKT</dc:creator>
      <dc:date>2022-07-25T09:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509783#M2384</link>
      <description>&lt;P&gt;Hi Mithun,&lt;BR /&gt;Each agent have its own unique ID to communicate to XDR server. XDR server communicate to each endpoint agent based on this unique ID. XDR server cant communicate to multiple agents (that have same unique ID) at same time. But it communicate to multiple agents where its service started recently which could be happening in your case.&lt;/P&gt;
&lt;P&gt;From your statements, I can understand that agent might have received same unique ID to multiple endpoints when they registered to XDR server.&lt;BR /&gt;There could be a possibility where a multiple endpoint XDR Agents can receive same agent ID during its registration process.&lt;BR /&gt;So when a endpoint agent services getting started, it is able to start communicating to XDR server. The other endpoint already connected stop any connections with XDR server at this stage.&lt;/P&gt;
&lt;P&gt;This can happen because of two reasons.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;1.SSL inspection enabled on firewall.&lt;BR /&gt;If SSL decryption is enabled in the firewall, we recommend adding the Resources required for Cortex XDR access to your SSL Decryption Exclusion list for proper communication between agent and server. Refer step #7 in &lt;A title="Enable Access to Cortex XDR" href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with-cortex-xdr-pro/set-up-endpoint-protection/enable-access-to-cortex-xdr" target="_self"&gt;Enable Access to Cortex XDR&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;2.Caching enabled on proxy servers.&lt;BR /&gt;Disable cache for all PAN URLs in the proxy server for proper communication and response between agent and server. &lt;BR /&gt;Since you already mentioned there is no proxy, you can ignore this point.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;After above settings are fixed, you can verify if a new agent installed is getting unique agent ID from XDR server or not.&lt;BR /&gt;&lt;BR /&gt;Coming to cleanup existing duplicate endpoints,&amp;nbsp;&lt;SPAN&gt;machines which are already affected with this duplicate agent ID, we can force the agent to get a new agent ID(unique ID) to resolve the issue on affected machines with the following steps:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;1.Uninstall agent from the machine. &lt;BR /&gt;2.Locate and Delete agent id file from the machine using below steps.&lt;BR /&gt;For Windows: Delete agent.id file under the path C:\ProgramData\Cyvera\LocalSystem\OSPersistence\&lt;/P&gt;
&lt;P&gt;For Linux: Delete the agent.id file under the path /etc/traps/&lt;/P&gt;
&lt;P&gt;For Mac: Delete the agent.id file under the path /etc/traps/&lt;/P&gt;
&lt;P&gt;3.Delete the Endpoint entry from Endpoints -&amp;gt; All Endpoints section in the XDR Management Console.&lt;BR /&gt;4.Restart the endpoint.&lt;BR /&gt;5.Install the agent package on the endpoint and verify agent ID on the XDR console.&lt;BR /&gt;6.Verify the Agent ID value under the Endpoint ID column for the particular endpoint from Endpoints -&amp;gt; All Endpoints section in the XDR Management Console. It shows the unique agent ID for each endpoint.&lt;BR /&gt;&lt;BR /&gt;Coming to license portion, if there are any duplicates showing up in XDR console, all these duplicate may consume license.&lt;BR /&gt;&lt;BR /&gt;If you found this post helpful, please mark this as Answer/Solution.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 09:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/509783#M2384</guid>
      <dc:creator>creddy</dc:creator>
      <dc:date>2022-07-27T09:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/510036#M2393</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192854"&gt;@creddy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am referring to the steps you listed here:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1.Uninstall agent from the machine.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2.Delete agent id file from the machine using below command.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3.Disable Agent Tampering Protection and perform the below step.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We do not need to disable agent tamper protection as the agent is already uninstalled. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What can be done as an alternative is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. disable all processes (cytool runtime stop all)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. disable tamper protection (for Windows only)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3.&amp;nbsp;delete/rename the agent.id file&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. enable tamper protection (for Windows only)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5. restart all processes (cytool runtime start all)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;6. delete the old entry from Cortex XDR console.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That'll get the agent a new agent ID. See an example below:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1658914097585.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42630i678E1449EB9FDD1B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1658914097585.png" alt="bbarmanroy_0-1658914097585.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 09:30:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/510036#M2393</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-07-27T09:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/510038#M2394</link>
      <description>&lt;P&gt;Thank&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;There was a typo in my steps shared earlier. I have corrected it.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 09:23:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/510038#M2394</guid>
      <dc:creator>creddy</dc:creator>
      <dc:date>2022-07-27T09:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/510139#M2396</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192854"&gt;@creddy&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 06:07:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/510139#M2396</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-07-28T06:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate endpoint entries observed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/510141#M2397</link>
      <description>&lt;P&gt;With XDR 3.4, there is a new feature to automatically cleanup duplicate entries.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/release-information/features-introduced/features-introduced-in-2022" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/release-information/features-introduced/features-introduced-in-2022&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1658988946168.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42671i9EB43D693F19363C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1658988946168.png" alt="bbarmanroy_0-1658988946168.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 06:15:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/duplicate-endpoint-entries-observed/m-p/510141#M2397</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-07-28T06:15:58Z</dc:date>
    </item>
  </channel>
</rss>

