<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint administrative cleanup in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/517392#M3031</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Based on what parameter is cortex XDR removing endpoints under endpoint administrative cleanup?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Eg if we chose hostname then will it remove the hostname found first or will delete the hostname XDR found last checked in?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;And if we have 2 mac addresses and 2 IPs on what basis will it delete the endpoint?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We also observed that when we select the option of mac address while configuring the endpoint periodic clean-up settings it automatically selects hostname as well. What should we do in order to only remove duplicates using the mac address or IP and not via hostname.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Oct 2022 04:46:20 GMT</pubDate>
    <dc:creator>Shashanksinha</dc:creator>
    <dc:date>2022-10-11T04:46:20Z</dc:date>
    <item>
      <title>Endpoint administrative cleanup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/517392#M3031</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Based on what parameter is cortex XDR removing endpoints under endpoint administrative cleanup?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Eg if we chose hostname then will it remove the hostname found first or will delete the hostname XDR found last checked in?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;And if we have 2 mac addresses and 2 IPs on what basis will it delete the endpoint?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We also observed that when we select the option of mac address while configuring the endpoint periodic clean-up settings it automatically selects hostname as well. What should we do in order to only remove duplicates using the mac address or IP and not via hostname.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 04:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/517392#M3031</guid>
      <dc:creator>Shashanksinha</dc:creator>
      <dc:date>2022-10-11T04:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint administrative cleanup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/518228#M3034</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello &lt;/SPAN&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Endpoint Administrative Cleanup will delete duplicate entries based on the listed parameters, being the Host Name, Host IP (IPv4 only), and MAC address. This will leave only one entry, being the last endpoint that has reported to the Cortex XDR server.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To answer your first question, it will delete the hostname XDR found to be last checked in.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To answer your second question regarding duplicate IP/MAC addresses, duplications will only be removed if they contain all of the parameters selected. For your example, the endpoints would need an identical Hostname AND MAC address to be removed. This is further clarified in the gray text below the parameter selection in the Endpoint Administration Cleanup menu.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_0-1666104469191.png" style="width: 833px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44712i1085263F1060FE58/image-dimensions/833x177/is-moderation-mode/true?v=v2" width="833" height="177" role="button" title="mfakhouri_0-1666104469191.png" alt="mfakhouri_0-1666104469191.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As for your issue regarding selecting only the MAC address or Host IP, are you not able to uncheck the Host Name box and check the MAC Address or Host IP box? From my personal testing, the Host Name box is checked by default when enabling the Periodic duplicate cleanup but can be disabled by clicking on its checkmark box.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_1-1666104469174.gif" style="width: 776px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44713i9E111EF8D87041AB/image-dimensions/776x245/is-moderation-mode/true?v=v2" width="776" height="245" role="button" title="mfakhouri_1-1666104469174.gif" alt="mfakhouri_1-1666104469174.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information regarding Endpoint Administration Cleanup, please refer to the documentation along with our latest How-To Video on the topic:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;View Details About an Endpoint:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoints/view-details-for-an-endpoint" target="_blank"&gt;&lt;SPAN&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoints/view-details-for-an-endpoint&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cortex XDR How-To Video: Endpoint Administration Cleanup:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-endpoint-administration-cleanup/ta-p/513765" target="_blank"&gt;&lt;SPAN&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-endpoint-administration-cleanup/ta-p/513765&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 14:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/518228#M3034</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-10-18T14:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint administrative cleanup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/528189#M3442</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223246"&gt;@mfakhouri&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can you please answer one more query regarding Endpoint administration?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can we see deleted duplicate entries because of using this feature? In management logs or audit logs or anywhere else?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 16:13:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/528189#M3442</guid>
      <dc:creator>Shashanksinha</dc:creator>
      <dc:date>2023-01-23T16:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint administrative cleanup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/528333#M3447</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You would be able to see the information about any duplicate removed entries in the audit log.&amp;nbsp; Please see the link below for further information on the audit log and what can be viewed there that may be of use to you.&lt;BR /&gt;ref:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Monitor-Administrative-Activity" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Monitor-Administrative-Activity&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 14:26:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-administrative-cleanup/m-p/528333#M3447</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-01-24T14:26:47Z</dc:date>
    </item>
  </channel>
</rss>

