- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
10-10-2022 09:46 PM
Based on what parameter is cortex XDR removing endpoints under endpoint administrative cleanup?
Eg if we chose hostname then will it remove the hostname found first or will delete the hostname XDR found last checked in?
And if we have 2 mac addresses and 2 IPs on what basis will it delete the endpoint?
We also observed that when we select the option of mac address while configuring the endpoint periodic clean-up settings it automatically selects hostname as well. What should we do in order to only remove duplicates using the mac address or IP and not via hostname.
10-18-2022 07:55 AM
Hello @Shashanksinha,
Endpoint Administrative Cleanup will delete duplicate entries based on the listed parameters, being the Host Name, Host IP (IPv4 only), and MAC address. This will leave only one entry, being the last endpoint that has reported to the Cortex XDR server.
To answer your first question, it will delete the hostname XDR found to be last checked in.
To answer your second question regarding duplicate IP/MAC addresses, duplications will only be removed if they contain all of the parameters selected. For your example, the endpoints would need an identical Hostname AND MAC address to be removed. This is further clarified in the gray text below the parameter selection in the Endpoint Administration Cleanup menu.
As for your issue regarding selecting only the MAC address or Host IP, are you not able to uncheck the Host Name box and check the MAC Address or Host IP box? From my personal testing, the Host Name box is checked by default when enabling the Periodic duplicate cleanup but can be disabled by clicking on its checkmark box.
For more information regarding Endpoint Administration Cleanup, please refer to the documentation along with our latest How-To Video on the topic:
View Details About an Endpoint:
Cortex XDR How-To Video: Endpoint Administration Cleanup:
10-18-2022 07:55 AM
Hello @Shashanksinha,
Endpoint Administrative Cleanup will delete duplicate entries based on the listed parameters, being the Host Name, Host IP (IPv4 only), and MAC address. This will leave only one entry, being the last endpoint that has reported to the Cortex XDR server.
To answer your first question, it will delete the hostname XDR found to be last checked in.
To answer your second question regarding duplicate IP/MAC addresses, duplications will only be removed if they contain all of the parameters selected. For your example, the endpoints would need an identical Hostname AND MAC address to be removed. This is further clarified in the gray text below the parameter selection in the Endpoint Administration Cleanup menu.
As for your issue regarding selecting only the MAC address or Host IP, are you not able to uncheck the Host Name box and check the MAC Address or Host IP box? From my personal testing, the Host Name box is checked by default when enabling the Periodic duplicate cleanup but can be disabled by clicking on its checkmark box.
For more information regarding Endpoint Administration Cleanup, please refer to the documentation along with our latest How-To Video on the topic:
View Details About an Endpoint:
Cortex XDR How-To Video: Endpoint Administration Cleanup:
01-23-2023 08:13 AM
Hello @mfakhouri,
Can you please answer one more query regarding Endpoint administration?
Can we see deleted duplicate entries because of using this feature? In management logs or audit logs or anywhere else?
01-24-2023 06:26 AM
Hi @Shashanksinha,
You would be able to see the information about any duplicate removed entries in the audit log. Please see the link below for further information on the audit log and what can be viewed there that may be of use to you.
ref:
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Monitor...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!