xAgent IDs are used by the Endpoint Security (HX) server to identify each endpoint. Cloned xAgents are Trellix Endpoint Security (HX) xAgents that have provisioned with the Endpoint Security (HX) server using the same agent ID. If cloned xAgents are not resolved, communication between the Endpoint Security (HX) server and the host endpoints becomes problematic. If multiple endpoints have the same agent ID, the Endpoint Security (HX) server cannot be sure which endpoint it is communicating with, which endpoint it is acquiring data or triage information for, which endpoint it is polling, or which endpoint it is trying to contain.
Important
In order for the Endpoint Security (HX) server and Trellix Endpoint Security (HX) xAgent software to communicate properly, each host endpoint must be assigned a unique xAgent ID.
Cloned xAgents can be accidentally created if a golden or master image has an assigned xAgent ID and is used to deploy the Trellix Endpoint Security (HX) xAgent software. When deployment is completed, all the host endpoints on which the image was deployed have the same agent ID as the golden or master image. To avoid creating a golden or master image with an assigned agent ID, .
When cloned xAgents are identified by the Endpoint Security (HX) server, a red message appears at the top of the Web UI.
.png)
To resolve them, read "Resolving Cloned Agents" in the Endpoint Security (HX) Server User Guide.
If you do not know why cloned agent IDs exist in your Endpoint Security (HX) environment or you need additional assistance, contact Trellix Technical Support.