Resolving cloned agents

Prev Next

Agent IDs are used by the Endpoint Security (HX) to identify each endpoint. Cloned agents are Trellix Endpoint Security (HX) Agents that have provisioned with the Endpoint Security (HX) using the same agent ID. If cloned agents are not resolved, communication between the Endpoint Security (HX) and the host endpoints becomes problematic. When multiple endpoints have the same agent ID, the Endpoint Security (HX) cannot uniquely identify an individual endpoint to poll, contain, acquire data or triage information for, or communicate with.

Important

In order for the Endpoint Security (HX) and Trellix Endpoint Security (HX) xAgent software to communicate properly, each host endpoint must be assigned a unique agent ID.

Cloned agents can be accidentally created if a golden or master image is assigned an agent ID before the image is used to deploy the Endpoint Security (HX) xAgent software. When deployment is completed, all the host endpoints on which the image was deployed have the same agent ID as the golden or master image. To avoid creating a golden or master image with an assigned agent ID, see "Installing Agents Using a Golden or Master Image" in the Endpoint Security Agent (HX) Administration Guide.

Prerequisites
  • Admin access

When cloned agents are identified by the Endpoint Security (HX), a red message appears at the top of the Endpoint Security (HX) Web UI.

clonedagtwarn.png

To manage cloned agent IDs from the Web UI:

  1. Click Click here to review them in the red message at the top of the Endpoint Security (HX) Web UI page. A Hosts page appears showing only the hosts with cloned agent IDs.

  2. Do either of the following things.

    • Select a cloned host on the Hosts page. Then select Resolve Cloned Agent ID in the Actions drop-down box and click Go.

    • Expand a host by clicking on its expand icon (ExpandIcon.png). The Host Details section of the Hosts page appears with a Resolve Cloned Agent ID button at the top of the page. Click the Resolve Cloned Agent ID button.

      clonedagtresolve.png

    The Resolve Cloned Agent IDs panel appears.

    clonedagtdialog.png
  3. Select an option:

    • Blacklisting the cloned agent ID deletes the clone from the Endpoint Security (HX) database, deletes any acquisition, triage, or alert data associated with the clone, and causes the Endpoint Security (HX) to generate a new agent ID for the selected host endpoint when its Endpoint Security (HX) xAgent next polls the appliance. For more information about agent polling, see "Configuring Agent Polling Settings" in the Endpoint Security Agent (HX) Administration Guide.

    • Dismissing the warnings indicates that you have resolved the cloned agent problem by other means. You might choose this option if you know exactly how the cloned agent was created, have removed the cloned agent software from the affected host endpoint, and are sure agent will not poll again using the cloned agent ID.

  4. Click Apply.

If you do not know why cloned agent IDs exist in your Endpoint Security (HX) environment or for additional assistance, contact Trellix Technical Support.