EDR: Multiple Windows endpoints checking in with the same sensor ID
book
Article ID: 288131
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Select a sensor in the UI redirects to the sensor page of a different sensor name
Multiple sensors reporting to the EDR cluster with the same sensor ID
The sensor report in the EDR UI changes hostnames as each endpoint checks in at different times
Doing a process search for the sensor ID will result in multiple hostnames listed under the search facets
Environment
EDR Server: 6.x and Higher
EDR Sensor: All supported versions
EDR Sensors imaged using a common gold disk
Microsoft Windows: All Supported Versions
Gold disk is pre-configured with a static sensor ID
Cause
The master image the endpoints are based on registered and set the sensor ID. All sensors based on that image will check-in with the same ID.
Resolution
Update each problematic endpoint to reset their sensor ID. This will result in the endpoint receiving a fresh ID the next time it checks in - https://community.carbonblack.com/t5/Knowledge-Base/EDR-Sensor-How-to-reset-sensor-ID-in-Windows/ta-p/108551
Update the gold disk image to prevent future sensors from registering with the same ID
The master gold disk must be re-generated with an empty sensor ID so that each new endpoint can have a unique one generated for it by the EDR server
Process event data will still show the correct sensor name and information, but selecting the sensor name in Process Analysis may still redirect to a different endpoint.
Resetting the sensor ID will cause the sensor to register as a new endpoint. This means old sensor data will not be linked to the new sensor. A workaround to find historical sensor data is to search for the computer name in process search.