Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5911

How Does the Windows Agents Determine Agent Id etc.

$
0
0

We are trying to use InstantClones through VMware to deploy our VDI desktops.  The issue I'm having is when I search the lem by hostname (ourVM-) I see a single entry, that changes every few seconds.

I ran a nDepth Search on InternalDuplicateConnection with thw same beginning of the hostname, "ourVM-" and I get like 1500 events in 30 minutes.

 

Notice below the EventInfo hostname is different than the AgentAddress.

 

          

EventInfoInsertionIPManagerDetectionIPInsertionTimeDetectionTimeToolAliasExtraneousInfoUniqueIDAgentAddress
OURVM-0638.MyDomain.commylemmylemn.n.n.nMon Jun 19 16:37:43 GMT-0700 2017Mon Jun 19 16:37:43 GMT-0700 2017TriGeoAgent is already online323637333231363OURVM-0629.MyDomain.com / 139.231.111.143
OURVM-0592.MyDomain.commylemmylemn.n.n.nMon Jun 19 16:37:46 GMT-0700 2017Mon Jun 19 16:37:46 GMT-0700 2017TriGeoAgent is already online323637333231373OURVM-0596.MyDomain.com / 139.231.111.165
OURVM-0017.MyDomain.commylemmylemn.n.n.nMon Jun 19 16:37:45 GMT-0700 2017Mon Jun 19 16:37:45 GMT-0700 2017TriGeoAgent is already online323637333231373

OURVM-0067.MyDomain.com / 139.231.111.199

I hope I am not confusing.  I'm just trying to figure out what I need to do, or what I need to have the admins that deploy the VMs do to correct this.

 

We have one network running LEM version 6.3.1 hotfix4, the other two networks are running LEM version 6.2.1 with the same results.

 

Thank You

 

Steve


Viewing all articles
Browse latest Browse all 5911

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>