Agent Spoofing alerts due to mismatched agent id's since 9.2.1 update

Since I updated this afternoon to 9.2.1 this alert triggers continuously for all my 3 agents.

Grtz

@willemdh is it agent-less related ? (host.name starts with agentless-*) if so we pushed a tuning to address this [Tuning] Agent Spoofing - Mismatched Agent ID by shashank-elastic · Pull Request #5295 · elastic/detection-rules · GitHub

1 Like

@Samir_Bousseaden Thanks for your answer. No it’s not agentless related. It is Elastic Security serverless related.

:waving_hand: @willemdh Do you mind attaching the sample alerts or reaching out on our community Slack if you feel more comfortable?

1 Like

Yeah I have exactly the same problem for all my windows and mac hosts. Updated the rule but that doesn’t help since its only solves the serverless issue. Seems like a bug maybe.

1 Like