# Agent Spoofing alerts due to mismatched agent id's since 9.2.1 update

**URL:** <https://discuss.elastic.co/t/agent-spoofing-alerts-due-to-mismatched-agent-ids-since-9-2-1-update/383420>\
**Category:** Elastic Security\
**Created:** [November 13, 2025, 12:55pm UTC](https://discuss.elastic.co/t/agent-spoofing-alerts-due-to-mismatched-agent-ids-since-9-2-1-update/383420 "2025-11-13T12:55:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 13, 2025, 12:55pm UTC](https://discuss.elastic.co/t/agent-spoofing-alerts-due-to-mismatched-agent-ids-since-9-2-1-update/383420/1 "2025-11-13T12:55:19Z")

</div>

> **[Agent Spoofing - Mismatched Agent ID | Prebuilt detection rules reference](https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/cross-platform/defense_evasion_agent_spoofing_mismatched_id)**
>
> Detects events that have a mismatch on the expected event agent ID. The status "agent\_id\_mismatch/mismatch" occurs when the expected agent ID associated...

Since I updated this afternoon to 9.2.1 this alert triggers continuously for all my 3 agents.

Grtz

---

<div class="post-metadata">

**Author:** ![Samir\_Bousseaden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samir_bousseaden/32/135089_2.png) [@Samir\_Bousseaden](https://discuss.elastic.co/u/Samir_Bousseaden)\
**Post date:** [November 13, 2025, 3:57pm UTC](https://discuss.elastic.co/t/agent-spoofing-alerts-due-to-mismatched-agent-ids-since-9-2-1-update/383420/2 "2025-11-13T15:57:42Z")

</div>

@willemdh is it agent-less related ? (host.name starts with agentless-\*) if so we pushed a tuning to address this [[Tuning] Agent Spoofing - Mismatched Agent ID by shashank-elastic · Pull Request #5295 · elastic/detection-rules · GitHub](https://github.com/elastic/detection-rules/pull/5295/files)

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 13, 2025, 4:11pm UTC](https://discuss.elastic.co/t/agent-spoofing-alerts-due-to-mismatched-agent-ids-since-9-2-1-update/383420/3 "2025-11-13T16:11:30Z")

</div>

@Samir_Bousseaden Thanks for your answer. No it’s not agentless related. It is Elastic Security serverless related.

---

<div class="post-metadata">

**Author:** ![Mika\_Ayenson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mika_ayenson/32/111469_2.png) [@Mika\_Ayenson](https://discuss.elastic.co/u/Mika_Ayenson)\
**Post date:** [November 13, 2025, 4:36pm UTC](https://discuss.elastic.co/t/agent-spoofing-alerts-due-to-mismatched-agent-ids-since-9-2-1-update/383420/4 "2025-11-13T16:36:20Z")

</div>

👋 @willemdh Do you mind attaching the sample alerts or reaching out on our community [Slack](https://elasticstack.slack.com/archives/C016E72DWDS) if you feel more comfortable?

---

<div class="post-metadata">

**Author:** ![Rorb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rorb/32/98764_2.png) [@Rorb](https://discuss.elastic.co/u/Rorb)\
**Post date:** [November 20, 2025, 10:25pm UTC](https://discuss.elastic.co/t/agent-spoofing-alerts-due-to-mismatched-agent-ids-since-9-2-1-update/383420/5 "2025-11-20T22:25:19Z")

</div>

Yeah I have exactly the same problem for all my windows and mac hosts. Updated the rule but that doesn’t help since its only solves the serverless issue. Seems like a bug maybe.
