Hi,
We are using Velociraptor in AWS with two Linux VMs, one running Velociraptor and the other a client and two Windows clients.
They came from the same base OS AMI images as appropriate. Something odd is happening with the Windows instances, first it picks up one of the Windows VMs and we can see its entry when we request the clients but then when we pick up the second one it overwrites the entry for the first one like this:
[{'client_id': 'C.95663721cc039b77', 'agent_information': {'version': '2021-02-08T20:10:48+10:00', 'name': 'velociraptor', 'build_time': ''}, 'os_info': {'system': 'windows', 'node': '', 'release': 'Microsoft Windows Server 2008 R2 Standard Service Pack 16.1.7601 Build 7601', 'version': '', 'machine': 'amd64', 'kernel': '', 'fqdn': 'INTERNAL1', 'install_date': 0, 'libc_ver': '', 'architecture': ''}, 'first_seen_at': 1621573214, 'last_seen_at': 1621573302949746, 'last_booted_at': 0, 'last_clock': 0, 'last_crash_at': 0, 'last_ip': '10.0.30.179:52863', 'last_interrogate_flow_id': 'F.C2JJSNI9OSTA4', 'last_ip_class': 'EXTERNAL', 'labels': []},
[{'client_id': 'C.95663721cc039b77', 'agent_information': {'version': '2021-02-08T20:10:48+10:00', 'name': 'velociraptor', 'build_time': ''}, 'os_info': {'system': 'windows', 'node': '', 'release': 'Microsoft Windows Server 2008 R2 Standard Service Pack 16.1.7601 Build 7601', 'version': '', 'machine': 'amd64', 'kernel': '', 'fqdn': 'INTERNAL1', 'install_date': 0, 'libc_ver': '', 'architecture': ''}, 'first_seen_at': 1621573214, 'last_seen_at': 1621573310330303, 'last_booted_at': 0, 'last_clock': 0, 'last_crash_at': 0, 'last_ip': '10.0.30.37:51879', 'last_interrogate_flow_id': 'F.C2JJSNI9OSTA4', 'last_ip_class': 'EXTERNAL', 'labels': []},
The 10.0.30.179 host does have the hostname INTERNAL1 but 10.0.30.37 has a different hostname.
Does anyone have any idea on what is causing this strange behaviour?
TIA.