Checking the agent status

Prev Next

Use the General information tab to get an overview of the agent status.

The information on the General information tab is designed to confirm expectations and answer basic questions. Are the agent processes and drivers running? What product versions are installed? What is the current operation mode and policy?

Agent processes and drivers

One of the most important questions in troubleshooting is, "Is everything running as expected?" The Agent processes and Drivers sections show this at a glance. The checkboxes show if the process is enabled; the colored dot shows if it is running. If the process or driver is down, the text box gives information on what is wrong.

The default maximum memory is 150 MB. A high value for this parameter can indicate problems.

Agent processes

Term

Process

Expected status

Fcag

Trellix DLP Endpoint agent (client)

enabled; running

Fcags

Trellix DLP Endpoint agent service

enabled; running

Fcagte

Trellix DLP Endpoint text extractor

enabled; running

Fcagwd

Trellix DLP Endpoint watch dog

enabled; running

Fcagd

Trellix DLP Endpoint agent with automatic dump

enabled only for troubleshooting.



Drivers

Term

Process

Expected status

Hdlpflt

Trellix DLP Endpoint minifilter driver (enforces removable storage device rules)

enabled; running

Hdlpevnt

Trellix DLP Endpoint event

enabled; running

Hdlpdbk

Trellix DLP Endpoint device filter driver (enforces device Plug and Play rules)

can be disabled in configuration

Hdlpctrl

Trellix DLP Endpoint control

enabled; running

Hdlhook

Trellix DLP Endpoint Hook driver

enabled; running



Agent info section

Operation mode and Agent status are expected to match. The Agent Connectivity indication, together with EPO address, can be useful in troubleshooting.

Note

Agent Connectivity has three options: online, offline, or connected by VPN.