Use the General information tab to get an overview of the agent status.
The information on the General information tab is designed to confirm expectations and answer basic questions. Are the agent processes and drivers running? What product versions are installed? What is the current operation mode and policy?
Agent processes and drivers
One of the most important questions in troubleshooting is, "Is everything running as expected?" The Agent processes and Drivers sections show this at a glance. The checkboxes show if the process is enabled; the colored dot shows if it is running. If the process or driver is down, the text box gives information on what is wrong.
The default maximum memory is 150 MB. A high value for this parameter can indicate problems.
Term | Process | Expected status |
|---|---|---|
Fcag | Trellix DLP Endpoint agent (client) | enabled; running |
Fcags | Trellix DLP Endpoint agent service | enabled; running |
Fcagte | Trellix DLP Endpoint text extractor | enabled; running |
Fcagwd | Trellix DLP Endpoint watch dog | enabled; running |
Fcagd | Trellix DLP Endpoint agent with automatic dump | enabled only for troubleshooting. |
Term | Process | Expected status |
|---|---|---|
Hdlpflt | Trellix DLP Endpoint minifilter driver (enforces removable storage device rules) | enabled; running |
Hdlpevnt | Trellix DLP Endpoint event | enabled; running |
Hdlpdbk | Trellix DLP Endpoint device filter driver (enforces device Plug and Play rules) | can be disabled in configuration |
Hdlpctrl | Trellix DLP Endpoint control | enabled; running |
Hdlhook | Trellix DLP Endpoint Hook driver | enabled; running |
Agent info section
Operation mode and Agent status are expected to match. The Agent Connectivity indication, together with EPO address, can be useful in troubleshooting.
Note
Agent Connectivity has three options: online, offline, or connected by VPN.