In the Event Details side panel, click View Host Details. The All Hosts page opens in a new tab.
The All Hosts page displays the following options:
Filter by drop-down boxes
Sort by options
Actions area
Host details
Filter by drop-down boxes
You can filter the data in the grid on this page by using the Filter By drop-down boxes.
Using these boxes, you can filter the data in the grid.
Use the Host set drop-down menu to filter the data by host set name, active hosts, inactive hosts, or by high-value hosts. The drop-down menu lists all the host sets you have defined and options for High-value hosts, Active hosts, and Inactive hosts.
Use the Containment state drop-down menu to filter the data by containment state (All, Contained, Containment requested, Containment failed, or Containment ineligible).
Use the Agent drop-down menu to filter the data by agent version number.
Sort By options
You can sort the hosts in the grid on this page by using the Sort By options.

Select an option to sort the hosts in the grid by the times the last system information (sysinfo) task was run for the agents on the host endpoints. Select Oldest Sysinfo to sort the hosts with the oldest sysinfo task times first. Select Most recent Sysinfo to sort the hosts with the most recent sysinfo task times first.
These options are mutually exclusive.
Actions area
The Actions area allows you to take action on any host endpoint in the list.

The selection box (
) to the left of the Actions drop-down box allows you to select every host endpoint in the grid. Use this with care. The number of hosts selected for an action is listed to the right of the Go button in the Actions area.
The Actions drop-down menu allows you to select an action for the host endpoints you have selected in the grid. The list of actions that can be selected varies, depending on the operating systems of the selected host endpoints. You can:
Run a Malware Scan — Initiates an immediate on-demand scan of the selected host.
Restart Agent — Restarts the agent on the selected host.
Acquire — Accesses data collection options, including Single File, Triage, Multiple Files, Standard/Comprehensive Investigative Details, Quick File Listing, and Agent Diagnostics.
Delete host — Removes the selected host from the management list.
If no hosts are selected, no actions can be selected in the Actions drop-down menu.
After selecting an action in the Actions drop-down, click Go to start the selected action.
Download option
To download a CSV file of details for all the host endpoints in the grid (on all pages), click the download (
) button.
The CSV file contains the following fields:
Agent ID—The system-generated ID for the host endpoint.
Hostname—The hostname of the host endpoint.
IP Address—The IP address of the host system.
Operating System (OS)—The OS of the host system.
Timezone—The timezone where the host system is installed.
Domain—The network domain of the host system.
User—The host user account running Agent.
Agent Version—The version of Agent software running on the host endpoint.
Malware Protection Status—The current status of malware protection on the host endpoint.
Signature and Heuristic Detection status—Indicates whether signature-based and heuristic detection is enabled or disabled.
Malware Guard status—The current status of the Malware Guard engine.
Malware AV Content Version—The version of Signature and Heuristic Detection content on the host endpoint.
MalwareGuard Content Version—The version of MalwareGuard content on the host endpoint.
Security Content Intel Version— The version of Security Content on the host endpoint.
Security Content Intel Updated—The timestamp of the most recent Security Content update on the host endpoint.
Last System Audit—The timestamp of the last system audit on the host endpoint.
Agent Last Poll—The timestamp of the most recent communication between the agent and the management console.
High Value Host—Indicates whether the host endpoint is defined as a high value host.
Containment Status—Indicates the containment state of the host endpoint.
Alert Count—The total count of alerts on the host endpoint.
Newest Alert—The timestamp of the most recent alert on the host endpoint.
Alert Types—A list of all alert types for the host endpoint in a semi-colon separated list.
Blocked Count—The number of exploits that have been blocked.
Newest Block—The timestamp of the most recent exploit block.
Block—The block status for the host endpoint.
Quarantine Count—The number of quarantined files on the host endpoint.
Hosts grid
The hosts grid lists all the host endpoints that have provisioned with your server.
Information is provided about each host. From left to right, the following information is provided in the columns:
Column | Description |
|---|---|
![]() | Select a host endpoint for which you want to take action. |
![]() | Expand a host endpoint to see more details about the alerts and acquisitions for the host and to access more details about the host endpoint. |
(Containment Status) | Icons identify the containment status of the host endpoint: requested ( |
(Host Type) | The type of machine: Windows ( |
Agent ID and IP address | The agent ID of the host endpoint. Its IP address is listed beneath the agent ID. |
Operating System and Timezone | The operating system and time zone of the host endpoint. |
Workgroup | The workgroup of the host endpoint. |
Agent Version and Sysinfo Time | The version number of the agent installed on the host endpoint and the last time system information (sysinfo task) was requested from the endpoint by the Endpoint Security (HX) . Timestamps in the Web UI are presented in UTC time. |
Host details
Select the plus (+) icon to expand the host details panel for comprehensive information on the host.
General section
This section of the Host Details page provides general information about the host endpoint.
Field | Description |
|---|---|
Active Directory: Domain Components | A list of all domains assigned to the host. |
Active Directory: Organizational Units | A list of all organizational units assigned to the host. |
Active Directory: Common Names | Common names assigned to the host. |
Agent ID | The unique agent ID assigned to the host endpoint. |
Agent Version | The version of the agent installed on the host endpoint. |
Bit Level | The bitness of the host endpoint. |
Domain | The domain of the host endpoint. |
GMT Offset | The GMT offset time of the host endpoint. |
IP Address | The IP address of the host endpoint. |
Client IP | The IP address of the EDRF Client. |
Initial Agent Connection | The UTC timestamp identifying when the endpoint initially provisioned with the Endpoint Security (HX). |
Kernel (Linux only) | The Linux kernel version running on the endpoint. |
KernelServices Status | The status of the Linux KernelServices on the endpoint. |
Last Sysinfo | The UTC timestamp identifying when the last system information task (sysinfo) reported results from the agent on the host endpoint. See the comparison of this time with the Last Sysinfo (skewed) time next. |
Agent Last Poll | The UTC timestamp identifying when the agent last polled for audit jobs. |
Last Sysinfo (skewed) | A skewed UTC timestamp identifying when the last sysinfo task reported results from the agent on the host endpoint. This value is skewed to include the calculated difference between the actual clock time on the host endpoint and the clock time on the Endpoint Security (HX). These clock times can be different because each machine may be affected by different things, such as clock delays, network delays, and the service used for time synchronization. For the value in this field, Endpoint Security (HX) treats the server time as the true time and skews the time with the calculated difference between the server and the endpoint times. The skewed time should be close, if not the same, as the unskewed Last Sysinfo time, but if they are different, the skewed time should more accurately reflect the actual agent time when the last sysinfo task reported results to the server. |
OS | The operating system installed on the host endpoint. |
Patch | The patch level of the operating system installed on the host endpoint. |
Timezone | The UTC time zone of the host endpoint. |
Malware Protection section
Host Details provides malware protection information for the host endpoint, which is divided into Signature and Heuristic Detection and MalwareGuard Detection.
Field | Description |
|---|---|
Malware Engine Version | The malware engine version used for malware protection. |
Malware Content Version | The version of Signature and Heuristic Detection content on the host endpoint. The version number of the malware protection definitions on the host endpoint. |
Last Updated | The timestamp when the malware protection definitions were last updated on the host endpoint. |
MalwareGuard Engine Version | The MalwareGuard engine version used for malware protection. |
MalwareGuard Content Version | The version of MalwareGuard content on the host endpoint. |
Last Updated | The timestamp when the MalwareGuard content was last updated on the host endpoint. |
Exploit Guard Version | The version of Exploit Guard software currently running on the host endpoint. |
Engine Version | The engine version used for exploit protection on the host endpoint. |
DTI Config Version | The version of the Data Threat Intelligence (DTI) configuration on the host endpoint. |
Content Rules Version | The version of the exploit protection content rules on the host endpoint |
Content Whitelist Version | The version of the exploit protection content whitelist on the host endpoint. |
Security Content section
Field | Description |
|---|---|
Intel Version | The version number of the latest installed security content. |
Intel Last Updated | The UTC time the security content was last updated. |
Operating System section
Field | Description |
|---|---|
OS, Build & Patch | The operating system, version and patch installed on the host endpoint. |
Install Date | The timestamp identifying when the operating system was installed on the host endpoint. |
Product ID | The host endpoint product ID. |
Processor | The processor driver installed for the host endpoint. |
Processor Type | The processor type of the host endpoint. |
System Timestamp | The system UTC time of the host endpoint. |
Machine Name | The machine name of the host endpoint. |
System Directory | The location of the system directory on the host endpoint. |
Up Time | The number of seconds the host endpoint has been running. |
BIOS section (Windows only)
Field | Description |
|---|---|
Release Date | The date of the Basic Input/Output System (BIOS) on the host endpoint. |
Version | The version of the BIOS on the host endpoint. |
Physical Memory section
Field | Description |
|---|---|
Total | The total memory of the host endpoint. |
Available | The amount of memory available on the host endpoint. |
User section
Field | Description |
|---|---|
Primary User | The primary user of the host endpoint. |
Registered Org (Windows only) | The registered organization of the host endpoint. |
Registered Owner (Windows only) | The registered owner of the host endpoint. |
Network Adapters section
Field | Description |
|---|---|
DHCP Address | (Windows only) The Dynamic Host Configuration protocol (DHCP) of the network adapter on the host endpoint. |
IP Address | The IP address of the network adapter on the host endpoint. |
IP Gateway Address | The IP gateway address of the network adapter on the host endpoint. |
Lease Expiry Date | The date the lease for the network adapter expires. |
Lease Obtained Date | The date the lease for the network adapter was obtained. |
MAC | The media access control (MAC) address of the network adapter. |
Name | The name of the network adapter on the host endpoint. |
Subnet Mask | The subnet mask of the network adapter on the host endpoint. |










