The All Hosts page lists all of the host endpoints monitored by the Endpoint Security (HX) Server. A host endpoint is a computer, server, or other related enterprise component on which the Trellix Endpoint Security (HX) xAgent software is installed.
Filter by drop-down boxes
You can filter the data in the grid on this page by using the Filter By drop-down boxes.
.png)
Using these boxes, you can filter the data in the grid.
Use the Alert type drop-down menu to filter the data by the alert type. Options include All (all alerts), XPLT (Exploit), PRS (Presence), EXC (Execution), MAL (Malware), and Others.
Use the Protection & Remediation drop-down menu to filter the data by a specific protection or remediation action. Options include All, Blocked, Quarantined, Cleaned, and Not Blocked.
Use the Disposition drop-down menu to filter data by the false positive attribute. Options include All, False Positive, and Not False Positive.
Use the Host set drop-down menu to filter the data by host set name, active hosts, inactive hosts, or by high-value hosts. The drop-down menu lists all the host sets you have defined and options for High-value hosts, Active hosts, and Inactive hosts.
Use the Containment state drop-down menu to filter the data by containment state (All, Contained, Containment requested, Containment failed, or Containment ineligible).
Use the Agent drop-down menu to filter the data by agent version number.
Sort By options
You can sort the hosts in the grid on this page by using the Sort By options.
.png)
Select an option to sort the hosts in the grid by the times the last system information (sysinfo) task was run for the agents on the host endpoints. Select Oldest Sysinfo to sort the hosts with the oldest sysinfo task times first. Select Most recent Sysinfo to sort the hosts with the most recent sysinfo task times first.
These options are mutually exclusive.
Paging area
The paging area indicates the range of host endpoints shown on this page of the grid and the total number of host endpoints that have provisioned with the Endpoint Security (HX) . Server.
.png)
Actions area
The Actions area allows you to take action on any host endpoint in the list.
.png)
The selection box (
) to the left of the Actions drop-down box allows you to select every host endpoint in the grid. Use this with care. The number of hosts selected for an action is listed to the right of the Go button in the Actions area.
The Actions drop-down menu allows you to select an action for the host endpoints you have selected in the grid. The list of actions that can be selected varies, depending on the operating systems of the selected host endpoints. You can:
Delete host endpoints
Contain host endpoints
Run a malware scan on host endpoints
Request a file acquisition, data acquisition, or triage acquisition for host endpoints. The data acquisition scripts listed in the Actions menu vary by platform and include any custom data acquisition scripts you have created that apply to the selected endpoints.
Triage acquisitions are not available for Linux host endpoints. (Endpoint Security 4.8 added triage support for Linux.)
For information on creating custom data acquisition scripts, see Maintaining data acquisition scripts. For information on the supplied data acquisition scripts, see Supplied data acquisition scripts.
Restart Agent at host endpoints
If no hosts are selected, no actions can be selected in the Actions drop-down menu.
After selecting an action in the Actions drop-down, click Go to start the selected action.
Download option
To download a CSV file of details for all the host endpoints in the grid (on all pages), click the download (
) button.
The CSV file contains the following fields:
Agent ID—The system-generated ID for the host endpoint.
Hostname—The hostname of the host endpoint.
IP Address—The IP address of the host system.
Operating System (OS)—The OS of the host system.
Timezone—The timezone where the host system is installed.
Domain—The network domain of the host system.
User—The host user account running Agent.
Agent Version—The version of Agent software running on the host endpoint.
Malware Content Version—The version of Signature and Heuristic Detection content on the host endpoint.
MalwareGuard Content Version—The version of MalwareGuard content on the host endpoint.
Last System Audit—The timestamp of the last system audit on the host endpoint.
High Value Host—Indicates whether the host endpoint is defined as a high value host.
Containment Status—Indicates the containment state of the host endpoint.
Alert Count—The total count of alerts on the host endpoint.
Newest Alert—The timestamp of the most recent alert on the host endpoint.
Alert Types—A list of all alert types for the host endpoint in a semi-colon separated list.
Blocked Count—The number of exploits that have been blocked.
Newest Block—The timestamp of the most recent exploit block.
Block—The block status for the host endpoint.
Quarantine Count—The number of quarantined files on the host endpoint.
Hosts grid
The hosts grid lists all the host endpoints that have provisioned with your server.
Information is provided about each host. From left to right, the following information is provided in the columns:
Column | Description |
|---|---|
![]() | Select a host endpoint for which you want to take action. |
![]() | Expand a host endpoint to see more details about the alerts and acquisitions for the host and to access more details about the host endpoint. |
(Containment Status) | Icons identify the containment status of the host endpoint: requested ( |
(Host Type) | The type of machine: Windows ( |
Agent ID and IP address | The agent ID of the host endpoint. Its IP address is listed beneath the agent ID. |
Operating System and Timezone | The operating system and time zone of the host endpoint. |
Workgroup | The workgroup of the host endpoint. |
Agent Version and Sysinfo Time | The version number of the agent installed on the host endpoint and the last time system information (sysinfo task) was requested from the endpoint by the Endpoint Security (HX) . Timestamps in the Web UI are presented in UTC time. |
Alerts | The number of alerts that have occurred on the host endpoint and the time (minutes, hours, days) since the most recent alerts occurred. If you hover the cursor over the alert count in this column, a breakdown of the total alert count for the host is shown.
|
Remediation Actions | The column farthest to the right in the grid indicates how many of the following remediation actions occurred for a threat identified by an alert on the endpoint host. This column can show:
Block exploit counts only appear if the exploit prevention component of Exploit Guard is activated. For more information, see the description of the Exploit Guard policies in the Endpoint Security Agent (HX) Administration Guide. Quarantine and clean counts only appear if exploit detection and quarantine are enabled. For more information, see the description of the malware protection policies in the Endpoint Security Agent (HX) Administration Guide. |
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)