All Hosts page

Prev Next

The All Hosts page lists all of the host endpoints monitored by the Endpoint Security (HX) Server. A host endpoint is a computer, server, or other related enterprise component on which the Trellix Endpoint Security (HX) xAgent software is installed.

Filter by drop-down boxes

You can filter the data in the grid on this page by using the Filter By drop-down boxes.

HX_HostFilters.png

Using these boxes, you can filter the data in the grid.

  • Use the Alert type drop-down menu to filter the data by the alert type. Options include All (all alerts), XPLT (Exploit), PRS (Presence), EXC (Execution), MAL (Malware), and Others.

  • Use the Protection & Remediation drop-down menu to filter the data by a specific protection or remediation action. Options include All, Blocked, Quarantined, Cleaned, and Not Blocked.

  • Use the Disposition drop-down menu to filter data by the false positive attribute. Options include All, False Positive, and Not False Positive.

  • Use the Host set drop-down menu to filter the data by host set name, active hosts, inactive hosts, or by high-value hosts. The drop-down menu lists all the host sets you have defined and options for High-value hosts, Active hosts, and Inactive hosts.

  • Use the Containment state drop-down menu to filter the data by containment state (All, Contained, Containment requested, Containment failed, or Containment ineligible).

  • Use the Agent drop-down menu to filter the data by agent version number.

Sort By options

You can sort the hosts in the grid on this page by using the Sort By options.

HX_HostsSortBy.png

Select an option to sort the hosts in the grid by the times the last system information (sysinfo) task was run for the agents on the host endpoints. Select Oldest Sysinfo to sort the hosts with the oldest sysinfo task times first. Select Most recent Sysinfo to sort the hosts with the most recent sysinfo task times first.

These options are mutually exclusive.

Paging area

The paging area indicates the range of host endpoints shown on this page of the grid and the total number of host endpoints that have provisioned with the Endpoint Security (HX) . Server.

Paging.png

Actions area

The Actions area allows you to take action on any host endpoint in the list.

Actions.png

The selection box (SelectionBox.png) to the left of the Actions drop-down box allows you to select every host endpoint in the grid. Use this with care. The number of hosts selected for an action is listed to the right of the Go button in the Actions area.

The Actions drop-down menu allows you to select an action for the host endpoints you have selected in the grid. The list of actions that can be selected varies, depending on the operating systems of the selected host endpoints. You can:

  • Delete host endpoints

  • Contain host endpoints

  • Run a malware scan on host endpoints

  • Request a file acquisition, data acquisition, or triage acquisition for host endpoints. The data acquisition scripts listed in the Actions menu vary by platform and include any custom data acquisition scripts you have created that apply to the selected endpoints.

    Triage acquisitions are not available for Linux host endpoints. (Endpoint Security 4.8 added triage support for Linux.)

    For information on creating custom data acquisition scripts, see Maintaining data acquisition scripts. For information on the supplied data acquisition scripts, see Supplied data acquisition scripts.

  • Restart Agent at host endpoints

If no hosts are selected, no actions can be selected in the Actions drop-down menu.

After selecting an action in the Actions drop-down, click Go to start the selected action.

Download option

To download a CSV file of details for all the host endpoints in the grid (on all pages), click the download (HX_Download.png) button.

The CSV file contains the following fields:

  • Agent ID—The system-generated ID for the host endpoint.

  • Hostname—The hostname of the host endpoint.

  • IP Address—The IP address of the host system.

  • Operating System (OS)—The OS of the host system.

  • Timezone—The timezone where the host system is installed.

  • Domain—The network domain of the host system.

  • User—The host user account running Agent.

  • Agent Version—The version of Agent software running on the host endpoint.

  • Malware Content Version—The version of Signature and Heuristic Detection content on the host endpoint.

  • MalwareGuard Content Version—The version of MalwareGuard content on the host endpoint.

  • Last System Audit—The timestamp of the last system audit on the host endpoint.

  • High Value Host—Indicates whether the host endpoint is defined as a high value host.

  • Containment Status—Indicates the containment state of the host endpoint.

  • Alert Count—The total count of alerts on the host endpoint.

  • Newest Alert—The timestamp of the most recent alert on the host endpoint.

  • Alert Types—A list of all alert types for the host endpoint in a semi-colon separated list.

  • Blocked Count—The number of exploits that have been blocked.

  • Newest Block—The timestamp of the most recent exploit block.

  • Block—The block status for the host endpoint.

  • Quarantine Count—The number of quarantined files on the host endpoint.

Hosts grid

The hosts grid lists all the host endpoints that have provisioned with your server.

Information is provided about each host. From left to right, the following information is provided in the columns:

Column

Description

SelectionBox.png

Select a host endpoint for which you want to take action.

ExpandIcon.png

Expand a host endpoint to see more details about the alerts and acquisitions for the host and to access more details about the host endpoint.

(Containment Status)

Icons identify the containment status of the host endpoint: requested (containment-requested.png), approved (containment-approved.png), contained (Contained.png), cancellation in progress (containment-uncontain.png), failed (containment-failed.png), and ineligible for containment (containment-ineligible.png). See Containing hosts .

(Host Type)

The type of machine: Windows (IconWinHost.png), macOS( IconOSXHost.png), Linux (linux.png), or server (IconSrvHost.png).

Agent ID and IP address

The agent ID of the host endpoint. Its IP address is listed beneath the agent ID.

Operating System and Timezone

The operating system and time zone of the host endpoint.

Workgroup

The workgroup of the host endpoint.

Agent Version and Sysinfo Time

The version number of the agent installed on the host endpoint and the last time system information (sysinfo task) was requested from the endpoint by the Endpoint Security (HX) .

Timestamps in the Web UI are presented in UTC time.

Alerts

The number of alerts that have occurred on the host endpoint and the time (minutes, hours, days) since the most recent alerts occurred.

If you hover the cursor over the alert count in this column, a breakdown of the total alert count for the host is shown.

  • EXC identifies the number of executed alerts

  • MAL identifies the number of malware alerts

  • PRS identifies the number of presence alerts

  • XPLT identifies the number of exploit alerts.

Remediation Actions

The column farthest to the right in the grid indicates how many of the following remediation actions occurred for a threat identified by an alert on the endpoint host. This column can show:

  • The number of exploits that were blocked

  • The number of malware infections that were quarantined.

  • The number of malware infections that were cleaned.

Block exploit counts only appear if the exploit prevention component of Exploit Guard is activated. For more information, see the description of the Exploit Guard policies in the Endpoint Security Agent (HX) Administration Guide.

Quarantine and clean counts only appear if exploit detection and quarantine are enabled. For more information, see the description of the malware protection policies in the Endpoint Security Agent (HX) Administration Guide.