Cancel a containment request

Prev Next

You can cancel a containment request for a host endpoint at any time.

Once the containment request is canceled, no further containment actions are allowed for the endpoint, until its agent has checked back in with the HX appliance and completed the cancellation task.

Prerequisites
  • Admin, investigator, senior analyst, or analyst access

  • A containment request is ongoing. See Requesting containment.

To cancel a containment request:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select the checkbox to the left of a host endpoint for which containment is requested, but not approved.

  3. Select Cancel containment request from the Actions menu.

  4. Click Go.

You can also cancel containment from the host alert details and host details sections of the Hosts page.

To cancel containment of a host endpoint from the host alert details or host details sections:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Request host details by clicking on the Expand icon (ExpandIcon.png) associated with a host.

  3. At the top of the details page, click Cancel containment request.

After you cancel a containment request for a host, the host's status changes to Stopping containment.

When the cancellation succeeds, all containment icons disappear from beside the hostname. The Contained Hosts area of the Dashboard shows one fewer hosts in the number of hosts requested for containment.

If the cancellation fails for a host, its containment status changes to Containment cancellation failed. The containment cancellation failed icon appears beside the hostname on every page where the host is listed.