Create an Agent Version Summary query best practice

Prev Next

Find systems with old Trellix Agent versions using a query to generate a list of all agent versions that are older than the current version.

For details about product features, usage, and best practices, click ? or Help.

  1. To duplicate the Agent Versions Summary query, select MenuReportingQueries & Reports, then find the Agent Versions Summary query in the list.

  2. In the Actions column of the Agent Versions Summary query, click Duplicate. In the Duplicate dialog box, change the name, select a group to receive the copy of the query, then click OK.

  3. Navigate to the duplicate query that you created, then click Edit in the Actions column to display the preconfigured Query Builder.

  4. In the Chart tab, in the Display Results As list, expand List and select Table.

  5. To configure the Sort by fields, in the Configure Chart: Table page, select Product Version (Agent) under Agent Properties in the list, click Value (Descending), then click Next.

  6. In the Columns tab, remove all preconfigured columns except System Name, then click Next.

  7. In the Filter tab, configure these columns, then click Run:

    1. For the Property column, select Product Version (Agent) from the Available Properties list.

    2. For the Comparison column, select Less than.

    3. For the Value column, type the current Trellix Agent version number.

      Note

      Typing the current agent number means that the query finds only versions "earlier than" that version number.

Now your new query can run from a product deployment to update the old Trellix Agent versions.