Endpoint Security (HX) lets you create host groups for a standard set based on expressions for some of the host group filters. Expressions are search filters that allow you to further filter a host group by searching among relatively large metadata values. They are available only for some filters.
You can create host groups based on expressions even before any hosts are provisioned. As eligible hosts are provisioned, they automatically join the groups.
Use either CIDR notation or regular expressions (regex) to create groups based on expressions that will search for hosts.
Using CIDR notation lets you create expressions that search subnets.
Important
If you enter a CIDR notation expression incorrectly, Endpoint Security (HX) processes what you enter as regex, which may not produce ideal results.
Using regex lets you create expressions that further filter the OS & patch, Windows domain, or hostname filters for a host group.
Log in to the Endpoint Security (HX) Web UI.
On the Manage Hosts menu, select Host Sets.
Hover over the Create Host Set button, and select Using set builder.
The Create Standard Set page appears.
In the Filters pane, select a filter. These filters allow you to specify expressions or enter specific filter criteria: Domain, OS & Patch, Timezone, Subnet, Hostname, or Last Sysinfo.
The Filter Criteria pane lists filter criteria for the selected filter, a link called Create Expression, or a box in which you can enter one or more criteria for the filter. Press CTRL+Click to select multiple expressions.
Click the Create Expression link in the Filter Criteria pane to specify a regular expression for the filter, in regex or in CIDR notation. Supply values or a valid expression in regex or in CIDR notation in the resulting text box.
The Set Navigator circle shows the hosts that match the filters you have selected.
Drag the Set Navigator circle to the Result Set circle in the Set Visualizer.
You have now created a standard set that contains one host group.
Define more host groups using the filters in the Filters and Filter Criteria panes. Drag the Set Navigator circle to the Set Visualizer each time to add another host group to the standard set.
For additional information about filters and filter expressions, see Embedding host sets in a host group for a standard set and Creating a standard set using filters.
When you have finished adding host groups to the standard set, specify the relationships between them in the Set Visualizer. For more information, see Manipulating relations between host groups in a standard set.
Enter a name in the Set Name box, and then click Create.
The standard set, containing one or more host groups, is created.
Log in to the Endpoint Security (HX) Web UI.
On the Manage Hosts menu, select Host Sets.
Locate the host set in the Host Sets pane, and click the Edit icon.
In the Set Builder view, Alt+Click the host you want to remove from the host set.