Enterprise Search page

Prev Next

The Enterprise Search page lets you search for threats or threat indicator rules on your Windows and macOS host endpoints if they are running Trellix Endpoint Security (HX) xAgent version 25 or later and Linux host endpoints running Endpoint Security (HX) xAgent version 34. The functionality shown in your environment might vary, based on the role assigned to your user account and based on the Trellix licenses you have installed. To access the Enterprise Search page, select Enterprise Search from the Investigate tab in the main menu.

HX_EnterpriseSearch.png

The Enterprise Search page consists of a single search box and results from any defined searches. The number of active searches and the number of total searches are shown under the search box:

ES_counts.png

A series of tabs are shown in the search results:

  • The Matched tab lists the host endpoints that match the search criteria and the data that matched.

  • The Not Matched tab lists the host endpoints that do not match the search criteria.

  • The Not Responded tab lists the host endpoints for which Enterprise Search processing has not completed.

  • The Not Searched tab lists the host endpoints for which the search was not valid and, therefore, not performed. A search may not be valid for an endpoint because the Trellix Endpoint Security (HX) version installed on the endpoint is not supported by the search request or the endpoint has an incompatible operating system platform installed.

  • The Errors tab lists errors that were encountered during the search.

The values shown in the tab names will change, as the Enterprise Search is processed.

Note

Timestamps in the Web UI are presented in UTC time.

Use the Stop Collecting Results button to stop the Enterprise Search. Use the Delete Results button to delete the results of an Enterprise Search. Click the Export option on a tab to download the list of host endpoints (and data, if appropriate) listed on that tab to a CSV file.

For information about how to use this page, see Searching your Enterprise .

Prerequisites
  • Admin, Analyst, Senior Analyst, or Investigator privileges (full access)

  • Exhaustive search functionality for enterprise searches requires an Endpoint Security (HX) Power license.