Finding inactive systems: best practice

Prev Next

Most environments are changing constantly, new systems are added and old systems removed. These changes create inactive Trellix Agent systems that, if not deleted, can ultimately skew your compliance reports.

As systems are decommissioned, or disappear because of extended travel, users on leave, or other reasons, remove them from the System Tree. An example of a skewed report might be your DAT report on compliance. If you have systems in your System Tree that have not reported into the ePO - On-prem server for 20 days, they appear as out of date by 20 days and ultimately skew your compliance reports.

Initial troubleshooting

Initially, when a system is not communicating with the ePO - On-prem server, try these steps:

  1. From the System Tree, select the system and click ActionsAgentsWake Up Agents.

    Note

    Configure a Retry interval of, for example, 3 minutes.

  2. To delete the device from ePO - On-prem, but not remove the agent in the System Tree, select the system and click ActionsDirectory ManagementDelete. Do not select Remove agent on next agent-server communication.

  3. Wait for the system to communicate with ePO - On-prem again.

    Note

    The system appears in the System Tree Lost and Found group.

Dealing with inactive systems

You can create a query and report to filter out systems that have not communicated with the ePO - On-prem server in X number of days. Or your query and report can delete or automatically move these systems.

It's more efficient to either delete or automatically move these inactive systems. Most organizations choose a deadline of between 14–30 days of no communication to delete or move systems. For example, if a system has not communicated with the ePO - On-prem server after that deadline you can:

  • Delete that system.

  • Move that system to a group in your tree that you can designate as, for example, Inactive Agents.

Note

A preconfigured Inactive Agent Cleanup Task exists, disabled by default, that you can edit and enable on your server.