Host details provides detailed information about your host endpoint. Slight differences in the display appear, depending on the operating system of the endpoint.
You can perform the following tasks from this page:
Control containment of the host endpoint. Depending on the host's current containment state and your Endpoint Security (HX) Web UI user role, you can request containment of the host, approve containment of the host, or cancel or stop containment of the host. The containment button at the top of the page changes depending on the containment state for the host endpoint. See The containment process.
Note
Host containment is provided for Windows and macOS endpoints only.
Acquire file, triage, or data acquisitions from the host endpoint. Select an option from the Acquire menu. The list of items that can be acquired varies, depending on the operating system of the host endpoint.
Delete all alerts for the host. Click Delete alerts.
Acknowledge and dismiss an alert on your host endpoint.
Mark an alert as false positive.
View host alert details.
The rest of the host details page lists information about the host endpoint environment. Information about an endpoint is organized on this page in the following sections: General, Malware Protection, Operating System, BIOS (Windows only), Physical Memory (RAM), User, and Network Adapters.
Note
Timestamps in the Web UI are presented in UTC time.
Admin, Analyst, Senior Analyst, or Investigator privileges (full access)
Operator privilege (read only access)
Accessing the page
To access host details:
Select Manage Hosts from the main menu.
Click All Hosts.
In the list, click the expand icon (
) next to the host for which you want to view the host detail information.To return to the All Hosts page list, click the collapse (
) icon in the upper left corner of the page or select All Hosts from the Hosts menu at the top of the page.
General section
This section of the Host Details page provides general information about the host endpoint.
Field | Description |
|---|---|
Active Directory: Domain Components | A list of all domains assigned to the host. |
Active Directory: Organizational Units | A list of all organizational units assigned to the host. |
Active Directory: Common Names | Common names assigned to the host. |
Agent ID | The unique agent ID assigned to the host endpoint. |
Agent Version | The version of the agent installed on the host endpoint. |
Bit Level | The bitness of the host endpoint. |
Domain | The domain of the host endpoint. |
GMT Offset | The GMT offset time of the host endpoint. |
IP Address | The IP address of the host endpoint. |
Initial Agent Connection | The UTC timestamp identifying when the endpoint initially provisioned with the Endpoint Security (HX). |
Kernel (Linux only) | The Linux kernel version running on the endpoint. |
KernelServices Status | The status of the Linux KernelServices on the endpoint. |
Last Sysinfo | The UTC timestamp identifying when the last system information task (sysinfo) reported results from the agent on the host endpoint. See the comparison of this time with the Last Sysinfo (skewed) time next. |
Agent Last Poll | The UTC timestamp identifying when the agent last polled for audit jobs. |
Last Sysinfo (skewed) | A skewed UTC timestamp identifying when the last sysinfo task reported results from the agent on the host endpoint. This value is skewed to include the calculated difference between the actual clock time on the host endpoint and the clock time on the Endpoint Security (HX). These clock times can be different because each machine may be affected by different things, such as clock delays, network delays, and the service used for time synchronization. For the value in this field, Endpoint Security (HX) treats the server time as the true time and skews the time with the calculated difference between the server and the endpoint times. The skewed time should be close, if not the same, as the unskewed Last Sysinfo time, but if they are different, the skewed time should more accurately reflect the actual agent time when the last sysinfo task reported results to the server. |
OS | The operating system installed on the host endpoint. |
Patch | The patch level of the operating system installed on the host endpoint. |
Timezone | The UTC time zone of the host endpoint. |
Malware Protection section
Host Details provides malware protection information for the host endpoint, which is divided into Signature and Heuristic Detection and MalwareGuard Detection.
Field | Description |
|---|---|
Malware Engine Version | The malware engine version used for malware protection. |
Malware Content Version | The version of Signature and Heuristic Detection content on the host endpoint. The version number of the malware protection definitions on the host endpoint. |
Last Updated | The timestamp when the malware protection definitions were last updated on the host endpoint. |
MalwareGuard Engine Version | The MalwareGuard engine version used for malware protection. |
MalwareGuard Content Version | The version of MalwareGuard content on the host endpoint. |
Last Updated | The timestamp when the MalwareGuard content was last updated on the host endpoint. |
Security Content section
Field | Description |
|---|---|
Intel Version | The version number of the latest installed security content. |
Intel Last Updated | The UTC time the security content was last updated. |
Operating System section
Field | Description |
|---|---|
OS, Build & Patch | The operating system, version and patch installed on the host endpoint. |
Install Date | The timestamp identifying when the operating system was installed on the host endpoint. |
Product ID | The host endpoint product ID. |
Processor | The processor driver installed for the host endpoint. |
Processor Type | The processor type of the host endpoint. |
System Timestamp | The system UTC time of the host endpoint. |
Machine Name | The machine name of the host endpoint. |
System Directory | The location of the system directory on the host endpoint. |
Up Time | The number of seconds the host endpoint has been running. |
BIOS section (Windows only)
Field | Description |
|---|---|
Release Date | The date of the Basic Input/Output System (BIOS) on the host endpoint. |
Version | The version of the BIOS on the host endpoint. |
Physical Memory section
Field | Description |
|---|---|
Total | The total memory of the host endpoint. |
Available | The amount of memory available on the host endpoint. |
User section
Field | Description |
|---|---|
Primary User | The primary user of the host endpoint. |
Registered Org (Windows only) | The registered organization of the host endpoint. |
Registered Owner (Windows only) | The registered owner of the host endpoint. |
Network Adapters section
Field | Description |
|---|---|
DHCP Address | (Windows only) The Dynamic Host Configuration protocol (DHCP) of the network adapter on the host endpoint. |
IP Address | The IP address of the network adapter on the host endpoint. |
IP Gateway Address | The IP gateway address of the network adapter on the host endpoint. |
Lease Expiry Date | The date the lease for the network adapter expires. |
Lease Obtained Date | The date the lease for the network adapter was obtained. |
MAC | The media access control (MAC) address of the network adapter. |
Name | The name of the network adapter on the host endpoint. |
Subnet Mask | The subnet mask of the network adapter on the host endpoint. |