Host details

Prev Next

Host details provides detailed information about your host endpoint. Slight differences in the display appear, depending on the operating system of the endpoint.

You can perform the following tasks from this page:

  • Control containment of the host endpoint. Depending on the host's current containment state and your Endpoint Security (HX) Web UI user role, you can request containment of the host, approve containment of the host, or cancel or stop containment of the host. The containment button at the top of the page changes depending on the containment state for the host endpoint. See The containment process.

    Note

    Host containment is provided for Windows and macOS endpoints only.

  • Acquire file, triage, or data acquisitions from the host endpoint. Select an option from the Acquire menu. The list of items that can be acquired varies, depending on the operating system of the host endpoint.

  • Delete all alerts for the host. Click Delete alerts.

  • Acknowledge and dismiss an alert on your host endpoint.

  • Mark an alert as false positive.

  • View host alert details.

The rest of the host details page lists information about the host endpoint environment. Information about an endpoint is organized on this page in the following sections: General, Malware Protection, Operating System, BIOS (Windows only), Physical Memory (RAM), User, and Network Adapters.

Note

Timestamps in the Web UI are presented in UTC time.

Prerequisites
  • Admin, Analyst, Senior Analyst, or Investigator privileges (full access)

  • Operator privilege (read only access)

Accessing the page

To access host details:

  1. Select Manage Hosts from the main menu.

  2. Click All Hosts.

  3. In the list, click the expand icon (ExpandIcon.png) next to the host for which you want to view the host detail information.

    • To return to the All Hosts page list, click the collapse (ContractIcon.png) icon in the upper left corner of the page or select All Hosts from the Hosts menu at the top of the page.

General section

This section of the Host Details page provides general information about the host endpoint.

Field

Description

Active Directory: Domain Components

A list of all domains assigned to the host.

Active Directory: Organizational Units

A list of all organizational units assigned to the host.

Active Directory: Common Names

Common names assigned to the host.

Agent ID

The unique agent ID assigned to the host endpoint.

Agent Version

The version of the agent installed on the host endpoint.

Bit Level

The bitness of the host endpoint.

Domain

The domain of the host endpoint.

GMT Offset

The GMT offset time of the host endpoint.

IP Address

The IP address of the host endpoint.

Initial Agent Connection

The UTC timestamp identifying when the endpoint initially provisioned with the Endpoint Security (HX).

Kernel (Linux only)

The Linux kernel version running on the endpoint.

KernelServices Status

The status of the Linux KernelServices on the endpoint.

Last Sysinfo

The UTC timestamp identifying when the last system information task (sysinfo) reported results from the agent on the host endpoint. See the comparison of this time with the Last Sysinfo (skewed) time next.

Agent Last Poll

The UTC timestamp identifying when the agent last polled for audit jobs.

Last Sysinfo (skewed)

A skewed UTC timestamp identifying when the last sysinfo task reported results from the agent on the host endpoint. This value is skewed to include the calculated difference between the actual clock time on the host endpoint and the clock time on the Endpoint Security (HX). These clock times can be different because each machine may be affected by different things, such as clock delays, network delays, and the service used for time synchronization. For the value in this field, Endpoint Security (HX) treats the server time as the true time and skews the time with the calculated difference between the server and the endpoint times. The skewed time should be close, if not the same, as the unskewed Last Sysinfo time, but if they are different, the skewed time should more accurately reflect the actual agent time when the last sysinfo task reported results to the server.

OS

The operating system installed on the host endpoint.

Patch

The patch level of the operating system installed on the host endpoint.

Timezone

The UTC time zone of the host endpoint.

Malware Protection section

Host Details provides malware protection information for the host endpoint, which is divided into Signature and Heuristic Detection and MalwareGuard Detection.

Field

Description

Malware Engine Version

The malware engine version used for malware protection.

Malware Content Version

The version of Signature and Heuristic Detection content on the host endpoint. The version number of the malware protection definitions on the host endpoint.

Last Updated

The timestamp when the malware protection definitions were last updated on the host endpoint.

MalwareGuard Engine Version

The MalwareGuard engine version used for malware protection.

MalwareGuard Content Version

The version of MalwareGuard content on the host endpoint.

Last Updated

The timestamp when the MalwareGuard content was last updated on the host endpoint.

Security Content section

Field

Description

Intel Version

The version number of the latest installed security content.

Intel Last Updated

The UTC time the security content was last updated.

Operating System section

Field

Description

OS, Build & Patch

The operating system, version and patch installed on the host endpoint.

Install Date

The timestamp identifying when the operating system was installed on the host endpoint.

Product ID

The host endpoint product ID.

Processor

The processor driver installed for the host endpoint.

Processor Type

The processor type of the host endpoint.

System Timestamp

The system UTC time of the host endpoint.

Machine Name

The machine name of the host endpoint.

System Directory

The location of the system directory on the host endpoint.

Up Time

The number of seconds the host endpoint has been running.

BIOS section (Windows only)

Field

Description

Release Date

The date of the Basic Input/Output System (BIOS) on the host endpoint.

Version

The version of the BIOS on the host endpoint.

Physical Memory section

Field

Description

Total

The total memory of the host endpoint.

Available

The amount of memory available on the host endpoint.

User section

Field

Description

Primary User

The primary user of the host endpoint.

Registered Org

(Windows only)

The registered organization of the host endpoint.

Registered Owner

(Windows only)

The registered owner of the host endpoint.

Network Adapters section

Field

Description

DHCP Address

(Windows only) The Dynamic Host Configuration protocol (DHCP) of the network adapter on the host endpoint.

IP Address

The IP address of the network adapter on the host endpoint.

IP Gateway Address

The IP gateway address of the network adapter on the host endpoint.

Lease Expiry Date

The date the lease for the network adapter expires.

Lease Obtained Date

The date the lease for the network adapter was obtained.

MAC

The media access control (MAC) address of the network adapter.

Name

The name of the network adapter on the host endpoint.

Subnet Mask

The subnet mask of the network adapter on the host endpoint.