The Hosts with Alerts page lists all host endpoints in your enterprise with alerts. An alert is a match between an indicator condition, an exploit condition, or a malware definition and evidence of potentially malicious activity on the endpoint.
Filter by drop-down boxes
You can filter the data in the grid on this page using the Filter by drop-down boxes.
.png)
Using these boxes, you can filter the data in the grid.
Use the Alert type drop-down menu to filter the data by alert type (All, XPLT, PRS, EXC, or MAL). When an alert type is selected, the host grid is filtered for hosts with at least one of the selected alert type.
Use the Protection & Remediation drop-down menu to filter the data by protection and remediation state (All, Blocked, Quarantined, Cleaned, or Not Blocked). When Blocked is selected, the host grid is filtered for hosts for which all alert conditions are blocked or prevented. Alternatively, the Not Blocked filter shows hosts for which at least one alert condition is not blocked.
When Quarantined is selected, the host grid is filtered for hosts for which all files containing malware were quarantined.
When Cleaned is selected, the host grid is filtered for hosts for which all files containing malware were cleaned. Cleaning means the system attempts to remove malware from a file (for example, deleting one malicious file from a .zip archive containing 10 files). If the malicious file can be removed, the rest of the submission is not quarantined.
Use the Disposition drop-down menu to filter the data by false positive disposition (all, False Positive, or Not False Positive). When False Positive is selected, a host is included in the grid if all of its alerts (IOC, exploit, and malware alerts) are for a false positive condition. For more information about how hosts are filtered by disposition, see About false positive badges.
Use the Host set drop-down menu to filter the data by host set name or by high-value hosts. The drop-down menu lists all the host sets you have defined and an option for High-value hosts.
Use the Containment state drop-down menu to filter the data by containment state (All, Contained, Containment requested, Containment failed, or Containment ineligible).
Use the Agent drop-down menu to filter the data by agent version number.
Sort By options
You can sort the hosts in the grid on this page using the Sort By options.
.png)
Select an option to sort the hosts in the grid by the alert options. Select Priority (the default) to sort the hosts with the highest priority alerts first. Select Newest alert to sort the hosts with the most recent alert times first. Select Most events to sort the hosts with the highest number of alerting events first. Select Most alert types to sort the hosts with the highest number of different alert types first.
By default, hosts are sorted by highest priority. Hosts with IOC or exploit alerts will sort with a higher priority in the list than hosts with only malware alerts. As a secondary sort within the priority sort, hosts are sorted in reverse chronological order by their last alerted dates.
These options are mutually exclusive.
Paging area
The paging area indicates the range of host endpoints shown on this page of the grid and the total number of host endpoints that have provisioned with the Endpoint Security (HX).
.png)
Actions area
The Actions area allows you to take action on any host endpoint in the list.
.png)
The selection box (
) to the left of the Actions drop-down box allows you to select every host endpoint in the grid. Use this with care. The number of hosts selected for an action is listed to the right of the Go button in the Actions area.
The Actions drop-down menu allows you to select an action for the host endpoints you have selected in the grid. The list of actions that can be selected varies, depending on the operating systems of the selected host endpoints. You can:
Delete host endpoints
Delete alerts
Contain host endpoints
Run a malware scan on host endpoints
Request a file acquisition, data acquisition, or triage acquisition for host endpoints. The data acquisition scripts listed in the Actions menu vary by platform and include any custom data acquisition scripts you have created that apply to the selected endpoints.
For information on creating custom data acquisition scripts, see Maintaining data acquisition scripts. For information on the supplied data acquisition scripts, see Supplied data acquisition scripts.
If no hosts are selected, no actions can be selected in the Actions drop-down menu.
After selecting an action in the Actions drop-down, click Go to start the selected action.
Download option
To download a CSV file of all the host endpoints in the grid (on all pages), click the download (
) button.
The CSV file contains the following fields:
Agent ID—The system-generated ID for the host endpoint.
Hostname—The hostname of the host endoint.
IP Address—The IP address of the host system.
Operating System (OS)—The OS of the host system.
Timezone—The timezone where the host system is installed.
Domain—The network domain of the host system.
User—The host user account running Agent.
Agent Version—The version of Agent software running on the host endpoint.
Malware Content Version—The version of Signature and Heuristic Detection content on the host endpoint.
MalwareGuard Content Version—The version of MalwareGuard content on the host endpoint.
Last System Audit—The timestamp of the last system audit on the host endoint.
High Value Host—Indicates whether the host endoint is defined as a high value host.
Containment Status—Indicates the containment state of the host endpoint.
Alert Count—The total count of alerts on the host endpoint.
Newest Alert—The timestamp of the most recent alert on the host endoint.
Alert Types—A list of all alert types for the host endoint in a semi-colon separated list.
Blocked Count—The number of exploits that have been blocked.
Newest Block—The timestamp of the most recent exploit block.
Block—The block status for the host endoint.
Quarantine Count—The number of quarantined files on the host endoint.
Hosts grid
The hosts grid lists all the host endpoints for which an alert is generated.
Information is provided about each host. From left to right, the following information is provided in the columns:
Column | Description |
|---|---|
![]() | Select a host endpoint for which you want to take action. |
![]() | Expand a host endpoint to see more details about the alerts and acquisitions for the host and to access more details about the host endpoint. See Host Alert Details page and Host Details tab. |
(Containment Status) | Icons identify the containment status of the host endpoint: requested ( |
(Host Type) | The type of machine: Windows ( |
Agent ID and IP address | The agent ID of the host endpoint. Its IP address is listed beneath the agent ID. |
Operating System and Timezone | The operating system and time zone of the host endpoint. |
Workgroup | The workgroup of the host endpoint. |
Agent Version and Sysinfo Time | The version number of the agent installed on the host endpoint and the last time system information (sysinfo task) was requested from the endpoint by the Endpoint Security (HX). Timestamps in the Web UI are presented in UTC time. |
Alerts | The number of alerts that have occurred on the host endpoint and the time (minutes, hours, days) since the most recent alerts occurred. If you hover the cursor over the alert count in this column, a breakdown of the total alert count and possible false positives for the host is shown.
If the total number of unique IOC (indicator), exploit, and malware alerts matches the total number of unique false positive conditions for a host, the false positive badge ( |
Remediation Actions | The column farthest to the right in the grid indicates how many of the following remediation actions occurred for a threat identified by an alert on the endpoint host. This column can show:
Block exploit counts only appear if the exploit prevention component of Exploit Guard is activated. For more information, see the description of the Exploit Guard policies in the Endpoint Security Agent (HX) Administration Guide. Quarantine and clean counts only appear if exploit detection and quarantine are enabled. For more information, see the description of the malware protection policies in the Endpoint Security Agent (HX) Administration Guide. |
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)