An inactive Trellix Agent is one that has not communicated with ePO - On-prem in a user-specified time period.
It's possible for agents to become disabled, or for users to uninstall them. In other cases, the system hosting Trellix Agent might have been removed from the network. We recommend performing regular weekly searches for systems with these inactive agents.
Select → → .
In the Groups list, select Trellix Groups, then select Agent Management group.
Click Run in the Inactive Agents row to run the query.
The default configuration for this query finds systems that have not communicated with ePO - On-prem in the last 30 days.
When you find inactive agents, review their activity logs for problems that might interfere with agent-server communication.
Note
(ePO - On-prem) The query results allow you to take actions on the systems identified, including ping, delete, wake up, and redeploy Trellix Agent.