Removing hosts

Prev Next

As your enterprise retires, reorganizes, replaces, or reimages host endpoints, you must handle the old agent and host IDs. You can create special host sets to exclude them from operations. Trellix recommends that you remove the old identities from the Endpoint Security (HX) system entirely.

Administrators and operators can completely remove hosts from the Endpoint Security (HX) database. When you remove a host from the database, you also remove any associated alerts and acquisitions, as well as the host endpoint's membership in host sets and all of the host endpoint's upgrade and containment history. If you delete all hosts from a host set, the host set remains, but contains no members.

If you mistakenly remove an active host endpoint, the endpoint reappears in the system the next time the Endpoint Security (HX) checks for agents that are removed from the Endpoint Security (HX) Web UI but are still polling (usually within 15 minutes).

Note

When a removed host is restored in the system, previous acquisition data and agent activity history do not reappear. You might see alerts that were previously deleted. This is because when the host was removed from the system, the information about which of its alerts were deleted was also removed.

Prerequisites
  • Admin, Analyst, Senior Analyst, or Investigator privileges

To remove hosts using the Web UI:
  1. Select Manage Hosts from the main menu of the Endpoint Security (HX) Web UI to access the Hosts page.

  2. Select the checkbox to the left of any hosts that you want to remove.

  3. From the Actions menu, select Delete host, and then click Go.

  4. Click Delete to confirm removal of the host endpoint from the Endpoint Security (HX) system.

    The hosts and all its associated acquisitions and alerts are removed from the Endpoint Security (HX) database.