When deploying Trellix Endpoint Security (ENS) 26.x upgrades, Endpoint Upgrade Assistant provides the ability to monitor some endpoint events by using command-line options. This allows you to know when specific events occur and respond to them, if needed. For example, you can check when it's time to restart the endpoint after upgrading Trellix DLP.
Events are reported in one of the four Custom fields that appear on the System Properties tab of the ePO - On-prem System Details page.
To enable this feature, create an Upgrade Automation deployment task in ePO - On-prem and specify this command-line option:
--tag[=1–4]
where 1–4 specifies one of four Custom fields.
For example, --tag=3 reports endpoint events in the Custom 3 field, and --tag or --tag=1 reports in the Custom 1 field.
Supported events for Custom fields
Not all upgrade workflows use all the supported event properties. Endpoint Upgrade Assistant reports these properties:
Property | Description |
|---|---|
EUA_CLIENT_EXECUTION_STARTED | Endpoint upgrade has started. |
EUA_REBOOT_REQUIRED ENS_INSTALL_PENDING | Restart the endpoint. |
EUA_ENDPOINT_REBOOTED ENS_INSTALLING |
|
EUA_EXECUTION_COMPLETE |
|
EUA_EXECUTION_COMPLETE REBOOT_REQUIRED DLP_UPGRADED |
|
These are some general guidelines for using the Custom fields:
Endpoint Upgrade Assistant doesn't remove or change the value displayed. For example, if you restart an endpoint, the REBOOT_REQUIRED value doesn't change.
The value in the Custom field isn't updated or removed until it is overwritten by another task on the endpoint.
If a Custom field is being used by another application for another purpose, reporting for Endpoint Upgrade Assistant might be affected.
The
--tagoption is not related to tagging endpoints for updates in the System Tree.