You can request containment for a host endpoint through the Endpoint Security (HX) Web UI from the Host page or the Host Details page. Requesting containment does not contain the endpoint. The request must be approved by an administrator or investigator first. See Approving a containment request.
You can also request containment of a host endpoint using the API if you have a user account that is assigned the api_admin role. If you use the API method, the containment request does not need to be approved.
Admin, investigator, senior analyst, or analyst Web UI access
Select Hosts in the Endpoint Security (HX) Web UI.
Click the selection box (
) to the left of the host endpoints that you want to contain.From the Actions menu, select Request containment.
Click Go.
You can also request containment from the host alert details and host details sections of the Hosts page.
Select Hosts in the Endpoint Security (HX) Web UI.
Request host details by clicking on the Expand icon (
) associated with a host.At the top of the details page, click Request containment.
After containment is requested, the host's containment status changes to Containment requested. A containment requested icon (
) appears beside the hostname on every page where the host is listed. The Contained Hosts area of the Dashboard shows an additional host in the number of hosts requested for containment.
Important
If you request containment for more than one host at the same time, and any of the hosts displays an Ineligible for containment icon (
), containment fails for all the hosts.