Requesting agent diagnostics

Prev Next

You can acquire agent diagnostics from a host using the Endpoint Security (HX) Web UI.

Prerequisites
  • Analyst, Senior Analyst, or Admin access

  • The host is running the Trellix Endpoint Security (HX) xAgent version 20 or later.

To request agent diagnostics:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select the host for which you want to acquire agent diagnostics.

  3. In the Actions menu, select Acquire: Agent Diagnostics.

  4. Click Go.

You can monitor the status of an acquisition request in the Status column of the Acquisitions page. The status changes from Requested, to Acquiring, and then to Acquired when the acquisition is ready.

Note

The following error indicates that the agent log was actively being written to at the time of the request and was busy.

1729, MX_API_SQLITE_DATABASE_BUSY, "SQL database busy".

If this error occurs, submit the request again.