You can schedule an endpoint reboot remotely at a specified date and time.
If a specific file can't be deleted because of a process blocking it, the file is deleted when the endpoint restarts.
Important
On the Linux client endpoints, the ScheduleReboot reaction leverages the “at” system command, which is not available by default on some Linux platforms (for example, RHEL 8.1 and SUSE). Hence, you must install the “at” system command manually. Once installed, make sure the associated scheduler daemon “atd” is running and it is set to start on boot. For more information, see https://linuxize.com/post/at-command-in-linux/.
The Schedule Reboot reaction is supported on Windows, Linux, and macOS endpoints.
Log on to Trellix EDR.
Select Menu → Real-time Search.
On the Search box, enter a search expression.
Click the search icon to start collecting data from managed devices.
Based on the search expression, the list of events, processes, or devices is displayed.
From the list, select the affected event, process, or device, then select Action → Contain → Schedule Reboot.
A new window appears and then you can enter details:
Reboot time — The specific local endpoint time for a system scheduled reboot.
Click Confirm to complete the Schedule Reboot action.
A confirmation message displays as the action launched is completed successfully.
On the Action History dashboard, Action Status displays the schedule reboot action as Completed.