Standard sets are dynamic. They consist of groups of hosts created by filtering criteria. The relationships between the filtered groups in a standard set can be manipulated so the host set filters further on combinations of groups, intersections of groups, or the relative complement of groups. Standard sets are populated automatically when agents are provisioned for the first time after you install them on a host endpoint.
Membership in a standard set changes whenever the following happens:
A new eligible host is provisioned
Filtering criteria are changed
Members are directly added or removed
Standard sets can be an advantage if you want to do any of the following:
Create large sets that automatically include and exclude current and future hosts based on criteria that you set, eliminating the need to add or exclude new hosts manually
Work with large numbers of hosts based on criteria that you customize
Exclude groups of hosts from a larger group of hosts, based on additional criteria (for example, you can exclude hosts with an earlier agent version that are not running a particular operating system version)
Standard sets let you create and edit complex collections of hosts. You create standard sets to search agent metadata using a variety of filtering criteria:
Existing host sets. These are static or standard host sets that you combine in another set. Such sets are called an embedded sets. For example, you might embed a set to include or exclude a smaller, specific group of hosts that you have already identified.
Important
Embedding sets can save you time in creating and maintaining sets, let you fine-tune relationships among groups of hosts, and help with reporting.
Keep track of where you embed host sets. The membership of a host set changes when you edit or delete its embedded host sets.
Embedding more than 10 host sets can affect system performance. Trellix recommends that you avoid embedding more than 10 sets in a host set. (ENDPT-3090)
On the Host Sets page, an asterisk (*) is displayed after the host set name of any host set that is embedded in another host set.
Filters based on business criteria. For example, a group can be formed by filtering all provisioned hosts by agent version, Windows domain, operating system, patch or bit level, time zone, hostname, last sysinfo, or subnet.
Expressions in the form of search terms that you enter directly either in regex or in CIDR notation. For example, subnet or Windows domains.
Caution
Endpoint Security (HX) does not support a Save As or Copy function. If you save a host set with a new name, the host set is simply renamed. If the host set was embedded in another host set, the other host set's membership reflects the changes you made and the new name of the host set.