View dynamic acquisition failure information

Prev Next

Acquisition settings control how agents collect and report triage, data, and file acquisition information from the endpoint host. In the event of an acquisition failure, the Endpoint Security (HX) UI provides information detailing the cause of the failure. Depending on the type of acquisition failure, the HX HX UI prompts you to perform various predefined actions.

HX_Acquisition_Failure.png

Examples of acquisition failures include:

Acquisition failure

Description

"Response limit exceeded"

The agent returned data that exceeded the limit specified in the task creation resulting in a timeout.

"Manifest is empty"

The agent returned an empty manifest or was unable to read it.

"Maximum output stream limit reached"

The result is too large. Trellix recommends that you narrow the scope of your request and retry.

"Manifest too large to open"

The resulting manifest is too large. Trellix recommends that you narrow the scope of your request.

Important

In the event of an acquisition failure, the information provided by the Endpoint Security (HX) UI detailing the cause of the failure is dynamically generated. The documentation provided on this feature is not comprehensive.