The xAgent upgrade process is completely invisible to endpoint users. The process does not usually require restarting host endpoints and does not prompt end users for action. However, after installing or upgrading Endpoint Security (HX) software to version 35.31.25, a reboot may be required for Mac and Windows endpoints to ensure:
macOS xAgent s receive a new configuration from the Endpoint Security (HX) server.
xAgent notifications start on Windows endpoints.
A reboot may also be required to complete the Windows installation and avoid problems with future installations that check for pending reboots. You can use the wevtutil qe Application command to query the event log and determine if a reboot is necessary.
To query the event log, open the Windows command line and run the following command at the prompt:
wevtutil qe Application /rd:true /f:text /q:"*[System/EventID=1029] and * [EventData[Data='FireEye Endpoint Agent']]"
If a reboot is required, the following message appears:
Trellix Endpoint Agent (HX). Restart required. The installation or update for the product required a restart for all changes to take effect. The restart was deferred for a later time.