All Hosts page

Prev Next

In the Event Details side panel, click View Host Details. The All Hosts page opens in a new tab.

The All Hosts page displays the following options:

  • Filter by drop-down boxes

  • Sort by options

  • Actions area

  • Host details

Filter by drop-down boxes

You can filter the data in the grid on this page by using the Filter By drop-down boxes.

Using these boxes, you can filter the data in the grid.

  • Use the Host set drop-down menu to filter the data by host set name, active hosts, inactive hosts, or by high-value hosts. The drop-down menu lists all the host sets you have defined and options for High-value hosts, Active hosts, and Inactive hosts.

  • Use the Containment state drop-down menu to filter the data by containment state (All, Contained, Containment requested, Containment failed, or Containment ineligible).

  • Use the Agent drop-down menu to filter the data by agent version number.

Sort By options

You can sort the hosts in the grid on this page by using the Sort By options.

HX_HostsSortBy.png

Select an option to sort the hosts in the grid by the times the last system information (sysinfo) task was run for the agents on the host endpoints. Select Oldest Sysinfo to sort the hosts with the oldest sysinfo task times first. Select Most recent Sysinfo to sort the hosts with the most recent sysinfo task times first.

These options are mutually exclusive.

Actions area

The Actions area allows you to take action on any host endpoint in the list.

Actions.png

The selection box (SelectionBox.png) to the left of the Actions drop-down box allows you to select every host endpoint in the grid. Use this with care. The number of hosts selected for an action is listed to the right of the Go button in the Actions area.

The Actions drop-down menu allows you to select an action for the host endpoints you have selected in the grid. The list of actions that can be selected varies, depending on the operating systems of the selected host endpoints. You can:

  • Run a Malware Scan — Initiates an immediate on-demand scan of the selected host.

  • Restart Agent — Restarts the agent on the selected host.

  • Acquire — Accesses data collection options, including Single File, Triage, Multiple Files, Standard/Comprehensive Investigative Details, Quick File Listing, and Agent Diagnostics.

  • Delete host — Removes the selected host from the management list.

If no hosts are selected, no actions can be selected in the Actions drop-down menu.

After selecting an action in the Actions drop-down, click Go to start the selected action.

Download option

To download a CSV file of details for all the host endpoints in the grid (on all pages), click the download (HX_Download.png) button.

The CSV file contains the following fields:

  • Agent ID—The system-generated ID for the host endpoint.

  • Hostname—The hostname of the host endpoint.

  • IP Address—The IP address of the host system.

  • Operating System (OS)—The OS of the host system.

  • Timezone—The timezone where the host system is installed.

  • Domain—The network domain of the host system.

  • User—The host user account running Agent.

  • Agent Version—The version of Agent software running on the host endpoint.

  • Malware Protection Status—The current status of malware protection on the host endpoint.

  • Signature and Heuristic Detection status—Indicates whether signature-based and heuristic detection is enabled or disabled.

  • Malware Guard status—The current status of the Malware Guard engine.

  • Malware AV Content Version—The version of Signature and Heuristic Detection content on the host endpoint.

  • MalwareGuard Content Version—The version of MalwareGuard content on the host endpoint.

  • Security Content Intel Version— The version of Security Content on the host endpoint.

  • Security Content Intel Updated—The timestamp of the most recent Security Content update on the host endpoint.

  • Last System Audit—The timestamp of the last system audit on the host endpoint.

  • Agent Last Poll—The timestamp of the most recent communication between the agent and the management console.

  • High Value Host—Indicates whether the host endpoint is defined as a high value host.

  • Containment Status—Indicates the containment state of the host endpoint.

  • Alert Count—The total count of alerts on the host endpoint.

  • Newest Alert—The timestamp of the most recent alert on the host endpoint.

  • Alert Types—A list of all alert types for the host endpoint in a semi-colon separated list.

  • Blocked Count—The number of exploits that have been blocked.

  • Newest Block—The timestamp of the most recent exploit block.

  • Block—The block status for the host endpoint.

  • Quarantine Count—The number of quarantined files on the host endpoint.

Hosts grid

The hosts grid lists all the host endpoints that have provisioned with your server.

Information is provided about each host. From left to right, the following information is provided in the columns:

Column

Description

SelectionBox.png

Select a host endpoint for which you want to take action.

ExpandIcon.png

Expand a host endpoint to see more details about the alerts and acquisitions for the host and to access more details about the host endpoint.

(Containment Status)

Icons identify the containment status of the host endpoint: requested (containment-requested.png), approved (containment-approved.png), contained (Contained.png), cancellation in progress (containment-uncontain.png), failed (containment-failed.png), and ineligible for containment (containment-ineligible.png). See Containing hosts .

(Host Type)

The type of machine: Windows (IconWinHost.png), macOS( IconOSXHost.png), Linux (linux.png), or server (IconSrvHost.png).

Agent ID and IP address

The agent ID of the host endpoint. Its IP address is listed beneath the agent ID.

Operating System and Timezone

The operating system and time zone of the host endpoint.

Workgroup

The workgroup of the host endpoint.

Agent Version and Sysinfo Time

The version number of the agent installed on the host endpoint and the last time system information (sysinfo task) was requested from the endpoint by the Endpoint Security (HX) .

Timestamps in the Web UI are presented in UTC time.

Host details

Select the plus (+) icon to expand the host details panel for comprehensive information on the host.

General section

This section of the Host Details page provides general information about the host endpoint.

Field

Description

Active Directory: Domain Components

A list of all domains assigned to the host.

Active Directory: Organizational Units

A list of all organizational units assigned to the host.

Active Directory: Common Names

Common names assigned to the host.

Agent ID

The unique agent ID assigned to the host endpoint.

Agent Version

The version of the agent installed on the host endpoint.

Bit Level

The bitness of the host endpoint.

Domain

The domain of the host endpoint.

GMT Offset

The GMT offset time of the host endpoint.

IP Address

The IP address of the host endpoint.

Client IP

The IP address of the EDRF Client.

Initial Agent Connection

The UTC timestamp identifying when the endpoint initially provisioned with the Endpoint Security (HX).

Kernel (Linux only)

The Linux kernel version running on the endpoint.

KernelServices Status

The status of the Linux KernelServices on the endpoint.

Last Sysinfo

The UTC timestamp identifying when the last system information task (sysinfo) reported results from the agent on the host endpoint. See the comparison of this time with the Last Sysinfo (skewed) time next.

Agent Last Poll

The UTC timestamp identifying when the agent last polled for audit jobs.

Last Sysinfo (skewed)

A skewed UTC timestamp identifying when the last sysinfo task reported results from the agent on the host endpoint. This value is skewed to include the calculated difference between the actual clock time on the host endpoint and the clock time on the Endpoint Security (HX). These clock times can be different because each machine may be affected by different things, such as clock delays, network delays, and the service used for time synchronization. For the value in this field, Endpoint Security (HX) treats the server time as the true time and skews the time with the calculated difference between the server and the endpoint times. The skewed time should be close, if not the same, as the unskewed Last Sysinfo time, but if they are different, the skewed time should more accurately reflect the actual agent time when the last sysinfo task reported results to the server.

OS

The operating system installed on the host endpoint.

Patch

The patch level of the operating system installed on the host endpoint.

Timezone

The UTC time zone of the host endpoint.

Malware Protection section

Host Details provides malware protection information for the host endpoint, which is divided into Signature and Heuristic Detection and MalwareGuard Detection.

Field

Description

Malware Engine Version

The malware engine version used for malware protection.

Malware Content Version

The version of Signature and Heuristic Detection content on the host endpoint. The version number of the malware protection definitions on the host endpoint.

Last Updated

The timestamp when the malware protection definitions were last updated on the host endpoint.

MalwareGuard Engine Version

The MalwareGuard engine version used for malware protection.

MalwareGuard Content Version

The version of MalwareGuard content on the host endpoint.

Last Updated

The timestamp when the MalwareGuard content was last updated on the host endpoint.

Exploit Guard Version

The version of Exploit Guard software currently running on the host endpoint.

Engine Version

The engine version used for exploit protection on the host endpoint.

DTI Config Version

The version of the Data Threat Intelligence (DTI) configuration on the host endpoint.

Content Rules Version

The version of the exploit protection content rules on the host endpoint

Content Whitelist Version

The version of the exploit protection content whitelist on the host endpoint.

Security Content section

Field

Description

Intel Version

The version number of the latest installed security content.

Intel Last Updated

The UTC time the security content was last updated.

Operating System section

Field

Description

OS, Build & Patch

The operating system, version and patch installed on the host endpoint.

Install Date

The timestamp identifying when the operating system was installed on the host endpoint.

Product ID

The host endpoint product ID.

Processor

The processor driver installed for the host endpoint.

Processor Type

The processor type of the host endpoint.

System Timestamp

The system UTC time of the host endpoint.

Machine Name

The machine name of the host endpoint.

System Directory

The location of the system directory on the host endpoint.

Up Time

The number of seconds the host endpoint has been running.

BIOS section (Windows only)

Field

Description

Release Date

The date of the Basic Input/Output System (BIOS) on the host endpoint.

Version

The version of the BIOS on the host endpoint.

Physical Memory section

Field

Description

Total

The total memory of the host endpoint.

Available

The amount of memory available on the host endpoint.

User section

Field

Description

Primary User

The primary user of the host endpoint.

Registered Org

(Windows only)

The registered organization of the host endpoint.

Registered Owner

(Windows only)

The registered owner of the host endpoint.

Network Adapters section

Field

Description

DHCP Address

(Windows only) The Dynamic Host Configuration protocol (DHCP) of the network adapter on the host endpoint.

IP Address

The IP address of the network adapter on the host endpoint.

IP Gateway Address

The IP gateway address of the network adapter on the host endpoint.

Lease Expiry Date

The date the lease for the network adapter expires.

Lease Obtained Date

The date the lease for the network adapter was obtained.

MAC

The media access control (MAC) address of the network adapter.

Name

The name of the network adapter on the host endpoint.

Subnet Mask

The subnet mask of the network adapter on the host endpoint.