You can execute the selected endpoint's operating system reboot. The endpoint operating system reboots immediately without saving any work or application data unless the application auto-saves by itself or manually saved.
If a specific file can't be deleted because of a process blocks it, the file is deleted when the endpoint restarts.
The Execute Reboot Operating System reaction is supported on Windows, Linux, and macOS endpoints.
Log on to Trellix EDR.
Select Menu → Real-time Search.
On the Search box, enter a search expression.
Click the search icon to start collecting data from managed devices.
Based on the search expression, the list of events, processes, or devices is displayed.
From the list, select the affected event, process, or device, then select Action → Mitigate → Execute Reboot Operating System.
A new window appears to complete the action.
Click Confirm to complete the Execute Reboot Operating System action.
A confirmation message displays as the action launched is completed successfully.
On the Action History dashboard, Action Status displays the execute reboot operating system action as Completed.