The Agents Page

Introduction

Use the Agents page to monitor endpoint agents across your environment, review device status, investigate endpoint activity, and access detailed endpoint telemetry.


From this page, you can:

  • View all endpoint agents deployed in your environment
  • Review detailed information about individual endpoints
  • Search and filter agent data
  • Customize table columns
  • Export agent information for reporting or analysis


This article covers the following topics: 


Access the Agents Page

After logging into the MDR SIEM, navigate to Security > Alerts in the sidebar. 



Navigate the Agents Page

The Agents page displays all endpoint agents in your organization in a single table.


The page includes:

  • A searchable and sortable agent list
  • Configurable columns
  • An agent details pane
  • Export capabilities


Agent List

The main table displays endpoint agents and their associated information.


You can:

  • Resize columns
  • Rearrange columns
  • Show or hide columns
  • Sort data by column



Agent Details

Select an agent row to view additional information about the endpoint. The details pane appears beneath the table and provides expanded information about the selected device.


You can:

  • View endpoint details
  • Expand the information into a larger modal window
  • Select View ARO to open the associated Asset Risk Object (ARO) in the Field Effect portal



Investigate an Endpoint

To review detailed telemetry for a specific endpoint:

  1. Open the Agents page.
  2. Select the endpoint's Host Name.



The Endpoint Details page opens and displays additional information about the selected device. The Overview tab provides the same high-level information available in the Agent Details pane.


Additional endpoint-specific views are available across the top of the page. These views provide deeper visibility into agent telemetry and endpoint activity. Select any row within these views to display additional details.



You can also expand detail views into a larger modal window using the Expand button.



Recent and Log Views

Some endpoint views contain additional sub-views. These may include:


Sub-viewDescription
RecentDisplays recent endpoint activity.
LogDisplays historical events reported by the endpoint agent.
ArchiveDisplays summarized historical process activity.


Data retention varies by view. In most views, approximately one month of data is retained. The Processes > Archive view retains approximately two weeks of historical data.




Search for Agents

The search bar is available on the main Agents page and within endpoint-specific views. You can use it to:

  • Search by keyword
  • Filter by specific columns
  • Create advanced search conditions
  • Sort search results


  1. Select a column from the search suggestions.
  2. Select an operator such as:
    1. Contains
    2. Is
    3. Is Not
    4. Is Null
  3. Select a suggested value or enter your own value.


The available suggestions depend on the selected column. For example, selecting the Created Time column displays available date and time values found within the current dataset.




Sort and Filter Results


Sort Results

To sort agents:

  • Select a column header to switch between ascending and descending order.
  • Use the Order By search option to define sorting criteria.


Filter Results

To filter displayed agents:

  • Use Is Not to exclude matching values.
  • Use Is Null to display records that contain no value for the selected column.


As you build a filter, the system automatically presents additional suggestions based on your selections.


Supported Date Formats

When filtering by date or time, use one of the following formats:

  • 2022-11-22T16:35:42
  • 2022-11-22T16:35:42Z
  • 2022-11-22T16:35:42.000
  • 2022-11-22T16:35:42.000+0000



Customize Columns

You can customize which columns appear in the agent table.


To show or hide columns:

  1. Select Edit Columns.
  2. Select the columns you want to display.
  3. Clear the columns you want to hide.
  4. Select Apply.



You can also:

  • Drag column borders to resize columns.
  • Drag columns to reorder them.
  • Sort columns using the header controls.



Export Agent Data

You can export all displayed agent data or only filtered results.


To export data:

  1. Configure any filters you want to apply.
  2. Select the Export .csv icon.


Background pattern

Description automatically generated


The export will be downloaded to your default folder.


Graphical user interface, application

Description automatically generated


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article