Introduction
Use the Agents page to monitor endpoint agents across your environment, review device status, investigate endpoint activity, and access detailed endpoint telemetry.
From this page, you can:
- View all endpoint agents deployed in your environment
- Review detailed information about individual endpoints
- Search and filter agent data
- Customize table columns
- Export agent information for reporting or analysis
This article covers the following topics:
- Access the Agents Page
- Navigate the Agents Page
- Investigate an Endpoint
- Search for Agents
- Sort and Filter Results
- Customize Columns
- Export Agent Data
Access the Agents Page
After logging into the MDR SIEM, navigate to Security > Alerts in the sidebar.

Navigate the Agents Page
The Agents page displays all endpoint agents in your organization in a single table.
The page includes:
- A searchable and sortable agent list
- Configurable columns
- An agent details pane
- Export capabilities
Agent List
The main table displays endpoint agents and their associated information.
You can:
- Resize columns
- Rearrange columns
- Show or hide columns
- Sort data by column

Agent Details
Select an agent row to view additional information about the endpoint. The details pane appears beneath the table and provides expanded information about the selected device.
You can:
- View endpoint details
- Expand the information into a larger modal window
- Select View ARO to open the associated Asset Risk Object (ARO) in the Field Effect portal

Investigate an Endpoint
To review detailed telemetry for a specific endpoint:
- Open the Agents page.
- Select the endpoint's Host Name.

The Endpoint Details page opens and displays additional information about the selected device. The Overview tab provides the same high-level information available in the Agent Details pane.
Additional endpoint-specific views are available across the top of the page. These views provide deeper visibility into agent telemetry and endpoint activity. Select any row within these views to display additional details.

You can also expand detail views into a larger modal window using the Expand button.

Recent and Log Views
Some endpoint views contain additional sub-views. These may include:
| Sub-view | Description |
|---|---|
| Recent | Displays recent endpoint activity. |
| Log | Displays historical events reported by the endpoint agent. |
| Archive | Displays summarized historical process activity. |
Data retention varies by view. In most views, approximately one month of data is retained. The Processes > Archive view retains approximately two weeks of historical data.

Search for Agents
The search bar is available on the main Agents page and within endpoint-specific views. You can use it to:
- Search by keyword
- Filter by specific columns
- Create advanced search conditions
- Sort search results
Build a Search
- Select a column from the search suggestions.
- Select an operator such as:
- Contains
- Is
- Is Not
- Is Null
- Select a suggested value or enter your own value.
The available suggestions depend on the selected column. For example, selecting the Created Time column displays available date and time values found within the current dataset.

Sort and Filter Results

Sort Results
To sort agents:
- Select a column header to switch between ascending and descending order.
- Use the Order By search option to define sorting criteria.
Filter Results
To filter displayed agents:
- Use Is Not to exclude matching values.
- Use Is Null to display records that contain no value for the selected column.
As you build a filter, the system automatically presents additional suggestions based on your selections.
Supported Date Formats
When filtering by date or time, use one of the following formats:
- 2022-11-22T16:35:42
- 2022-11-22T16:35:42Z
- 2022-11-22T16:35:42.000
- 2022-11-22T16:35:42.000+0000
Customize Columns
You can customize which columns appear in the agent table.
To show or hide columns:
- Select Edit Columns.
- Select the columns you want to display.
- Clear the columns you want to hide.
- Select Apply.

You can also:
- Drag column borders to resize columns.
- Drag columns to reorder them.
- Sort columns using the header controls.

Export Agent Data
You can export all displayed agent data or only filtered results.
To export data:
- Configure any filters you want to apply.
- Select the Export .csv icon.

The export will be downloaded to your default folder.

Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article