Malwarebytes OneView's Endpoints page allows you to perform actions on multiple endpoints across multiple sites. To display endpoint details, click an endpoint's name in the endpoint column.
Follow the steps below to initiate an action on an endpoint:
- In the left navigation pane, click Manage > Endpoints.
- Filter your endpoints that you want to perform an action on. For information on ways to filter your endpoints, see Filter endpoints in OneView.
- In the Endpoint column, check the boxes next to endpoints or endpoint groups that you want to perform an action on. You can select all of the endpoints if you check the box in the upper-left part of the table.
- Click the ellipsis icon
to display all available commands. Choose one of the following:
- Download .csv: Downloads a .csv file of the selected endpoints information.
- Download .xlsv: Downloads a .xlsv file of the selected endpoints information.
- Scan + Report: Checks protection updates and runs a Threat Scan to report the results. Any detected threats are not removed.
- Scan + Quarantine: Checks for protection updates and runs a Threat Scan. Any detected threats are quarantined and scan results are reported.
- Remediate Endpoint(s): Remediates found threats on an endpoint. A restart may be needed to complete remediation.
- Isolate Endpoint(s): Isolates the endpoint from the network to prevent an active threat from spreading. The console continues to communicate with the endpoint.
- Remove Isolation: Restores access to the endpoint if it is isolated.
- Launch Active Response Shell: Launches the Active Response Shell remote session on selected endpoints.
- Refresh Assets: Updates hardware and software asset information for the endpoint.
- Check for Protection Updates: Checks for protection updates. While scans also do this, selecting this action makes sure that Real-time Protection uses the most recent updates.
- Check for Agent Updates: Performs an immediate check for Malwarebytes Software Updates. If an update is available, a status indicator displays and an Update Agent action must be issued to initiate the update.
- Install Agent Update: Installs the latest Malwarebytes agent software to the endpoint. A restart may be needed to complete the installation. IMPORTANT: Reboots are handled as configured via your policy Reboot Options.
-
Restart Endpoint(s): Performs a system restart of the selected endpoint(s).
- Allow users to postpone: Enables a popup on endpoints, which allows users to postpone a reboot by preset times of 10, 30, or 60 minutes. A user can continue to postpone a reboot indefinitely unless the reboot delay time is reached. If a user postpones a reboot, the Events screen shows an Audit event.
- Reassign Endpoint(s): Reassigns selected endpoints to a separate site that is created and available in your console.
- Move Group: Move selected endpoints from the same site to another group.
- Delete Endpoint(s): Deletes selected endpoints from the Malwarebytes OneView console.
- Launch Active Response Shell: Launches the Active Response Shell remote session on selected endpoints.
- Check the Tasks tab for the status of the initiated action. The following list shows all the possible statuses:
- Pending: The endpoint is waiting to receive an action.
- Created: The task is created.
- Processing: The action is in progress.
- Success: The action is successful.
- Expired: The endpoint did not receive the action after 3 days pending.
- Failed: The action has failed. This may occur if you sent a repeat command to an endpoint while the same command is Pending. For more information, see Tasks page in OneView.
Return to the Malwarebytes OneView User Guide.