The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Locate inactive agents

Prev Next

An inactive Trellix Agent is one that has not communicated with ePO - On-prem in a user-specified time period.

It's possible for agents to become disabled, or for users to uninstall them. In other cases, the system hosting Trellix Agent might have been removed from the network. We recommend performing regular weekly searches for systems with these inactive agents.

  1. Select Menu → Reporting → Queries & Reports.

  2. In the Groups list, select Trellix Groups, then select Agent Management group.

  3. Click Run in the Inactive Agents row to run the query.

    The default configuration for this query finds systems that have not communicated with ePO - On-prem in the last 30 days.

When you find inactive agents, review their activity logs for problems that might interfere with agent-server communication.

Note

(ePO - On-prem) The query results allow you to take actions on the systems identified, including ping, delete, wake up, and redeploy Trellix Agent.