Start Agent
If the Agent has stopped on a server, it no longer monitors and captures events. You must restart it on the server to enable it to monitor and capture events again.
To start a stopped Agent on a server:
Step 1 – Click Agents in the left pane to launch the Agents interface.
Step 2 – Right-click a server/Agent and select Start Agent on the menu.
Step 3 – On the Enter Credentials window, enter a username and password with sufficient rights to connect to the target machine and query information about shares. A local Administrator account on the target machine should have access to the system shares. Click OK after entering the credentials.
The wizard doesn't block access to the Administration Console, and you can minimize it while actions are in progress. If you hide the wizard by clicking outside of the dialog box, a flashing blue link with the action name displays in the upper right corner of the interface. Click the flashing link to return the focus to the wizard.
Step 4 – On the Start Agent window, Threat Prevention starts the Agent. One of two status messages displays:
- Failed – Read the failure messages and close the window. Resolve any error messages before the next attempt.
- Completed – Indicates that the task is completed
Step 5 – When the task is successfully completed, click Finish to close the window.
The Agent now runs on the server.