Skip to main content

Actions and runs

Running an Action on endpoints creates a run. A run records every targeted endpoint, sends the Action out in waves, and keeps the outcome of each endpoint, including endpoints that were offline and never got it.

Beta

This feature is currently rolling out and may not be enabled for your organization.

Start a run​

WhereHow
Library › ActionsClick Run on an Action, or on its page.
An endpoint's pageChoose Respond and an Action under Saved Actions. The run targets that endpoint only.
ScoutScout can propose a run. You approve it in the chat, the hunt, or the Inbox. See Scout proposals.

In the Run dialog:

  1. Choose the fleet and the targets: specific Endpoints, endpoints carrying a Tag, or the Whole fleet. For tags, the dialog shows how many endpoints match and how many are offline.
  2. Fill in the parameters, or pick a preset.
  3. Choose the rollout (below) and how long the run waits for offline endpoints, 1 to 24 hours.
  4. Give a reason. It goes into the audit log.
  5. Click Run. If the Action needs approval, the run waits in Needs approval.

Rollouts​

A run reaches endpoints in waves. Between waves it checks a failure gate, and it pauses if too many endpoints failed.

RolloutWavesStops ifWho can choose it
Canary first1% of targets (at least one), then waits for a person to click Continue, then 2,000 every 2 minutesMore than 5% failAnyone who can run the Action
Standard2,000 every 2 minutesMore than 5% failAnyone who can run the Action
Urgent10,000 every 30 secondsMore than 10% failOrganization admins, with a reason

Small runs fit in one wave, so a run on a single endpoint goes out immediately.

Follow runs in Activity › Actions​

Activity Feed › Actions lists runs across all Actions: those running, those waiting for approval, and recent ones. Filter by Needs approval, Running or Finished.

A run's page shows:

  • progress by state across all targets;
  • each wave and the failure gate;
  • one row per endpoint with its state, exit code, duration and the first 2 KB of output. Click Show full output for the rest.

Controls depend on the run's state and your access: Approve, Reject, Continue (after a canary), Pause, Resume, Stop, Retry failed and Retry expired. A retry starts a new run for just those endpoints, linked to the original.

Endpoint states​

StateMeaning
WaitingNot sent yet; its wave hasn't started.
SentSent; the endpoint hasn't checked in.
RunningThe endpoint is running it.
SucceededFinished with exit code 0.
FailedFinished with an error. The output says why.
Timed outRan past the script's timeout and was stopped.
DeniedThe endpoint refused it, for example because safe mode is on or a check failed. The reason is shown.
ExpiredThe endpoint didn't check in before the run expired.

A run ends as Completed, Partial (some endpoints didn't succeed) or Timed out.

On an endpoint​

An endpoint's Actions tab lists every Action outcome on that machine, above its response history. An endpoint that is isolated right now carries an Isolated badge in its header.

Scout proposals​

Scout can look up Actions, check a run's progress, and propose a run. Scout never approves anything:

  • A proposal is a run that waits for a person's approval, shown as a card in the chat or hunt, or sent to your Inbox when Scout is working on its own.
  • Scout can't propose an Urgent rollout.
  • A proposal for more than 25 endpoints, or for a tag, always starts with a canary that a person must continue.

Output and retention​

The first 2 KB of each endpoint's output is kept with the run. The full output, up to 64 KB per stream, is stored in your organization's storage destination, or in Huntbase storage if you haven't set one.