Actions and runs
Running an Action on endpoints creates a run. A run records every targeted endpoint, sends the Action out in waves, and keeps the outcome of each endpoint, including endpoints that were offline and never got it.
This feature is currently rolling out and may not be enabled for your organization.
Start a run
| Where | How |
|---|---|
| Library › Actions | Click Run on an Action, or on its page. |
| An endpoint's page | Choose Respond and an Action under Saved Actions. The run targets that endpoint only. |
| Scout | Scout can propose a run. You approve it in the chat, the hunt, or the Inbox. See Scout proposals. |
In the Run dialog:
- Choose the fleet and the targets: specific Endpoints, endpoints carrying a Tag, or the Whole fleet. For tags, the dialog shows how many endpoints match and how many are offline.
- Fill in the parameters, or pick a preset.
- Choose the rollout (below) and how long the run waits for offline endpoints, 1 to 24 hours.
- Give a reason. It goes into the audit log.
- Click Run. If the Action needs approval, the run waits in Needs approval.
Rollouts
A run reaches endpoints in waves. Between waves it checks a failure gate, and it pauses if too many endpoints failed.
| Rollout | Waves | Stops if | Who can choose it |
|---|---|---|---|
| Canary first | 1% of targets (at least one), then waits for a person to click Continue, then 2,000 every 2 minutes | More than 5% fail | Anyone who can run the Action |
| Standard | 2,000 every 2 minutes | More than 5% fail | Anyone who can run the Action |
| Urgent | 10,000 every 30 seconds | More than 10% fail | Organization admins, with a reason |
Small runs fit in one wave, so a run on a single endpoint goes out immediately.
Follow runs in Activity › Actions
Activity Feed › Actions lists runs across all Actions: those running, those waiting for approval, and recent ones. Filter by Needs approval, Running or Finished.
A run's page shows:
- progress by state across all targets;
- each wave and the failure gate;
- one row per endpoint with its state, exit code, duration and the first 2 KB of output. Click Show full output for the rest.
Controls depend on the run's state and your access: Approve, Reject, Continue (after a canary), Pause, Resume, Stop, Retry failed and Retry expired. A retry starts a new run for just those endpoints, linked to the original.
Endpoint states
| State | Meaning |
|---|---|
| Waiting | Not sent yet; its wave hasn't started. |
| Sent | Sent; the endpoint hasn't checked in. |
| Running | The endpoint is running it. |
| Succeeded | Finished with exit code 0. |
| Failed | Finished with an error. The output says why. |
| Timed out | Ran past the script's timeout and was stopped. |
| Denied | The endpoint refused it, for example because safe mode is on or a check failed. The reason is shown. |
| Expired | The endpoint didn't check in before the run expired. |
A run ends as Completed, Partial (some endpoints didn't succeed) or Timed out.
On an endpoint
An endpoint's Actions tab lists every Action outcome on that machine, above its response history. An endpoint that is isolated right now carries an Isolated badge in its header.
Scout proposals
Scout can look up Actions, check a run's progress, and propose a run. Scout never approves anything:
- A proposal is a run that waits for a person's approval, shown as a card in the chat or hunt, or sent to your Inbox when Scout is working on its own.
- Scout can't propose an Urgent rollout.
- A proposal for more than 25 endpoints, or for a tag, always starts with a canary that a person must continue.
Output and retention
The first 2 KB of each endpoint's output is kept with the run. The full output, up to 64 KB per stream, is stored in your organization's storage destination, or in Huntbase storage if you haven't set one.