Endpoints overview
Endpoints is the workspace for the hosts you manage through Endpoint Control (osctrl). It brings every endpoint from every Endpoint Control connection you can see into one place: check fleet health, find a host, tag it, run a query on it, collect a file from it, decide who may do hands-on work, and review who did what.
This feature is currently rolling out and may not be enabled for your organization. The Files and Console tabs on an endpoint's page are a separate rollout and may be off even when Endpoints is on.
Words used on these pages
| Term | Meaning |
|---|---|
| Endpoint | One host that runs the endpoint software and checks in to Huntbase. |
| Fleet | All the endpoints that belong to one Endpoint Control connection. Each connection is one fleet, named after the connection. |
| Install link | What a new endpoint uses to join a fleet. It carries a secret and it expires. See Endpoint Control. |
Open Endpoints
Click Endpoints in the navigation menu. The page header reads Endpoints — "Every endpoint across your fleets".
If you see No fleets in this scope, there is no Endpoint Control connection in the scope you are working in, or you don't have access to one. Check the Target selector in the page header, or click Go to Connections to create a connection.
Fleets and scope
The scopes you pick in the Target selector decide which fleets you see. A fleet appears once an Endpoint Control connection exists in a selected scope and you have access to it.
The fleet switcher sits at the right of the tab strip. It shows All fleets with the number of fleets, or the name of the fleet you chose. Open it to switch; each fleet is listed with its endpoint count.
| What you see | What it means |
|---|---|
| All fleets | Every fleet in your current scope, combined. |
| A fleet name | Only that fleet. Your choice carries across the tabs. |
| Shared badge | The fleet serves more than one organization. It is view-only — see Shared fleets. |
| Simulated badge | The fleet holds simulated endpoints rather than real hosts. |
| Updated … ago | When online and offline status was last refreshed for the chosen fleet. |
| Live status unavailable on this fleet | Online and offline status for this fleet can be up to an hour old. |
If you only have one fleet, the switcher is locked to it.
The tabs at a glance
| Tab | What you do there | Works across all fleets? |
|---|---|---|
| Overview | Check fleet health at a glance. | Yes |
| Endpoints | Find, filter, tag and act on endpoints. See Endpoints and endpoint details. | Yes |
| Collections | Follow file collections and download the files. See Collect files. | Yes |
| Activity | Read the audit trail of hands-on operations. See Access and activity. | One fleet at a time |
| Access | Decide who can do hands-on work on a fleet's endpoints. See Access and activity. | One fleet at a time |
| Deploy | Get install and uninstall commands and manage the install link. See Endpoint Control. | One fleet at a time |
When you open Activity, Access or Deploy with All fleets selected, the tab shows Choose a fleet — "This section works on one fleet at a time" — with a button for each fleet. Pick one to continue.
An endpoint's own page has its own tabs: Overview, Logs, Files and Console. See Endpoints and endpoint details and Files and console.
Read the Overview tab
The Overview tab summarises the fleet you chose, or all your fleets combined.
Status tiles
| Tile | What it shows |
|---|---|
| Online | Endpoints that checked in within 5 minutes. |
| Stale | Endpoints seen in the last 24 hours that are not online. |
| Offline | Endpoints silent for over 24 hours. When some have been offline for over 7 days, the tile says how many. |
| Endpoints | The total, and which fleet or how many fleets it covers. |
| Enrolled, last 7 days | Endpoints whose first check-in was in the last 7 days. |
| Agent versions | How many different versions of the endpoint software are in use, and how many endpoints are behind the most common one. |
Click Online, Stale, Offline or Endpoints to open the Endpoints tab with that filter applied.
Cards
| Card | What it shows |
|---|---|
| Check-ins | A chart of check-ins over time. Use the time range menu (from Last 3 hours to Last 7 days; Last 24 hours by default). Under the chart are totals for Check-ins, Queries, File collections and Enrollments. |
| Needs attention | A short list of things worth a look, each with a link. See the table below. |
| Platforms | Endpoints by operating system. Click a platform to list its endpoints. |
| Agent versions | Endpoints by endpoint software version. |
| Recently enrolled | The newest endpoints, by first check-in. Click one to open its page. |
Check-ins, platforms and agent versions are reported per fleet. With many fleets in view, those cards ask you to pick one fleet from the fleet switcher.
| Needs attention item | Link |
|---|---|
| Install link has expired or Install link expires in … | Manage opens Deploy for that fleet. You see View instead if you can't change the link. |
| Endpoints offline for over 7 days | Review lists them, longest silent first. |
| Endpoints behind agent version … | List shows them, oldest version first. |
| Live status is unavailable | Endpoints lists the fleet. Its online and offline status can be up to an hour old. |
When there is nothing to flag, the card says "Nothing needs attention right now."
Who can do what
What you can do on a fleet depends on your role on its connection, plus any endpoint access a fleet admin has granted you. Buttons you can't use are disabled and say why — for example "You don't have permission to collect files on this fleet. Ask a fleet admin for access."
| Task | Who can do it |
|---|---|
| See endpoints and their details | Anyone with access to the fleet, or a Viewer grant or higher on a tag. |
| Read endpoint logs | Editors and admins of the connection, or an Operator grant or higher. |
| Tag endpoints, run collections | An Operator grant or higher, or a connection role that allows it. |
| Collect files, browse files, run console commands | Admins of the connection, or a Responder grant. |
| See install commands and the install link secret; manage the link | Fleet admins (admins of the connection). |
| Open the Access and Activity tabs | Fleet admins. |
The full model — roles, tag-scoped access and how to grant it — is on Access and activity.
Shared fleets
A fleet marked Shared serves more than one organization, so it is view-only. A banner reads This fleet is shared — view only, and changing the install link, removing endpoints, collecting files, granting access and opening Files or Console sessions are turned off. Contact Huntbase support to make changes to a shared fleet.
Next steps
- Endpoints and endpoint details — find an endpoint and work on it
- Collect files — pull a file from one or more endpoints
- Access and activity — who can do what, and the audit trail
- Endpoint Control — connect a fleet and install on endpoints