Skip to main content

Endpoints overview

Endpoints is the workspace for the hosts you manage through Endpoint Control (osctrl). It brings every endpoint from every Endpoint Control connection you can see into one place: check fleet health, find a host, tag it, run a query on it, collect a file from it, decide who may do hands-on work, and review who did what.

Beta

This feature is currently rolling out and may not be enabled for your organization. The Files and Console tabs on an endpoint's page are a separate rollout and may be off even when Endpoints is on.

Words used on these pages

TermMeaning
EndpointOne host that runs the endpoint software and checks in to Huntbase.
FleetAll the endpoints that belong to one Endpoint Control connection. Each connection is one fleet, named after the connection.
Install linkWhat a new endpoint uses to join a fleet. It carries a secret and it expires. See Endpoint Control.

Open Endpoints

Click Endpoints in the navigation menu. The page header reads Endpoints — "Every endpoint across your fleets".

If you see No fleets in this scope, there is no Endpoint Control connection in the scope you are working in, or you don't have access to one. Check the Target selector in the page header, or click Go to Connections to create a connection.

Fleets and scope

The scopes you pick in the Target selector decide which fleets you see. A fleet appears once an Endpoint Control connection exists in a selected scope and you have access to it.

The fleet switcher sits at the right of the tab strip. It shows All fleets with the number of fleets, or the name of the fleet you chose. Open it to switch; each fleet is listed with its endpoint count.

What you seeWhat it means
All fleetsEvery fleet in your current scope, combined.
A fleet nameOnly that fleet. Your choice carries across the tabs.
Shared badgeThe fleet serves more than one organization. It is view-only — see Shared fleets.
Simulated badgeThe fleet holds simulated endpoints rather than real hosts.
Updated … agoWhen online and offline status was last refreshed for the chosen fleet.
Live status unavailable on this fleetOnline and offline status for this fleet can be up to an hour old.

If you only have one fleet, the switcher is locked to it.

The tabs at a glance

TabWhat you do thereWorks across all fleets?
OverviewCheck fleet health at a glance.Yes
EndpointsFind, filter, tag and act on endpoints. See Endpoints and endpoint details.Yes
CollectionsFollow file collections and download the files. See Collect files.Yes
ActivityRead the audit trail of hands-on operations. See Access and activity.One fleet at a time
AccessDecide who can do hands-on work on a fleet's endpoints. See Access and activity.One fleet at a time
DeployGet install and uninstall commands and manage the install link. See Endpoint Control.One fleet at a time

When you open Activity, Access or Deploy with All fleets selected, the tab shows Choose a fleet — "This section works on one fleet at a time" — with a button for each fleet. Pick one to continue.

An endpoint's own page has its own tabs: Overview, Logs, Files and Console. See Endpoints and endpoint details and Files and console.

Read the Overview tab

The Overview tab summarises the fleet you chose, or all your fleets combined.

Status tiles

TileWhat it shows
OnlineEndpoints that checked in within 5 minutes.
StaleEndpoints seen in the last 24 hours that are not online.
OfflineEndpoints silent for over 24 hours. When some have been offline for over 7 days, the tile says how many.
EndpointsThe total, and which fleet or how many fleets it covers.
Enrolled, last 7 daysEndpoints whose first check-in was in the last 7 days.
Agent versionsHow many different versions of the endpoint software are in use, and how many endpoints are behind the most common one.

Click Online, Stale, Offline or Endpoints to open the Endpoints tab with that filter applied.

Cards

CardWhat it shows
Check-insA chart of check-ins over time. Use the time range menu (from Last 3 hours to Last 7 days; Last 24 hours by default). Under the chart are totals for Check-ins, Queries, File collections and Enrollments.
Needs attentionA short list of things worth a look, each with a link. See the table below.
PlatformsEndpoints by operating system. Click a platform to list its endpoints.
Agent versionsEndpoints by endpoint software version.
Recently enrolledThe newest endpoints, by first check-in. Click one to open its page.

Check-ins, platforms and agent versions are reported per fleet. With many fleets in view, those cards ask you to pick one fleet from the fleet switcher.

Needs attention itemLink
Install link has expired or Install link expires in …Manage opens Deploy for that fleet. You see View instead if you can't change the link.
Endpoints offline for over 7 daysReview lists them, longest silent first.
Endpoints behind agent version …List shows them, oldest version first.
Live status is unavailableEndpoints lists the fleet. Its online and offline status can be up to an hour old.

When there is nothing to flag, the card says "Nothing needs attention right now."

Who can do what

What you can do on a fleet depends on your role on its connection, plus any endpoint access a fleet admin has granted you. Buttons you can't use are disabled and say why — for example "You don't have permission to collect files on this fleet. Ask a fleet admin for access."

TaskWho can do it
See endpoints and their detailsAnyone with access to the fleet, or a Viewer grant or higher on a tag.
Read endpoint logsEditors and admins of the connection, or an Operator grant or higher.
Tag endpoints, run collectionsAn Operator grant or higher, or a connection role that allows it.
Collect files, browse files, run console commandsAdmins of the connection, or a Responder grant.
See install commands and the install link secret; manage the linkFleet admins (admins of the connection).
Open the Access and Activity tabsFleet admins.

The full model — roles, tag-scoped access and how to grant it — is on Access and activity.

Shared fleets

A fleet marked Shared serves more than one organization, so it is view-only. A banner reads This fleet is shared — view only, and changing the install link, removing endpoints, collecting files, granting access and opening Files or Console sessions are turned off. Contact Huntbase support to make changes to a shared fleet.

Next steps