Skip to main content

Entity timeline

The entity timeline shows everything Huntbase knows about one host, user, IP address or file hash, newest first, in a single list. It answers "what happened on hr-ws-03?" or "where has this hash shown up?" without searching telemetry, the entity graph, hunts and alerts one at a time.

Beta

This feature is currently rolling out and may not be enabled for your organization. Where it isn't enabled, none of the entry points below appear.

What the timeline merges​

The timeline is built when you open it, from the sources below. Each item shows its kind, time and a one-line summary. Most items also have a link to where they came from.

KindWhat it isWhere it links
TelemetryProcess, network, DNS, sign-in and file events from your telemetry, read through Huntbase's normalised OCSF surfaces. The same event looks the same whichever vendor sent it.Expand the item to see its fields.
ResultsQuery runs whose results contained the entity.Open run
AlertsWatcher firings that involve the entity.Open alert
InsightsInsights linked to the entity.Open insight
HuntsHunts where the entity came up, placed at the time it first appeared in the hunt.Open hunt
NotesHunt notes that mention the entity.Open in hunt

Everything is read-only and stays within your current scope. Each kind also needs its own permission. For example, you need access to telemetry to see telemetry items. If you don't have it, that kind is listed as skipped in the coverage note.

Open a timeline​

FromHow
The entity panelOpen a host, user, IP or file entity (a file needs a hash) and choose the Timeline tab. Open full page opens the timeline page. See Entities.
A result rowOpen a row's details in a query tab. Under Open timeline, click one of the chips. There is one chip for each host, user, IP address and hash found in the row.
Search telemetryIn an expanded event, click the clock icon next to a host, user, IP or hash field. On the Fields tab, the same icon sits next to each qualifying value. See Search telemetry.
A Scout chatClick Open timeline on Scout's timeline card. See Ask Scout below.
A linkTimeline pages have their own address, /entities/<type>/<value>/timeline, which you can bookmark or share with anyone in your organization.

In result rows and events, Huntbase decides what counts as a host, user, IP address or hash as follows:

  • Hosts and users are recognised by the column name, such as host, hostname, Computer, device_hostname, user, TargetUserName or actor_user_name.
  • IP addresses are recognised from the value itself, in any column.
  • Hashes are recognised from the value (MD5, SHA-1 or SHA-256). Sysmon's Hashes field is supported, and the timeline opens on its SHA-256.
  • Skipped: placeholders such as -, machine accounts ending in $, and loopback addresses.

Read the timeline​

  • Kind chips show or hide each kind.
  • Time window can be the last hour, 24 hours (the default) or 7 days.
  • The activity strip counts items over the window, coloured by kind.
  • Items are listed newest first. Click an item to see its fields and what it matched on, for example device_hostname.

How names are matched​

Different sources write the same entity in different ways. The timeline turns every name into one key and looks for all the usual spellings:

TypeYou can enterAlso matches
Hosthr-ws-03, HR-WS-03 or hr-ws-03.corp.example.comThe short name in any case, and the fully qualified name (FQDN).
Userj.chen, CORP\j.chen or [email protected]The bare name, DOMAIN\user, and the sign-in name (user@domain, as used by Okta and Entra ID).
IP address10.14.42.103, 2001:db8::1Other ways of writing the same IPv6 address, and IPv4-mapped IPv6 addresses such as ::ffff:10.14.42.103.
HashAn MD5, SHA-1 or SHA-256 valueThe same value in upper or lower case.

Host and user names are only unique within one organization, so the timeline only ever searches your own data. A short name can belong to more than one domain, for example CORP\j.chen and LAB\j.chen. Check each item's matched on field when that matters.

Coverage​

A quiet timeline doesn't always mean nothing happened. The coverage note above the list says what was actually searched:

  • Surfaces searched gives the number of telemetry surfaces and rows read.
  • Skipped lists kinds that weren't searched, with the reason. For example, you may not have access, a source may have timed out, or a hunt or note needs a signed-in user.
  • Formats without the matching column are log formats that don't carry this kind of field, for example a source with no hash column. Those events weren't searched.
  • Row cap reached: a surface returned the most rows it can. Older matches in the window aren't shown.

Telemetry is searched over the last 7 days at most. Other kinds reach back up to 90 days. Your own connected lakes are not searched yet.

Ask Scout​

When you ask Scout about a single entity, for example "what happened on hr-ws-03 in the last day?" or "have we seen this hash?", Scout uses the entity timeline instead of writing a query for you. The tool shows as get_entity_timeline in the chain of thought.

Scout's answer comes with a timeline card. The card shows:

  • the entity and the number of items of each kind
  • the newest few items
  • what wasn't searched
  • an Open timeline link to the full page

If the timeline couldn't be built, the card says so. In that case, activity is unknown rather than empty. Scout only reads telemetry for the timeline when its telemetry tools are on for you.

Next steps​