Skip to main content

Start a hunt

Start a hunt when a question turns into an investigation, so the hypothesis, the steps, the evidence and the verdict stay together. On this page you pick where to start from, set up the empty notebook, choose how much Scout does on its own, and add work you did elsewhere.

Ways to start a hunt​

FromWhat to doWhat you get
A chat with ScoutClick Start hunt on a Hypothesis Draft card.A hunt built from the conversation — hypothesis, queries already run, entities found. See Chatting with Scout.
An entityOpen the entity's panel and click Hunt now.A conversation seeded with that entity; Scout drafts the hunt with you.
A hunt playbookIn the Library, open a playbook and click Launch, then Launch hunt.A fresh hunt with the playbook's steps copied in. See Hunt playbooks.
The dockClick New hunt (the +) in the Workspace header.A blank hunt, opened on an empty notebook.
A new tabPick Hunt in a new tab, or New hunt from the ▾ next to +. Type what you suspect, choose the Scout autonomy, and press Enter.A hunt that Scout plans from your hypothesis, or an empty hunt if you typed nothing. No hunt exists until you press Enter.
Work in another tabAdd to hunt › New hunt from this on query results, a Scout answer or a graph node.A hunt that starts with that work as its first step. See Add work to a hunt.
The Activity FeedClick New and choose New hunt.A blank hunt.
Explorer Home, with sample data onClick Start this hunt on a card under Try a hunt on Example Corp.A hunt of your own with the card's hypothesis and its suggested queries as query cells. Once you have started one, the card offers Resume instead.
Query resultsIn a query tab, click Start hunt in the title row, or right-click rows and choose Start hunt from this row / Start hunt from N rows.A hunt seeded with those results.
An event in a searchExpand an event in Search telemetry and click Start a hunt.A hunt named after the event, with a telemetry view cell covering the 5 minutes either side of it.

New hunts begin as a Draft. Until it has any steps, the owner can remove it with ⋯ › Discard draft….

Start one from a new tab​

  1. Click + at the end of Explorer's tab bar and pick Hunt, or choose New hunt from the ▾ next to +.
  2. Type what you suspect, for example a service account is logging in from new countries.
  3. Choose the Scout autonomy (see Choose how much Scout does).
  4. Press Enter. Scout plans the hunt from your hypothesis. If you typed nothing, you get an empty hunt.

No hunt exists until you press Enter.

Start a blank hunt​

  1. Open the dock's Workspace view.
  2. Click New hunt (the +) in its header.
  3. The hunt opens on an empty notebook. Type what you're hunting in the Subject or hypothesis cell.

The empty notebook​

A new hunt's notebook opens with a Subject or hypothesis cell and three doors under How do you want to start?:

DoorWhat happens
Have Scout plan itScout reads the subject and proposes a section of query cells, behind one checkpoint that approves the plan. In Guide and Collaborator, nothing in the plan runs until you approve that checkpoint.
Write a queryAdds one blank query cell and opens it for editing.
Add from LibraryOpens the template picker; templates land as cells you can edit.

You can mix these at any time: add a query of your own after Scout's plan, or pull in a template halfway through.

Choose how much Scout does​

The Scout's autonomy selector under the doors sets how much Scout runs on its own. It is not anyone's access to the hunt.

ModeWhat Scout does
GuidePauses at every finding. You drive each step.
CollaboratorRuns low-risk queries automatically. You approve actions.
OperatorRuns the full investigation. You review the report.

The hunt header shows the mode afterwards as Scout: Guide, Scout: Collaborator or Scout: Operator. Click the chip to change it while the hunt is active; the change applies at the next checkpoint. Hunts started by a watcher default to Collaborator unless the trigger says otherwise.

Add work to a hunt​

Beta

This feature is currently rolling out and may not be enabled for your organization.

Work you do in other tabs goes into a hunt only when you add it. Add to hunt appears in these places:

WhereWhat it adds
The results header of a query tabThe query, as a step pinned to the run you're looking at.
Under a Scout answer in a chatThe answer, as a note with a link back to the chat.
A graph node's detail panelThe entity.
Next to Save view in a search of your telemetryThe search, as a query step.

Add to hunt adds to the hunt picked in the tab bar's Add to hunt goes to selector. Use its ▾ to pick another open or recent hunt, or New hunt from this to start a hunt with it. A message confirms the add, with Show in notebook.

A query tab you add is linked to its step. Its results header shows Step with the step's title and Show in notebook, and every later run in that tab updates the step.

Next steps​