Your first hunt
Connecting a source is only the start. Huntbase is useful once it can query that source and you have taken a hunt through to a verdict. This page covers the three things that get you there:
- Source status, which tells you whether Huntbase can query each source.
- Your first hunt, a hunt picked to fit the sources you have.
- Get set up, a checklist on Explorer's home tab that follows you after setup.
These features are currently rolling out and may not be enabled for your organization.
Can Huntbase query my source?
Every connection and telemetry ingest key gets a source status. It answers one question: has Huntbase read data back from this source yet?
| Status | Means |
|---|---|
| Checking… | Huntbase is checking the source now. |
| Connected | The source is set up. Huntbase hasn't checked for data yet. |
| Receiving | Data is arriving. Huntbase hasn't confirmed it can query it yet. |
| Queryable | A test query returned results. |
| Not queryable | The last check failed. |
| Not verified | Huntbase can't test this source directly. Its run history shows whether queries succeed. |
When a check fails, click the status to see what went wrong and how to fix it. The fix link takes you to the place to change it, for example the connection's credentials. Retry checks the source again without reloading the page. On a status that isn't a failure, the same button reads Check again.
You see the status in three places:
- The Add your connections and Send your first events steps of onboarding. When a source is queryable, Continue says so.
- Connections, on each product and at the top of a connection's page.
- Telemetry, next to each source.
A status is about querying, not about sending. A telemetry source can show Quiet on the Telemetry page because its shipper stopped a few minutes ago, while its data is still Queryable.
Huntbase checks a new ingest key a short while after its first event, because events take a little time to reach the data lake. Until then the key shows Receiving.
Start your first hunt
The last onboarding step, Time for your first run, leads with a Your first hunt card. What it offers depends on what you have connected.
| You have | The card offers |
|---|---|
| A source Huntbase can query | A starter hunt for that source. The card says which source it was picked for. |
| No queryable source yet, with sample data on | The Example Corp guided hunt. See Sample data. |
| No queryable source yet, without sample data | Install sample data, so you can hunt on Example Corp while your own data arrives. Admins can remove it at any time. |
| Nothing Huntbase can recommend | No card. The step works as described in the Quickstart. |
Click Start this hunt. Huntbase finishes onboarding and opens the hunt in Explorer. The hunt already has its title and hypothesis, and its first queries are in place as query cells.
Run a Query, Start a Hunt and I'll explore on my own are still there underneath if you'd rather do something else.
The walkthrough
A hunt opened from Your first hunt comes with a short walkthrough. It runs once.
- Results land under each query. Run a cell with the play button beside it. Its rows, or its error, appear right under the query.
- Flag what matters. Flag a result row to keep it as evidence. Your findings collect under Evidence in the side panel.
- Close it with a verdict. Pick an outcome, add one line on why, and choose Record & close hunt.
Close the walkthrough at any time with its close button or Esc. For everything else a hunt can do, see Hunts.
Get set up
Explorer's Home tab shows a Get set up checklist below the launcher until you have done everything on it:
| Item | Done when |
|---|---|
| Connect a source | You have a connection or a telemetry ingest key. |
| Receive data | A source has sent or returned events. |
| Make a source queryable | Huntbase has read data back from a source. See Can Huntbase query my source? |
| Run your first query | A query you ran has finished. |
| Close your first hunt | You recorded a verdict and closed a hunt. |
| Set up a watcher | You created a watcher. |
Each tick comes from what has actually happened, so the checklist is the same after a reload and on another device. It belongs to the organization you're working in: switch organizations with the scope selector and you see that organization's progress. The three source items count for the whole organization, so a source a teammate connected ticks them for you too. The query, hunt and watcher items are your own.
The next item to do shows a short hint and Start, which takes you where you do it. An item you have only done on Example Corp sample data, such as a hunt closed on sample data, is ticked more lightly and marked On sample data. It keeps its Go link, so you can do it on your own data too.
To hide the checklist, click its close button. It stays hidden for that organization in this browser.
Next steps
- Quickstart — the whole path from sign-up to your first hunt
- Sample data — hunt on Example Corp before your own data arrives
- Hunts — the notebook, evidence and verdicts in full
- Telemetry — whether each source is still sending