Sample data
Example Corp is a made-up company whose data lets you try Huntbase before your own sources are connected. An organization can have a copy of it: sample connections, alerts, entities, hunts, playbooks and saved queries, plus a small read-only endpoint fleet. None of it is yours, and it never mixes with your own data. It only sits beside your data until an admin removes it or it removes itself.
While sample data is on, a banner across the top of every page says so: You're exploring Example Corp sample data — none of it is yours. It has Connect your data and, for admins, Remove sample data. You can dismiss the banner for the rest of your browser session.
Sample data belongs to an organization. Under a personal scope there is none.
How to recognise it
Anything that came with sample data carries an amber Sample chip. Hover it for Example Corp sample data. None of it is yours, and it goes when an admin removes sample data.
| Where | What you see |
|---|---|
| Connections | Sample connections are listed with the Sample chip and are read-only. |
| Activity Feed | Sample rows have the Sample chip, and their owner is Example Corp rather than the person who set up the organization. |
| Hunts | Sample hunts are owned by Example Corp (sample) and are read-only. See Sample hunts are read-only. |
| Entities | Sample entities have the Sample chip. |
| Endpoints | The Example Corp fleet is read-only: nothing can be deployed to it, and endpoint cells and response actions can't run on it. |
What counts, and what doesn't
- Queries. Sample connections are in scope for your organization, so a query on Auto-select runs on them like any other connection. That's how you can try queries before you connect anything.
- The catalog. A sample connection doesn't make a product Connected. In Connections, Add a source opens on All until you have a connection of your own, and a product that only Example Corp has a connection for shows the Sample chip instead of Connected. It stays under Available, so you can still find and connect it.
- Your connections. The list of your connections still shows the sample ones, with their chip.
Try a hunt on Example Corp
While sample data is on, Explorer's Home tab has a Try a hunt on Example Corp section with guided hunts that follow the Example Corp story. You may also be offered one while you set up your organization.
- Start this hunt creates a hunt of your own with the card's hypothesis, and adds the card's suggested queries as query cells, ready to run.
- Once you have started a hunt from a card, the card shows Resume, which opens that hunt instead of creating another.
- The story plays out over time. A card for a part that hasn't happened yet is disabled and says when it will be available, for example This part of the story hasn't happened yet — available in about 20 hours.
A hunt you start yourself is yours: you can run, edit and close it like any other. See Hunts.
Sample hunts are read-only
The hunts that come with sample data are owned by Example Corp (sample). The access chip says Example Corp sample hunt. You can read it but not change it. You can open and read them, but not add cells, import YAML, arm triggers or reopen them.
Manage sample data
Open Settings, pick your organization, and choose Sample data. Everyone in the organization can see its status and what it includes; only an org admin can change it.
| Section | What it shows |
|---|---|
| Status | On, Paused, Installing, Removing, Removed, Not installed or Needs attention, with when it was Installed, Your first real data, the Next sample alert and the date it Removes itself on. |
| What's included | How many Connections, Alerts, Hunts and Entities came with it. |
| New sample alerts | Example Corp keeps producing alerts over the first two weeks, so there is always something new to hunt. Pause stops new ones; what is already there stays. Resume starts them again. |
| Remove automatically | The date sample data removes itself, which you can change or clear with Keep. |
| Remove sample data | Removes it now. See Remove sample data. |
If an install or removal didn't finish, the status reads Needs attention, and an admin can remove it or install it again. After removal, an admin can Install sample data again from the same page.
Automatic removal
Sample data stays until you remove it, and is removed automatically 14 days after your own data starts arriving. Your data counts as arriving the first time a real connection runs successfully, a webhook receives an event, or a telemetry ingest key is used.
When that happens the banner changes to Your data is flowing. Remove Example Corp now? with the date it will otherwise remove itself. Admins can click Remove sample data, or Keep for now to push the date back. You get notice three days before the date. To keep sample data for good, clear the date with Keep under Remove automatically.
Remove sample data
Click Remove sample data, from the banner or the settings page. The page lists what goes and what stays before you confirm:
| Goes | Stays |
|---|---|
| The Example Corp connections, alerts, entities and graph | All of your own connections and data |
| The read-only sample endpoint fleet | Hunts that mixed sample and real data (their sample steps are marked removed) |
| Sample hunts, playbooks and saved queries that came with it | Playbooks, saved queries and schedules your team made (sample sources are dropped from them) |
| Hunts your team ran only on sample data, and their Scout chats | Scout chats that were not part of a removed hunt |
Removal hides sample data from everyone straight away, then deletes it everywhere it is stored in the background. It can't be undone, but an admin can install a fresh copy later.
Next steps
- Quickstart — connect your first source
- Connections — add a source of your own
- Hunts — the notebook, cells and verdicts
- Organization management — the rest of your organization's settings