Hunt Across the Book
One indicator, every customer at once: which estates have it in their records, and what the graph says about it.
On this page (7)
Hunt Across the Book Documentation
Hunt searches every customer at once for one indicator. Use it when something learned in one estate might be true in the others.
Step 1: enter the indicator
Hunt takes a hostname, an IP address or an ASN. Enter one:
cdn.example-delivery.net
The search box in the header is a different tool: it finds a customer, an endpoint or an incident by name. Hunt searches records.
Step 2: read the hits, customer by customer
The answer is grouped by customer: each estate that has the indicator in its records, and the endpoints there that carry it.
What the book records is DNS lookups and connections, so a hit means an endpoint in that estate looked the name up or opened a connection to the address. A customer with no rows has no such record. That is a different reading from a customer you hold no key for, which is named as ungranted; customer keys and grants covers why the portal draws that line.
Step 3: read the verdict beside it
The indicator itself is scored by the graph, alongside the hits, so you see what is known about the destination and who reached it on one screen. Unknown is reported as unknown.
A file hash returns the graph's verdict on the hash and nothing from the book. To find which endpoints touched something, hunt the name or the address it resolved to.
Step 4: open a case where it matters
For each customer with hits, open a case from the endpoint carrying them. The case is where the verdict, the endpoints and any action taken end up on one record; incidents and cases describes what it holds.
Open one case per affected customer rather than one across the book. Each estate has its own record, and a customer can read theirs.
Step 5: keep the hunt standing
A hunt you will want again can be saved as a standing hunt, so it keeps running against records as they arrive instead of being retyped.
What you should see
One group per customer with hits, the endpoints inside each group, and the graph's verdict on the indicator beside them. A customer with no record of the indicator has no group. An estate with no grant is listed and named as ungranted, so the absence of hits is never ambiguous.
Where a hit goes next
If the same destination turns up in more than one estate, shared infrastructure reads the book that way and pushes one verdict to the rest of it as a resolver rule. On the endpoint that reached it, the response verbs are what you dispatch.