Management

View Nodes

To view all deployed agents:

  1. Login go the SamurAI MDR Portal

  2. Click Telemetry and select SamurAI Endpoint Agent from the main menu.

Dashboard

The dashboard panel displays summary information:

  • Nodes: the total deployed and seen by the SamurAI platform
  • Online: the total currently online (have communicated with the SamurAI platform within five minutes)
  • Offline: the total number offline (have not communicated with the SamurAI platform for five minutes)
  • Platforms: the total number of platforms i.e Windows / MacOS / Linux

Nodes Table

A table displays all deployed agents with node specific information:

FieldDescription
IDUniversally Unique Identifier (UUID) of the node
Status DescriptionStatus of the agent. Potential status displayed: Online or Offline
NameHostname of the endpoint
PlatformPlatform and architecture - icon depicting OS and processor e.g AMD64
OS NameThe underlying operating system
OS VersionThe operating system version
Agent VersionThe SamurAI Endpoint Agent version installed
Sysmon VersionThe System Monitor (sysmon) version installed
Last external IPThe external IP address of the agent as seen by the SamurAI platform
Last SeenDate and timestamp of when the agent last checked-in to the SamurAI platform
Inactivity ThresholdAn indicator displaying time until the agent will be deemed inactive and purged from view

Inactive Node(s)

Nodes communicate with the SamurAI platform every minute and are marked offline if no communication is received after five minutes.

Offline nodes will be visible for 90 days, after this threshold it is deemed to be inactive and purged from the SamurAI platform backend and the current view.

You can view inactive and deleted nodes within the Node History.

Delete Node(s)

You can delete nodes from the table:

  1. Select the nodes you wish to Delete
  2. Click Actions and select Delete selected nodes
  3. To ensure you intended to delete the agents you will need to type DELETE in the field and select Delete
  4. The deleted node record will appear under Node History.

Node History

The Node History log displays a table of Deleted Nodes and Purged (deemed inactive) with node specific information:

FieldDescription
IDUniversally Unique Identifier (UUID) of the node
ActionThe action taken against the node. This could include Purged based on the inactivity threshold or Deleted
NameHostname of the endpoint
Last StatusThe Last known Status of the node (typically offline)
OS NameThe underlying operating system
UserThe user that deleted the node. This could also include System which denotes the SamurAI platform when the node is inactive and purged
Last EnrolledDate and timestamp of when the node was originally enrolled
Action AppliedDisplays when the Action was applied to the node