A tour of the console
Find your way around the Foxborne console. Learn what the marking banner and status bar report, where each task lives and how to reach any incident, run or event from the keyboard.
By the end you will know what each part of the frame reports and which page holds each task. You will also move around the console with search and keyboard shortcuts.
What you need#
- A Foxborne account. Any of the five roles works for the tour, and what you can change depends on your role, as Roles and permissions sets out.
- The console open in a browser window at least 1,180 px wide. Narrower windows hide two status bar segments, and narrow screens open the sidebar from Open navigation.
Take the tour#
Sign in
The sign-in page names your organization and shows the System use notice your administrator wrote. Tick I understand and consent, then select Continue with your identity provider. The button stays disabled until the box is ticked, and the audit log records the acknowledgment.
Below a divider labeled Break-glass access, the break-glass account signs in with an email and Use a hardware security key. That path is for when the identity provider is down, and "Every use is audited and alerts your security team."
Once you are signed in, the console opens on Incidents. Its home address,
/app, opens Range status, the one-screen view of the range described below.Read the frame
The marking banner frames every screen, across the top and again across the bottom. It carries the system-high marking, CUI or UNCLASSIFIED, in the standard classification colors. The status bar above the bottom banner repeats it and reports on the deployment:
Segment Example What it tells you Marking CUI The same marking as the banner, shown while the banner is on. Environment AWS GovCloud (US-West), CUI enclave Where this deployment runs. Hover over it for the network note. Network No outbound internet States that the deployment has no outbound internet access. Collectors 13 of 15 collectors reporting Enrolled collectors online now. The dot is green only when all of them are. Select it to open Vehicle collectors. Version Foxborne 1.4.2 The installed release. Clock Sat 26 Sep 2026 09:45:00Z The current time in UTC, updated every second. The values shown are examples. All times in the console are UTC, and clock readouts end in Z. Markings and handling explains the banner.
Walk the sidebar
The sidebar groups pages by what you do on them: Operations, Investigate, Analyze, Data, Connect and Administration.
Group Item What it holds Operations Range status One screen for the range: today's and yesterday's sorties, every vehicle's link state, open incidents by evidence level, rule firings in the last 24 h and what waits on an approver. See Range status. Investigate Incidents Failures under investigation, on a site map and in a table. Its count shows incidents that are not closed. Runs Every imported flight and bench run, with its import status and clock. While runs parse, it shows a count such as 1 parsing. Vehicles Each platform, its configuration and its runs. Import files Manual upload of the files for one run. Analyze Reports The fleet over 7, 30 or 90 days: sorties, flight hours, rule results, vehicles, investigations and data quality, and saved reports generated as marked documents. See Read the fleet over time. Data Sources Storage connections and vehicle collectors. An amber count shows sources that need attention. Rules The detection rules, with their thresholds and versions. Connect Integrations Destinations, ingest endpoints, exports and the delivery ledger. An amber count shows deliveries in the dead-letter queue. Alerts The alert rules, six by default, who they notify and their recent firings. Automations The automations, four by default, and their run history. Its count shows runs held for approval. Administration Hosting Where Foxborne runs, the encryption key, updates and outbound connections. Access Members, roles and sign-in. Audit log Every recorded action, on one hash chain. Settings Marking, retention, redaction, import limits and the ordering bound. Collapse the sidebar, beside the Foxborne name, shrinks it to a rail of icons, and selecting the name expands it again. The browser remembers your choice.
At the foot of the sidebar, the deployment button shows your organization and the mode, such as Self-hosted, CUI enclave, and opens Hosting. Your name, your job title and the Account menu button sit below it.
Use the top bar
Breadcrumbs on the left show where you are, such as Incidents / INC-0142, and each crumb links back. The browser tab takes the last crumb, as in INC-0142 - Foxborne.
Each screen has its own address, down to the incident tab and the selected event, so a copied link opens the same view.
In the top bar, a readout names the active range with its MGRS 100 km square and gives the date-time group in Zulu time, in the form
DDHHMMZ MON YY, such as260945Z SEP 26. On the right sit the search field, the Keyboard shortcuts button and the theme button, which switches between the default dark theme and light.Search from anywhere
Press ⌘ K, or Ctrl K, to jump to Search incidents, runs, evidence. Results appear from the second character, in four groups:
Group Matches Up to Incidents Incident ID, title, vehicle and run ID 5 Runs Run ID, label and vehicle 5 Evidence Event IDs that start with your text, or event titles once you type more than 3 characters 6 Vehicles Vehicle ID and frame name 4 Use ↓ and ↑ to move through the results, Enter to open one and Esc to clear the field. Type
INC-0142and press Enter to open the example incident. Search does not cover sources, collectors, rules, the Connect pages, people, the audit log or settings.Learn the shortcuts
Press ? anywhere outside a text field to open Keyboard shortcuts. The top bar button and the account menu open the same list:
Action Keys Search incidents, runs and evidence ⌘ K Previous or next event ← → Zoom in or out [ ] Fit the incident window F Close the inspector or a dialog Esc Show this list ? The event, zoom and fit keys act on an incident's timeline, and the arrow keys also step between events on an event page. Keyboard shortcuts lists every key.
Open the account menu
Select Account menu, the button beside your name. It offers Light theme or Dark theme, whichever is not active, then Keyboard shortcuts and Sign out. Signing out returns you to the sign-in page.
Where each task lives#
| Task | Where in the console | Guide |
|---|---|---|
| Import a flight log and its companion evidence | Import files | Import files in the console |
| Check a run's sources, clocks and import job | Runs, then the run | Check a run |
| Open a new incident on a run | Incidents, then New incident | Work an incident |
| Work an incident from timeline to report | Incidents, then the incident | Work an incident |
| Inspect one event and its original record | The incident's Reconstruction tab, then Open event | Inspect an event |
| Write, review and export a report | The incident's Report tab | Write and review a report |
| Compare a vehicle's parameters across runs | Vehicles, then the vehicle | Vehicles and parameter drift |
| Chart the fleet over a period | Reports | Read the fleet over time |
| Save, schedule or download a report | Reports, then New report or Saved and generated | Save and schedule reports |
| Add a vehicle to the roster | Vehicles, then Add vehicle | Vehicles and parameter drift |
| Connect storage or enroll a collector | Sources, on Connections or Vehicle collectors | Connect a storage source |
| Create a detection rule | Rules, then New rule | Thresholds, scopes and overrides |
| Change a rule's threshold or scope | Rules, then the rule, then Edit | Thresholds, scopes and overrides |
| Set up a destination and turn on its egress | Integrations, on Destinations, or Add destination | Egress, data classes and the delivery ledger |
| Create an alert rule | Alerts, then New alert rule | Alerts |
| Route an alert rule or switch it off | Alerts, then the rule's Edit or its switch | Alerts |
| Create an automation | Automations, then New automation | Automations |
| Switch an automation on or read its runs | Automations, on Automations or Run history | Automations |
| Export evidence from an incident | The incident's Export button, or Integrations, Exports, New export | Export formats and evidence bundles |
| Follow an export or replay a dead letter | Integrations, on Exports or Delivery ledger | Export formats and evidence bundles |
| Check which ingest endpoints listen | Integrations, on Ingest | Stream logs to Foxborne |
| Install an update | Hosting, then Install an update | Install an update |
| Invite people and change roles | Access, on Members | Invite, change and remove access |
| Verify or export the audit chain | Audit log, then Verify chain or Export | Audit log |
| Set the marking, retention, redaction, file limit or ordering bound | Settings | Markings and handling |
What you have now#
You know what the banner and status bar report and which page holds each task. You can reach any incident, run, event or vehicle from search, and step through a timeline from the keyboard.
Next#
- Quickstart: reconstruct your first incident puts the tour to work on the example dataset.
- Roles and permissions lists what each role can change.