Skip to content
Docs
foxborne.comRequest a pilot

A tour of the console

Find your way around the Foxborne console. Learn what the marking banner and status bar report, where each task lives and how to reach any incident, run or event from the keyboard.

TutorialMarkdown
On this page5

By the end you will know what each part of the frame reports and which page holds each task. You will also move around the console with search and keyboard shortcuts.

What you need#

  • A Foxborne account. Any of the five roles works for the tour, and what you can change depends on your role, as Roles and permissions sets out.
  • The console open in a browser window at least 1,180 px wide. Narrower windows hide two status bar segments, and narrow screens open the sidebar from Open navigation.

Take the tour#

  1. Sign in

    The sign-in page names your organization and shows the System use notice your administrator wrote. Tick I understand and consent, then select Continue with your identity provider. The button stays disabled until the box is ticked, and the audit log records the acknowledgment.

    Below a divider labeled Break-glass access, the break-glass account signs in with an email and Use a hardware security key. That path is for when the identity provider is down, and "Every use is audited and alerts your security team."

    Once you are signed in, the console opens on Incidents. Its home address, /app, opens Range status, the one-screen view of the range described below.

  2. Read the frame

    The marking banner frames every screen, across the top and again across the bottom. It carries the system-high marking, CUI or UNCLASSIFIED, in the standard classification colors. The status bar above the bottom banner repeats it and reports on the deployment:

    SegmentExampleWhat it tells you
    MarkingCUIThe same marking as the banner, shown while the banner is on.
    EnvironmentAWS GovCloud (US-West), CUI enclaveWhere this deployment runs. Hover over it for the network note.
    NetworkNo outbound internetStates that the deployment has no outbound internet access.
    Collectors13 of 15 collectors reportingEnrolled collectors online now. The dot is green only when all of them are. Select it to open Vehicle collectors.
    VersionFoxborne 1.4.2The installed release.
    ClockSat 26 Sep 2026 09:45:00ZThe current time in UTC, updated every second.

    The values shown are examples. All times in the console are UTC, and clock readouts end in Z. Markings and handling explains the banner.

  3. Walk the sidebar

    The sidebar groups pages by what you do on them: Operations, Investigate, Analyze, Data, Connect and Administration.

    GroupItemWhat it holds
    OperationsRange statusOne screen for the range: today's and yesterday's sorties, every vehicle's link state, open incidents by evidence level, rule firings in the last 24 h and what waits on an approver. See Range status.
    InvestigateIncidentsFailures under investigation, on a site map and in a table. Its count shows incidents that are not closed.
    RunsEvery imported flight and bench run, with its import status and clock. While runs parse, it shows a count such as 1 parsing.
    VehiclesEach platform, its configuration and its runs.
    Import filesManual upload of the files for one run.
    AnalyzeReportsThe fleet over 7, 30 or 90 days: sorties, flight hours, rule results, vehicles, investigations and data quality, and saved reports generated as marked documents. See Read the fleet over time.
    DataSourcesStorage connections and vehicle collectors. An amber count shows sources that need attention.
    RulesThe detection rules, with their thresholds and versions.
    ConnectIntegrationsDestinations, ingest endpoints, exports and the delivery ledger. An amber count shows deliveries in the dead-letter queue.
    AlertsThe alert rules, six by default, who they notify and their recent firings.
    AutomationsThe automations, four by default, and their run history. Its count shows runs held for approval.
    AdministrationHostingWhere Foxborne runs, the encryption key, updates and outbound connections.
    AccessMembers, roles and sign-in.
    Audit logEvery recorded action, on one hash chain.
    SettingsMarking, retention, redaction, import limits and the ordering bound.

    Collapse the sidebar, beside the Foxborne name, shrinks it to a rail of icons, and selecting the name expands it again. The browser remembers your choice.

    At the foot of the sidebar, the deployment button shows your organization and the mode, such as Self-hosted, CUI enclave, and opens Hosting. Your name, your job title and the Account menu button sit below it.

  4. Use the top bar

    Breadcrumbs on the left show where you are, such as Incidents / INC-0142, and each crumb links back. The browser tab takes the last crumb, as in INC-0142 - Foxborne.

    Each screen has its own address, down to the incident tab and the selected event, so a copied link opens the same view.

    In the top bar, a readout names the active range with its MGRS 100 km square and gives the date-time group in Zulu time, in the form DDHHMMZ MON YY, such as 260945Z SEP 26. On the right sit the search field, the Keyboard shortcuts button and the theme button, which switches between the default dark theme and light.

  5. Search from anywhere

    Press ⌘ K, or Ctrl K, to jump to Search incidents, runs, evidence. Results appear from the second character, in four groups:

    GroupMatchesUp to
    IncidentsIncident ID, title, vehicle and run ID5
    RunsRun ID, label and vehicle5
    EvidenceEvent IDs that start with your text, or event titles once you type more than 3 characters6
    VehiclesVehicle ID and frame name4

    Use ↓ and ↑ to move through the results, Enter to open one and Esc to clear the field. Type INC-0142 and press Enter to open the example incident. Search does not cover sources, collectors, rules, the Connect pages, people, the audit log or settings.

  6. Learn the shortcuts

    Press ? anywhere outside a text field to open Keyboard shortcuts. The top bar button and the account menu open the same list:

    ActionKeys
    Search incidents, runs and evidence⌘ K
    Previous or next event← →
    Zoom in or out[ ]
    Fit the incident windowF
    Close the inspector or a dialogEsc
    Show this list?

    The event, zoom and fit keys act on an incident's timeline, and the arrow keys also step between events on an event page. Keyboard shortcuts lists every key.

  7. Open the account menu

    Select Account menu, the button beside your name. It offers Light theme or Dark theme, whichever is not active, then Keyboard shortcuts and Sign out. Signing out returns you to the sign-in page.

Where each task lives#

TaskWhere in the consoleGuide
Import a flight log and its companion evidenceImport filesImport files in the console
Check a run's sources, clocks and import jobRuns, then the runCheck a run
Open a new incident on a runIncidents, then New incidentWork an incident
Work an incident from timeline to reportIncidents, then the incidentWork an incident
Inspect one event and its original recordThe incident's Reconstruction tab, then Open eventInspect an event
Write, review and export a reportThe incident's Report tabWrite and review a report
Compare a vehicle's parameters across runsVehicles, then the vehicleVehicles and parameter drift
Chart the fleet over a periodReportsRead the fleet over time
Save, schedule or download a reportReports, then New report or Saved and generatedSave and schedule reports
Add a vehicle to the rosterVehicles, then Add vehicleVehicles and parameter drift
Connect storage or enroll a collectorSources, on Connections or Vehicle collectorsConnect a storage source
Create a detection ruleRules, then New ruleThresholds, scopes and overrides
Change a rule's threshold or scopeRules, then the rule, then EditThresholds, scopes and overrides
Set up a destination and turn on its egressIntegrations, on Destinations, or Add destinationEgress, data classes and the delivery ledger
Create an alert ruleAlerts, then New alert ruleAlerts
Route an alert rule or switch it offAlerts, then the rule's Edit or its switchAlerts
Create an automationAutomations, then New automationAutomations
Switch an automation on or read its runsAutomations, on Automations or Run historyAutomations
Export evidence from an incidentThe incident's Export button, or Integrations, Exports, New exportExport formats and evidence bundles
Follow an export or replay a dead letterIntegrations, on Exports or Delivery ledgerExport formats and evidence bundles
Check which ingest endpoints listenIntegrations, on IngestStream logs to Foxborne
Install an updateHosting, then Install an updateInstall an update
Invite people and change rolesAccess, on MembersInvite, change and remove access
Verify or export the audit chainAudit log, then Verify chain or ExportAudit log
Set the marking, retention, redaction, file limit or ordering boundSettingsMarkings and handling

What you have now#

You know what the banner and status bar report and which page holds each task. You can reach any incident, run, event or vehicle from search, and step through a timeline from the keyboard.

Next#