The inventory
Hosts lists every endpoint that has enrolled in the organizations in your scope, including those currently offline. Columns include status (online, stale, offline, isolated), operating system and version, agent version, support tier, fleet group, the required-tools badge from Security Tool Availability, risk score and tags.
Hosts are identified by the fleet identifier issued at enrolment, so a renamed machine keeps its history and two machines with the same hostname stay distinct.
Status
| Status | Meaning |
|---|---|
| Online | Heartbeat within the expected interval. |
| Stale | No heartbeat for a while; usually asleep or off the network. |
| Offline | No heartbeat for longer than the stale threshold. |
| Isolated | Containment is applied. |
Actions
From a host: open the response panel, view its events in Logs, see its alerts and cases, change its fleet group, add tags, or retire it. Retiring a host removes it from the inventory without deleting its history.
Fleet groups
Assign hosts to fleet groups to give them a policy: telemetry collection, required tools, uninstall token, update channel. See Installer bundles and enrolment.