Find a security item
- Open Security > Huntress and confirm your company selection.
- In Huntress security items, use Search Huntress to find a title, company, organization, or text in the imported description.
- Choose All items, Escalations, Incidents, or Remediations to narrow the type.
- Review Item, Status, Severity, Company, and Detected. Browse additional pages when available; each page contains up to 25 items.
- Use Open in Huntress in the Open column when a link is supplied. It opens the provider record in a new tab and may require a separate authorized sign-in.
Understand the summaries
The summary cards use the selected company scope. Searching or changing the item type narrows the table without changing the cards.
The active-agent count can include an agent with a callback within the last 30 days, as well as explicit active/online status. Active does not guarantee that a device is online now. An Approved remediation is excluded from the pending count; approval alone does not establish that the remediation finished.
A missing status can still contribute to an open or pending count. Inspect the provider record before interpreting unfamiliar or absent statuses.
Read dates and related records
Detected is a shared column with different meanings by item type. For escalations it uses the occurrence time when supplied; incident reports use their report generation time when supplied. Both can fall back to an imported creation date. A remediation can show its last sync date. Do not treat every Detected value as the original security incident time. Escalations can involve multiple mapped organizations. In a portfolio view, one escalation can show several company names. Remediation links can open the parent incident report. Missing severity on a remediation is not a low-risk rating.If results are missing or unexpected
- Clear Search Huntress and choose All items. Confirm the company selection.
- After switching company from a later page, reset the search or type to return to page 1. A later page can be empty even when the new company has records, and pagination can disappear with an empty result.
- Ask the MSP to verify Huntress organization mapping and imports. Unmapped organizations are excluded from these results.
- Do not use No Huntress security items found or zero summary cards as proof of safety. A loading failure can look like an empty result or zero counts, and a previous result can remain visible during a later failure.
Frequently asked questions
Why do the cards stay the same when I search?
Why do the cards stay the same when I search?
The cards summarize the selected company scope. Search and type filters apply to the item table only.
Does Active mean the device is online right now?
Does Active mean the device is online right now?
No. The count can include a recent callback within 30 days. Confirm the current provider state when it matters.
Can I approve or run a remediation here?
Can I approve or run a remediation here?
No. This page displays imported records and available external links. Use the authorized provider workflow.
Why can a company switch leave an empty page?
Why can a company switch leave an empty page?
The previous page number can remain selected. Change or clear the search/type filter to return to page 1, then check mapping and import health if records remain missing.