Machines
What a machine is, how the Machines page lists your machines, what each status means and what the badges on a machine's row tell you.
What a machine is
A machine is one place where an EyalSec product runs and reports to your account: a laptop, a server, a container, a deployed service or a browser PC. Every event you see is attributed to the machine that reported it, so a machine's name is how you tell your hosts apart on the Events page.
Each machine belongs to exactly one product. An es-python machine is a host that runs your Python code, and an es-chromium machine is a PC running the EyalSec browser. If you run both products on the same computer, you add two machines.
The Machines page
The Machines page is where you add machines, get their install commands and look after them afterwards. Open it from Machines in the left sidebar.
The page has three parts:
- The toolbar at the top, where you add a machine. It is only shown when your account has at least one product enabled.
- The count line under the toolbar (see the machine count).
- One row per machine, newest first. Each row shows the machine's name, an OS or product chip, a status pill, the date it was created, and its buttons: Install, Configure and the actions menu (the
⋮button). What each button does is on Managing machines.
The page refreshes the rows on its own every few seconds while it is open, so you can watch a machine change status during an install without reloading.
The machine count
The line above the list counts your machines against your plan's machine limit. The limit applies to each product separately, so with one product it reads like 2/5 machines, and with both products it shows one count per product, for example 2/5 es-python · 1/5 es-chromium.
A product that is no longer enabled on your account but still has machines is listed with its count and the word (disabled).
The OS chip
The chip after the machine's name says what the machine runs. For an es-python machine it reads OS: followed by the target you picked, such as ubuntu_24_04_x86_64. For an es-chromium machine it reads Agent: es-chromium, because a browser machine has no OS to choose.
An es-python machine with no OS shows OS: not set (click to set) in amber. It cannot be installed until you set its OS.
Disabled rows
A row drawn faded belongs to a product that is not enabled on your account any more. The machine stays listed because the product may still be installed on that host, and you still need to reach the row to rename, delete or (for es-python) uninstall it.
A faded row has no Install button, and its events stay hidden until the product is enabled again. Hover over the row to see this explained. To have a product re-enabled, email sales@eyalsec.com.
Status
The status pill on each row, labelled STATUS:, says how far the machine has got with its install. A new machine starts at created and moves to installed once the product is running and reporting.
For es-python the full path is:
created > pending install > installed
If the es-python installer stops on an error it cannot recover from, the status becomes failed instead of installed.
created
created (gold) means the machine exists in your account but nothing has been installed on it yet. Every new machine starts here, and a machine goes back to created when you click Install again to reinstall it.
pending install
pending install (amber) means an install command has been run on the host and the install has started but not finished. It normally lasts as long as the download and setup take.
If an install is interrupted, the machine can stay at pending install. Click Install on the row for a fresh command and run it again; see Troubleshooting the install.
For an es-chromium machine, pending install also covers "installed but not opened yet". That is normal, however long it lasts; see es-chromium.
installed
installed (green, gently blinking) means the product is installed and the machine can report events. For es-python this is set only after the installer has checked that the runtime starts correctly on the host.
Being installed does not mean anything is being watched yet: every taint source starts switched off. Turn on the sources you want in Configure.
failed
failed means the es-python installer hit an error it could not recover from and stopped, for example a missing tool, not enough disk space, or a download that failed its integrity check. The installer prints the reason in the terminal where you ran it.
Fix the cause, then click Install on the row for a fresh command and run that. A copy of es-python that was already working on the host from an earlier install keeps working while you do. See Troubleshooting the install for the common causes.
Row badges
Badges are the small labels on a machine's row next to the status pill or under the machine's name. Each one flags one fact about the machine, and most only appear when there is something to report.
Build badge
The build badge says whether an installed machine is running the newest EyalSec build for its target. up to date (green) means it is; newer build available (amber) means a newer build has been published since the machine was installed, and reinstalling the machine picks it up.
Hover over the badge to see the build identifiers: the installed one, and the current one when they differ. The badge only appears on installed machines, and only when both builds are known, so es-chromium machines and some older installs show no build badge at all.
Python badge
The PYTHON: badge, under the machine's name on es-python rows, shows which Python version the machine was added with, for example PYTHON: 3.13. It is set when you add the machine and decides which runtime the install command lays down.
Socket-only badge
The MODE: socket-only badge marks an older es-python machine that runs a slimmer runtime which watches network data only. On such a machine only the socket taint source is live; the file, stdin, foreign and env sources have no effect.
You cannot create socket-only machines any more: every new es-python machine gets the full runtime. The badge remains only on machines created under the old option. To move one to the full runtime, add a new machine for that host and delete the old one.
Old copy running
⚠ old copy running (red) means an older copy of es-python, from a previous install of this machine, is still running on the host. Reinstalling a machine gives it a new credential and revokes the old one, so that old copy can no longer send events: whatever it detects is lost.
To clear it, stop the programs that are still running under the old install and start them again with es-python, so they use the latest install. See Reinstall.
Clone
⚠ clone (red) means the machine's runtime reported an identity that does not match what EyalSec expected, for example the same install appearing from a second computer (a copied disk image or container) or signs that the install was tampered with.
While the badge is shown, EyalSec refuses the machine's events. If you copied an installed machine on purpose, give each copy its own machine: add a new machine and install it on the copy. If you did not, treat it as a security finding and investigate the host. Reinstalling the machine issues a fresh credential and clears the flag.