Manage machines

How to look after a machine once it exists: setting a missing OS, renaming, reinstalling to take a newer build, configuring what it watches, uninstalling es-python from the host, and deleting a machine.

Where the controls are

Each machine's row on the Machines page has two buttons and a menu. Install gets an install command (and is also how you reinstall), Configure opens the machine's detection settings, and the ⋮ button opens the actions menu with Rename, Delete and, on es-python machines, Uninstall.

Install only appears when the machine can be installed: an es-python machine needs its OS set first, and a machine whose product is not enabled on your account has no Install button.

Set the OS

An es-python machine with no operating system shows OS: not set (click to set) in amber, and has no Install button until you set one. Click the chip, pick the Distro and Arch from the lists that appear under the row (the same lists as when adding a machine), and click Save. Cancel closes the picker without changes.

EyalSec publishes a runtime matched to each distro and architecture, which is why the OS has to be known before it can install.

Once an OS is set, the chip is no longer clickable, so the Machines page cannot change it. If a machine was added with the wrong distro or arch (the installer tells you, see Troubleshooting the install), add a new machine with the right values and delete the wrong one. You can also change it through the API: see Machines API.

Rename

Renaming changes the name a machine is shown under, everywhere in the dashboard. Open the ⋮ menu on the row, choose Rename, type the new name (up to 128 characters) and click Save or press Enter; Cancel or Escape keeps the old name.

Renaming is purely cosmetic. The machine keeps its events, settings and credential, and nothing needs to change on the host. An es-chromium browser shows the name it was installed with until it is reinstalled.

Reinstall and update

Reinstalling lays down a fresh copy of the product on a machine, and is how you update a machine to a newer EyalSec build. There is no separate Reinstall button: click Install on the row, exactly as for a first install, and run the new command on the host.

Reinstall when:

  • the row shows the build badge newer build available;
  • an install failed or was interrupted, and the machine shows failed or is stuck at pending install;
  • the row shows ⚠ clone and you want a fresh credential for it.

For an es-python machine, clicking Install on an installed machine puts it back to created and issues a new command. Its name, settings and events are kept. The copy already on the host keeps working until the new install starts; from that moment the machine gets a new credential and the old one stops being accepted.

Programs that were started under the old install and are still running then show up as ⚠ old copy running. Restart them after the reinstall so they pick up the new install.

For an es-chromium machine, clicking Install simply issues a fresh install command for the same machine; see Install es-chromium.

Reinstalling never adds a machine and never uses a new slot of your machine limit.

Configure

Configure opens the machine's detection settings: which taint sources it watches, which rules apply to it, and what it sends with each event. Settings made here apply to this machine only; anything you leave unset follows the settings for all machines of the product.

Every taint source is off on a new machine, so this is where you switch detection on after installing. The full walkthrough is on Configure, including which scope wins and when a change reaches the machine.

Uninstall

Uninstall removes es-python from the host and the machine from your dashboard in one step. It is in the ⋮ menu of es-python machines only.

  1. Choose Uninstall and confirm the warning. It says that running the command removes es-python and deletes the machine and all its events from the dashboard, and that this cannot be undone.
  2. An Uninstall EyalSec panel shows a one-line command. Click Copy.
  3. Run the command in a terminal on the host.

The command removes every es-python runtime under ~/opt/, every es-python launcher and the eyalsec helper from ~/.local/bin/, the ~/.eyalsec/ directory, and the # es-python PATH lines the installer added to your shell's startup files. When it runs, the server deletes the machine and all of its events.

Nothing happens until the command is run on the host: if you never run it, the machine and its events stay. The command's token works once and expires after 10 minutes; choose Uninstall again for a new one.

es-chromium machines have no Uninstall item. Remove the browser from the PC yourself (see es-chromium status), then delete the machine.

Delete

Delete removes a machine and all of its events from your account. Open the ⋮ menu, choose Delete (shown in red) and confirm the warning: "Delete machine "name"? This will also permanently delete all events from this machine. This cannot be undone."

Delete is permanent and there is no undo. It frees the machine's slot in your machine limit.

Delete does not touch the host. Whatever is installed there keeps running, but its credential no longer belongs to any machine, so nothing it detects is recorded. To remove es-python from the host as well, use Uninstall instead of Delete.

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo