Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

User Guide

Osprey is a web-based investigation and management console for safety teams. Query event data in real time, visualize trends, label entities, manage rules and features, and run bulk operations. If terms like events, features, and labels are new to you, start with Concepts.

The Osprey UI during an investigation: a query filtering events where SuspiciousDisplayName is True, timeseries charts of matching event volume, and the live event stream with one entity’s label popup open showing a negative spam_display_name label

The sidebar groups Osprey’s tools by task, and this guide follows the same sections:

  • Investigate: query events in real time, chart the results, and drill into individual events and entities. Query history and saved queries let you revisit and share past investigations.

    Two Top N tables for a query, grouping matching events by event type and by post text

  • Manage: browse the rules, features, and UDFs configured in your deployment, and visualize how rules and labels relate.

    The UDF Registry listing available functions with type signatures and descriptions, grouped by category

  • Operate: run bulk labeling jobs over query results and review past jobs.

    The Bulk Edit Labels form for roughly 9,800 entities matching a query, with label name, status, reason, and expiration fields

The sidebar can be collapsed to an icon-only strip with the toggle at the bottom, and its state persists between sessions. The interface follows your OS or browser color scheme preference, or you can select a light or dark style using the toggle in the navigation bar.