Skip to content

Runtime Explorer

Runtime Explorer combines recent event history with the latest host reports for selected sensors. Check which tab you are using: an execution or connection event is not proof that the process or socket is still running.

Use Monitor > Investigate for a different time range or more detailed historical conditions.


Sensor selection

Open Monitor > Runtime Explorer and select one or more Sensors. Large fleets require an explicit selection before data loads, preventing an accidental fleet-wide query.

The Runtime Explorer displays up to five Sensors at a time. Narrow the selection when you need to compare another set of nodes.


Tabs

The Runtime Explorer has seven tabs:

TabWhat it shows
ProcessRecorded process activity and execution context
TopProcesses ranked by CPU, memory, PID, or name
SystemRecent system-level runtime evidence
ConnectionRecorded connection activity attributed to processes
Red FlagsHigh-priority runtime evidence that requires review
ListeningListening services, addresses, ports, and owning processes
ContainerProcesses grouped by container or Kubernetes workload
Runtime Explorer Process tab showing process activity and relationships.
Runtime Explorer Process tab showing process activity and relationships. Click to enlarge
Runtime Explorer Top tab ranking processes by resource use.
Runtime Explorer Top tab ranking processes by resource use. Click to enlarge
Runtime Explorer System tab showing recent system-level evidence.
Runtime Explorer System tab showing recent system-level evidence. Click to enlarge
Runtime Explorer Connection tab showing process-attributed connection activity.
Runtime Explorer Connection tab showing process-attributed connection activity. Click to enlarge

History and current reports

Process, System, Connection, and Red Flags browse recorded activity from the recent seven-day window. Search and move through pages with Previous and Next. Browsing an older page keeps its position instead of replacing it with the latest events.

Top, Listening, and Container use the latest available sensor reports. Check the observation time before treating those reports as current.

Select a row for process identity, executable path, command, user, parent relationship, and workload context when available. Use Retry after a failed request; a load error does not mean the sensor reported no activity.


Network connections and listening services

Select Connection to review recorded process-attributed connection activity. Select Listening to identify exposed services and their owning executables. Use Network View for fleet-wide DNS and connection investigation.


  • Use Monitor > Live Feed to follow new events as they arrive.
  • Use Telco > Assurance > Packet Capture to start a bounded telecom packet capture and download PCAPNG evidence.
  • Use Monitor > Investigate to query historical runtime evidence.

Limitations

  • Current-state process data reflects the latest Sensor report. A short-lived process may appear only in Monitor > Investigate or Process Tree historical evidence.
  • Kernel threads may appear alongside user-space processes.
  • Multi-Sensor comparison is limited to five selected Sensors at a time.

Further reading

Released under the Telovix Commercial License.