Find the insights and best practices about our product.
Getting Started with Asset Management

Asset Management A central dashboard to view, organize, and take action on all your assets. This improves visibility and keeps your reporting accurate.

How to use Asset management?

To get started, navigate to Discover > Asset Management from the top menu.

 

Check guided user guide below 👇

 

Assets List View

This is the main dashboard where you can see an overview of all your assets.

 

 

  1. Toolbar: Use the Export button to download the current, filtered list of assets for audits or handoffs. You can also customize the columns shown in the table.
  2. Column Controls: Use the column headers to filter or sort your assets. This is useful for focusing investigations, for example, by filtering for assets with Critical criticality or Fully-Monitored status (Both Sensors Running).
  3. Inline Labels: Click the + icon to add or edit labels like Department or Tags. These labels are powerful tools for organization. For example, you can use them to quickly filter (Tag contains 'Prod') or to scope an incident investigation (Department is 'HR').

 

  • Asset Details View

Click on any asset from the list to open its detailed view, where you can find more information and perform specific actions.

 

 

  1. Actions Menu: This menu allows you to perform actions directly on the asset.
      1. Restart: Reboots the endpoint.
      2. Shutdown: Powers off the endpoint.
      3. Quarantine: Isolates the device from the network to contain a threat while maintaining your access to it.
        ⚠️ Important: These are powerful actions that can impact user productivity and business operations. Performing these actions requires specific user permissions. The Run a command feature is not yet available.
  2. Asset Type: Set the correct Asset Type (e.g., Windows Server, Workstation) to ensure your inventory and reports are accurate.
  3. Criticality: Set the asset's importance to the organization. Alerts generated from assets marked as Critical are automatically prioritized. You can also set up notifications to be alerted if a critical asset has been inactive for a set period (3 hours).
  4. Monitor Status: This section shows the health of the asset's security sensors ( Detect and Respond).
    1. Fully-Monitored: Both Detect and Respond sensors are operational.
    2. Partially-Monitored: Only one of the sensors is operational.
    3. Unmonitored: Neither sensor is operational.
      Use this status to quickly troubleshoot sensor issues and verify that an asset is sending logs or ready for threat hunting or incident response.

 

Did this answer you question?