Assets

The Assets page lists all asset entities that Anomali Agentic SOC Operations has consolidated from your connected asset management systems and data sources. Each entry displays the asset risk score, source, group memberships, and status, giving your team a complete view of every monitored asset in your organization.

Accessing Assets

To access Assets:

  1. On the left navigation bar, click Entity Management > Entities.

  2. On the Entities page, click the Assets tab.

Understanding the Assets List

The Assets list displays all asset entities in your organization. Use the search field and filters to narrow results. Click an asset hostname to open its details.

Search Assets: Filter the assets list by hostname, IP address, or MAC address. Results update as you type.

Source: Filter the list by the data source the asset was ingested from, for example, EDR, CMDB, or Tenable.

Risk Score: Filter the list by risk level. Possible values are Critical (75–100), High (50–74), Medium (25–49), and Low (0–24).

Group: Filter the list by peer group membership.

Status: Filter the list by asset status. Possible values are Active and Inactive.

Owner / OS: Filter the list by assigned owner or by operating system platform.

Hostname: The primary identifier for the asset. Click a hostname to open the Asset Details panel. See Viewing Asset Details for more information.

Hostname: The primary identifier for the asset. Click a hostname to open the Asset Details panel. See Viewing Asset Details for more information.

MAC Address: The hardware MAC address of the asset.

Platform: The operating system or platform of the asset, for example, Windows 11 Pro or Ubuntu 22.04 LTS.

Owner: The individual or team assigned as responsible for this asset.

Tags: Labels assigned to the asset for categorization or search.

Risk Score: The current risk score for the asset, calculated from detections in a rolling 24-hour window. See Entity Risk Scores for more information.

Source: The data source the asset record was ingested from.

Last Seen: The time elapsed since the asset was last observed in a detection or activity event.

To export all assets matching the current filters, click the more options menu () to the right of the Add Asset button, then select Export Assets. The export downloads the full current result set based on applied filters.

Click the View Settings gear icon () in the pagination bar to customize the table. The View Settings panel lets you toggle column visibility, drag columns to reorder them, and reset the layout to defaults with Reset View. Use the Density toggle to switch between Default and Compact row height.

Understanding Asset Details

The Asset Details panel gives you a complete view of a single monitored asset, including its current risk score on a 0–100 scale, active detections within the current 24-hour window, profile fields, and peer group memberships.

Reviewing the Risk Score tab shows how peer group multipliers and any configured overrides contribute to the final score.

See Viewing Asset Details for more information.

Understanding Asset Permissions

Users with the Manage Entities permission can add, edit, or remove assets, set or change risk overrides, and add or remove assets from peer groups. Users with only the View Entities permission can view the assets list, asset details, and export asset data.

Action Permission Required
View the assets list and asset details View Entities
Export asset data
Add an asset manually Manage Entities
Edit an asset record
Merge asset records
Set or change an asset risk override
Add or remove assets from peer groups

For details on assigning these permissions to a role, see Managing Roles.

Adding an Asset

Each asset record represents a single endpoint, device, or other resource monitored by Anomali Agentic SOC Operations. You can create assets manually one at a time. See Adding an Asset for more information.

Managing Existing Assets

Use bulk actions to apply risk overrides, assign assets to peer groups, or export records for multiple selected assets at once. Each row also has an options menu that lets you view details, edit, or remove a single asset without a bulk selection. See Managing Assets for more information.