Use Asset Manager to create assets, change their tags, create asset groups, add asset sources, and assign assets to groups.
An asset is any device on your network with an IP address. Events are activities on or involving an asset. Flows are connections between assets.
On the system navigation tree, select Receiver Properties, then click Asset Sources.
Click Add, then configure the asset.
Select Enabled to enable the automatic retrieval functionality. If the checkbox is not selected, you can still retrieve data from the asset source manually by clicking Retrieve. If it is selected, the system retrieves the data at the interval specified in the Retrieve Data field.
Select the type of asset source.
The remaining fields vary based on the type you select.
Type a name for this asset source.
(Optional) Select a zone for this asset source.
Select the priority that you want this asset source to have if it discovers an asset at the same time as vulnerability assessment or network discovery. The options are 1–5, 1 being the highest.
Type the IP address and port for your asset source.
Select if you want to use the TLS encryption protocol (for Active Directory) or SSL (for Altiris).
Type the user name and password needed to access the asset.
Type the name for the domain controller (for example,
dc=Trellix,dc=com).(Altiris only) To enable the proxy server, select Enable, and enter the proxy IP address, port, and credentials.
To retrieve data automatically, select how often to retrieve.
To test the connection, click Connect.
Click OK, then click Write on Asset Sources.
Note
Some data sources (including Linux and UNIX servers) can produce large amounts of non-uniform data that results in the Receiver not properly grouping similar events together. This results in a large range of different events when, in actuality, the same event is simply repeating, but with varying syslog data sent to the Receiver.