The asset detail pages show host and user profiles.
To view the asset detail pages:
Click an asset name in the Asset-Based Alert Correlation table on the Entities page or the Asset-Based Alert Correlation page.
Click an asset name on the Affected Assets tab on an alert details page.
Click the username or agenthostname field on the Most Recent Event or Events tab of an alerts detail page and then select Go to Asset Profile in the drop-down list.
Host details
The Host Details pane on the left side of the page shows the risk score, status, and source of the host. The Host details pane for Endpoint Security (HX) hosts also includes the containment status, device ID, and agent information.
Any related assets, such as users who logged in to this device, and their risk scores are also displayed. You can click the related asset to open the User Details page for that user.
The alerts list on the right side of the page contains the alerts related to the host. For details about working with the table, see Viewing the alerts page.
User details
The User Details pane on the left side of the page shows the risk score, status, and source of the user. The User Details pane for an Endpoint Security (HX) agent also shows the agent OS. Any related assets, such as devices the user logged in to, and their risk scores are also displayed. You can click the related asset to open the Host Details page for that device.
If the user has a profile in Microsoft Azure Active Directory and Azure AD is integrated with Helix Enterprise, user details from Azure AD are included. Some key profiles (CEO, VP, and so on) are tagged as VIP profiles and are displayed in gold with a crown icon throughout the Helix Enterprise Web UI for instant visibility.
The alerts list on the right side of the page contains the alerts related to the user. For details about working with the table, see Viewing the alerts page.