Asset Management
Collecting and viewing asset data helps you to identify threats and vulnerabilities. An accurate asset database makes it easier to connect offenses that are triggered in your system to physical or virtual assets in your network.
Asset data
An asset is any network endpoint that sends or receives data across your network infrastructure. For example, notebooks, servers, virtual machines, and handheld devices are all assets. Every asset in the asset database is assigned a unique identifier so that it can be distinguished from other asset records.
Detecting devices is also useful in building a data set of historical information about the asset. Tracking asset information as it changes helps you monitor asset usage across your network.
Asset limits
The asset database has a limited capacity. When the asset limit for your hardware is reached, you cannot create any new assets until sufficient space is available in the database. The following table describes the asset limits for each hardware type:
| Hardware type | Asset Limit for Console only | Asset Limit for Console with Managed Host |
|---|---|---|
| xx05 | 200,000 | 600,000 |
| xx24 | 300,000 | 700,000 |
| xx28 | 500,000 | 1,000,000 |
| xx29 | 500,000 | 1,000,000 |
| xx48 | 500,000 | 1,000,000 |
| Other hardware | 60,000 | 60,000 |
Asset profiles
An asset profile is a collection of all information that IBM QRadar SIEM collected over time about a specific asset. The profile includes information about the services that are running on the asset and any identity information that is known.
- Given name
- NETBios host name
- DNS host name
- IP address
Collecting asset data
Asset profiles are built dynamically from identity information that is passively absorbed from event or flow data, or from data that QRadar actively looks for during a vulnerability scan. You can also import asset data or edit the asset profile manually.