Searching asset profiles

You can configure search parameters to display only the asset profiles you want to investigate from the Asset page on the Assets tab.

About this task

When you access the Assets tab, the Asset page is displayed populated with all discovered assets in your network. To refine this list, you can configure search parameters to display only the asset profiles you want to investigate.

From the Asset Search page, you can manage Asset Search Groups. For more information about Asset Search Groups. See Asset search groups.

The search feature will allow you to search host profiles, assets, and identity information. Identity information provides more detail about log sources on your network, including DNS information, user logins, and MAC addresses.

Using the asset search feature, you can search for assets by external data references to determine whether known vulnerabilities exist in your deployment.

For example:

You receive a notification that CVE ID: CVE-2010-000 is being actively used in the field. To verify whether any hosts in your deployment are vulnerable to this exploit, you can select Vulnerability External Reference from the list of search parameters, select CVE, and then type the

2010-000

To view a list of all hosts that are vulnerable to that specific CVE ID.

Note: For more information about OSVDB, see http://osvdb.org/ . For more information about NVDB, see http://nvd.nist.gov/ .

Procedure

  1. Click the Assets tab.
  2. On the navigation menu, click Asset Profiles.
  3. On the toolbar, click Search > New Search.
  4. Choose one of the following options:
    • To load a previously saved search, go to Step 5.
    • To create a new search, go to Step 6.
  5. Select a previously saved search:
    1. Choose one of the following options:
      • Optional. From the Group list box, select the asset search group that you want to display in the Available Saved Searches list.
      • From the Available Saved Searches list, select the saved search that you want to load.
      • In the Type Saved Search or Select from List field, type the name of the search you want to load.
    2. Click Load .
  6. In the Search Parameters pane, define your search criteria:
    1. From the first list box, select the asset parameter that you want to search for. For example, Hostname, Vulnerability Risk Classification, or Technical Owner.
    2. From the second list box, select the modifier that you want to use for the search.
    3. In the entry field, type specific information that is related to your search parameter.
    4. Click Add Filter.
    5. Repeat these steps for each filter that you want to add to the search criteria.
  7. Click Search.

Results

You can save your asset search criteria. See Saving asset search criteria.