Skip to content

Asset management

Assets are hosts, users, and services that LogMan.io learns from your event stream. The platform tracks when each entity was first and last seen, whether it is still active, and how detection activity affects its risk score. Use Assets to maintain an inventory, spot inactive or risky entities, and jump into Discover for deeper investigation.

This page covers the Assets screens in the web app: inventory, detail, stale alerts, and typical investigation steps. For how activity events are produced in Parsec (identity mapping, skip, Kafka topics), see Asset management and activity stream.

Who can do this?

Opening the Assets module requires lmio:asset:access. Editing tags, alerts, or deleting assets requires lmio:asset:edit. Changing alternate names or risk score weight requires lmio:lookup:edit. Opening Discover from an asset requires bitswan:discover:access.


Open the Assets module

In the main menu, select Assets (box icon). You can browse:

Screen What it shows
All assets Full inventory
Hosts Computers and servers
Users User accounts
Services Service principals
Asset detail One entity with charts and settings

Assets are created automatically when matching events arrive. You do not create them manually in the UI.


What you see on the list

The asset table includes:

Column Meaning
Id Principal name (hostname, username, service id). Click to open detail.
Alert badge Whether a stale after alert is configured (see below)
Last activity Most recent event for this asset
Risk score Current entity risk from detections (time decayed)
Activity Green icon = active; red = inactive (see Active vs inactive)

Use the search box to filter by id or type. Use Activity filter for Active or Inactive only. Sort by id, last activity, risk score, or activity status.

Download all exports the current filtered list to CSV.


Asset detail: charts and sidebar

Click an asset Id to open its detail page.

  • Type: host, user, or service
  • First / last activity: when LogMan.io first and last saw this entity
  • Average risk score: decayed score from detection events
  • Activity status: active or inactive
  • Alternate names: aliases (hostname, IP, username, email) for hosts and users
  • Stale after (alert): inactivity threshold before an alert is raised
  • Risk score weight: multiplier that influences detection scoring for this principal
  • Tags: labels you assign for filtering and reporting

Charts

  • Activity: event volume over time (by dataset when available)
  • Risk score: peak detection risk per time bucket
  • Related principals: hosts show related users; users show related hosts

Use the date range picker and optional LARK filter, then Fetch data to refresh charts. Default range is the last three days.

Open in Discover

Click Open in Discover to search raw events for this principal in the selected time range. This is the main path from an asset to a full investigation.


Risk score vs activity

These measure different things:

Concept Source Question it answers
Activity Activity event lane Is this entity still sending logs?
Risk score Detection events (complex lane) How much suspicious activity involved this entity recently?

A host can be active (still logging) with a low risk score, or inactive with a high score left over from past detections until the score decays.

The line chart on the detail page shows when detections spiked. An empty bucket means no qualifying detection events in that interval.


Active vs inactive

The green/red Activity icon (and the Active / Inactive list filter) answers: Has this entity been seen recently enough?

active  ⇔  (now − last activity) ≤ threshold
Stale after (alert) Threshold for the badge
Set (for example 1d, 3d) Same window as the alert
Cleared / off 7 days

No last activity → inactive.

Badge vs Alert Management

Turning off Stale after (alert) does not mean the asset stays green forever. After 7 days without activity it still shows as inactive. What you stop is the Asset inactive ticket in Alert Management; that channel only runs while a threshold is set.

Technical detail (API field active): LogMan.io Assets - Active vs inactive.


Stale asset alerts

You can ask LogMan.io to alert when an asset stops sending events.

  1. On asset detail (or via Bulk actions on the list), set Stale after (alert): for example 1d or 3d
  2. Save

If no activity occurs within that window, Alert Management receives an Asset inactive signal. The open signal includes how long the asset has been quiet (event.duration by default, shown as a human-readable duration). When activity resumes, the alert closes automatically.

To stop monitoring, clear the threshold (X button on detail, or Clear alerts in bulk actions). If an Asset inactive ticket was already open for that asset, clearing (or raising the threshold so last activity falls inside the new window) sends a recovery signal that can close the ticket in Alert Management (description: asset is active again). Deleting the asset (or merging it away) also closes an open ticket, with description that the asset was deleted — not that it became active again.

Clearing the threshold does not freeze the Activity badge: without alert_after, inactive still means more than 7 days since last activity (see Active vs inactive).

Default for new assets

New assets get a default stale alert from server configuration: 3 days for hosts and services, 7 days for users. Short windows such as 2h often open and close tickets repeatedly on hosts that are healthy but quiet for part of the day. After a ticket recovers, another open is held off for about a day (stale_alert_reopen_cooldown_sec). You can change or clear the threshold per asset.


Notifications when a new asset appears

Administrators can enable asab-iris notifications (email, Slack, SMS, or push) when LogMan.io discovers a new host, user, or service from the activity stream.

Mode What you receive
Instant One message when the asset is first created
Scheduled A periodic summary of assets created in the last interval (default often 1 hour)

These are not the same as stale asset alerts (those go to Alert Management when an asset goes quiet). New-asset notifications only fire on first discovery, not on every later last_seen update.

Setup is Library + service config (channel, templates, optional filters). Ask your administrator, or see Assets configuration.


Filtering noise from the inventory

Some identities should never become assets (for example Windows SYSTEM, or throwaway hostnames). Administrators can filter them in two places:

Layer Where What it filters
Assets Library /Assets/Skip/settings.yaml Host and user titles via names / prefixes / suffixes / contains (case-insensitive); drops those assets on activity and complex
Parsec event lane parsec.asset.skip Host and user via exact / prefixes / suffixes / contains / ip; drops them from the activity Kafka stream

Use Library /Assets/Skip/ (prefixes, min_hyphens, ip, …) in the inventory. Details: Assets configuration and Parsec asset management.


Tags and alternate names

Tags

Tags are free form labels you assign on an asset (for example label=prod, team=soc, or critical). They live in a sidecar collection next to the asset document and appear on the detail page. Add or remove tags if you have edit permission.

Tags and events in Discover

To investigate all events for every host (or user / service) that shares a tag, you do not paste host names by hand.

In Discover / Chart

Pick a data source that declares asset_tag in the Library (for example Events (hosts label=prod) from Common Library). Chart asks Assets for matching principals and limits the query to those host.id (and optionally user.id / service.id) values. See Events for assets by tag.

Via the Assets API

  • List tagged assets: GET /api/lmio-assets/{tenant}/asset?atag=label:prod
  • Build a Discover filter string: GET /api/lmio-assets/{tenant}/asset/events-filter?atag=label:prod&akind=host

The events filter response includes data.filter (for example host.id:(web01, web02)). You can paste that into Discover, or rely on a Chart data source so the filter is applied automatically.

Requires lmio:asset:access. Matching is case insensitive.

Alternate names

Hosts and users can have alternate names: extra hostnames, IP addresses, MAC addresses, usernames, or emails that should map to the same asset. This helps when the same machine or person appears under different identifiers in logs.

Editing alternate names requires lookup edit permission because values are stored in watcher lookups.

To keep directory scale username → user.id mappings current from Active Directory, use an LDAP feed into usernames2userid. See LDAP / AD user identity feed.

Risk score weight

Risk score weight (0 to 100) adjusts how strongly detections affect this asset's score. Use it for known good systems (lower weight) or high value targets (higher weight). Requires lookup edit permission.


Bulk actions on the list

  1. Open All assets (or Hosts, Users, Services)
  2. Click Bulk actions (grid icon)
  3. Select rows with checkboxes, or select all on the page
  4. In the side panel:
  5. Set or clear Stale after (alert) for the selection
  6. Delete selected assets (confirmation required)

Deletion removes the asset record. It will be recreated if matching events arrive again.


Typical analyst workflows

Find risky or quiet assets

  1. Open Assets → All
  2. Sort by Risk score descending, or filter Inactive
  3. Open interesting rows to review charts and last activity

Investigate one host or user

  1. Open asset detail
  2. Set the date range to cover the incident
  3. Check the risk score chart for detection spikes
  4. Check the activity chart for logging gaps
  5. Click Open in Discover to read individual events
  6. For hosts or users, review related principals for lateral context

Monitor critical servers

  1. Open the host asset
  2. Set Stale after (alert) to a sensible window (for example 1d or 3d)
  3. Add tags such as critical
  4. Respond to Asset inactive alerts in Alert Management

Clean up after a rename

When the same host or user appears as two assets (for example short name and FQDN):

  1. Open the asset you want to keep (the canonical Id)
  2. Under Alternate names, add the other identifier
  3. If that name already exists as a separate asset, Assets can remove the duplicate when you confirm; events that still use the old name then resolve to the kept asset through the lookup

How assets relate to detections

flowchart TB
    EV[Incoming events]
    ACT[Activity lane]
    CMP[Complex lane / detections]
    AST[(Assets)]
    UI[Assets screens]
    DIS[Discover]
    ALM[Alert Management]

    EV --> ACT
    EV --> CMP
    ACT --> AST
    CMP --> AST
    AST --> UI
    UI --> DIS
    AST --> ALM
  • Activity updates first seen, last seen, and active or inactive status (see Asset management and activity stream)
  • Detections on the complex lane feed the risk score
  • Stale alerts link assets to Alert Management, not to the Detections screen
  • New-asset notifications (optional) go through asab-iris, not Alert Management

Permissions summary

Task Permission
View Assets lmio:asset:access
Edit tags, stale alert, delete lmio:asset:edit
Edit alternate names, risk weight lmio:lookup:edit
Open in Discover bitswan:discover:access
View underlying lookups lmio:lookup:access
Handle stale asset alerts lmio:alert:access (Alert Management)