LogMan.io Assets¶
TeskaLabs LogMan.io Assets (lmio-assets) is a microservice that maintains the asset inventory per tenant: hosts, users, and services identified by principal fields from the tenant schema. It exposes the inventory over HTTP (default tcp/8965) and keeps documents in MongoDB.
The service consumes two Kafka streams per tenant:
| Stream | Source | Effect on assets |
|---|---|---|
| Activity | Parsec activity topic (events.<tenant>.activity by default) |
Updates first_seen / last_seen, optional tags from activity payloads |
| Complex | Correlator output on the tenant complex event lane (events.<tenant>.complex by default) |
Updates entity risk score with a time decayed model (see Entity risk score) |
Activity and complex processing share the same consumer group (lmio_assets by default). Topic names and schema field mappings are rebuilt when the Library changes under /EventLanes/ or /Schemas/.
Asset document¶
Each asset row uses Mongo _id {tenant}:{kind}:{value} where kind is host, user, or service.
| Field | Meaning |
|---|---|
tenant, kind, value |
Identity (mirrors _id parts) |
first_seen, last_seen |
Unix ms from the schema principal datetime field on activity events |
risk_score |
Integer entity risk score (decayed at read time; see Risk score decay) |
alert_after |
Optional stale alert threshold in seconds (HTTP API); when ≥ 1 it is also the window for active |
active |
Computed (not stored): true when now − last_seen ≤ threshold (see below) |
User defined labels live in a separate tags collection (asset_tags by default) with the same _id as the asset.
Tags and events filter¶
Tags are free form key/value pairs on the sidecar (for example label → prod). Use them to group assets and to scope Discover or Chart to those principals.
| Goal | Endpoint |
|---|---|
| List assets with a tag | GET /{tenant}/asset?atag=field:value |
| CSV export of tagged assets | GET /{tenant}/asset/export?atag=field:value |
| Discover / Chart filter for their events | GET /{tenant}/asset/events-filter?atag=field:value |
- Preferred query param:
atag=field:value(exampleatag=label:prod). A bare value uses fieldtags. - Optional
akind/kindnarrows tohost,user, and/orservice. - Matching is case insensitive in application code (not Mongo
$regex). events-filterdoes not query Elasticsearch. It returnsdata.filterin Discover filter language (for examplehost.id:(a, b) OR user.id:(…)). Chart can apply this automatically when an Elasticsearch data source setsspecification.asset_tag. See Events for assets by tag.
Requires lmio:asset:access.
Active vs inactive¶
List, detail, and CSV export use the same rule as the green/red Activity icon in the web UI:
active ⇔ (now_ms − last_seen_ms) ≤ threshold_sec × 1000
alert_after on the document |
Threshold |
|---|---|
| Integer ≥ 1 | That value (seconds), same window as Stale after (alert) |
Missing, null, or < 1 (alert cleared / off) |
7 days (604800 s) |
Missing or invalid last_seen → inactive (active: false).
This badge is independent of nonactive / nonactive_since (those mark that a stale up signal was already sent to Alert Management). Clearing Stale after (alert) stops tickets, but the asset can still show as inactive after 7 days without activity.
For analysts: Asset management - Active vs inactive.
Stale asset signals¶
When alert_after ≥ 1 and the asset stays quiet longer than that window, StaleAssetAlertService emits an Alert Management signal (direction: up). On up, signal attributes include seconds without activity in the schema field marked like this (sibling of alert: on the field):
event.duration:
type: fp64
format: humanize
alert:
grouping:
method: log10
description: Groups large values into magnitude buckets
asset:
inactive_seconds: true
If no field is marked, the duration attribute is omitted from the signal. Recovery uses direction: down (same title/group; no duration attribute).
For analysts: Asset management - Stale asset alerts.
Related documentation¶
- Configuration: model, ASAB
[assets]settings, Library/Assets/Skip/, new asset notifications - Entity risk score: what analysts see in Assets, decay behavior, optional risk score weight
- Asset management (Analyst Manual): inventory UI, tags, stale alerts, notifications
- Chart data sources: events by asset tag: Discover limited to tagged hosts / users / services
- Parsec asset management: activity stream production and
parsec.asset.skip - Risk scoring in Correlator: per detection
event.risk_scoreon complex events - Kafka topics:
events.<tenant>.activity - Network ports:
lmio-assetson tcp/8965