Skip to content

LogMan.io Assets

TeskaLabs LogMan.io Assets (lmio-assets) is a microservice that maintains the asset inventory per tenant: hosts, users, and services identified by principal fields from the tenant schema. It exposes the inventory over HTTP (default tcp/8965) and keeps documents in MongoDB.

The service consumes two Kafka streams per tenant:

Stream Source Effect on assets
Activity Parsec activity topic (events.<tenant>.activity by default) Updates first_seen / last_seen, optional tags from activity payloads
Complex Correlator output on the tenant complex event lane (events.<tenant>.complex by default) Updates entity risk score with a time decayed model (see Entity risk score)

Activity and complex processing share the same consumer group (lmio_assets by default). Topic names and schema field mappings are rebuilt when the Library changes under /EventLanes/ or /Schemas/.

Asset document

Each asset row uses Mongo _id {tenant}:{kind}:{value} where kind is host, user, or service.

Field Meaning
tenant, kind, value Identity (mirrors _id parts)
first_seen, last_seen Unix ms from the schema principal datetime field on activity events
risk_score Integer entity risk score (decayed at read time; see Risk score decay)
alert_after Optional stale alert threshold in seconds (HTTP API); when ≥ 1 it is also the window for active
active Computed (not stored): true when now − last_seen ≤ threshold (see below)

User defined labels live in a separate tags collection (asset_tags by default) with the same _id as the asset.

Tags and events filter

Tags are free form key/value pairs on the sidecar (for example label → prod). Use them to group assets and to scope Discover or Chart to those principals.

Goal Endpoint
List assets with a tag GET /{tenant}/asset?atag=field:value
CSV export of tagged assets GET /{tenant}/asset/export?atag=field:value
Discover / Chart filter for their events GET /{tenant}/asset/events-filter?atag=field:value
  • Preferred query param: atag=field:value (example atag=label:prod). A bare value uses field tags.
  • Optional akind / kind narrows to host, user, and/or service.
  • Matching is case insensitive in application code (not Mongo $regex).
  • events-filter does not query Elasticsearch. It returns data.filter in Discover filter language (for example host.id:(a, b) OR user.id:(…)). Chart can apply this automatically when an Elasticsearch data source sets specification.asset_tag. See Events for assets by tag.

Requires lmio:asset:access.

Active vs inactive

List, detail, and CSV export use the same rule as the green/red Activity icon in the web UI:

active  ⇔  (now_ms − last_seen_ms) ≤ threshold_sec × 1000
alert_after on the document Threshold
Integer ≥ 1 That value (seconds), same window as Stale after (alert)
Missing, null, or < 1 (alert cleared / off) 7 days (604800 s)

Missing or invalid last_seen → inactive (active: false).

This badge is independent of nonactive / nonactive_since (those mark that a stale up signal was already sent to Alert Management). Clearing Stale after (alert) stops tickets, but the asset can still show as inactive after 7 days without activity.

For analysts: Asset management - Active vs inactive.

Stale asset signals

When alert_after ≥ 1 and the asset stays quiet longer than that window, StaleAssetAlertService emits an Alert Management signal (direction: up). On up, signal attributes include seconds without activity in the schema field marked like this (sibling of alert: on the field):

event.duration:
  type: fp64
  format: humanize
  alert:
    grouping:
      method: log10
      description: Groups large values into magnitude buckets
  asset:
    inactive_seconds: true

If no field is marked, the duration attribute is omitted from the signal. Recovery uses direction: down (same title/group; no duration attribute).

For analysts: Asset management - Stale asset alerts.