Mark assets as inactive

You can mark assets that are discovered through Aurora Vulnerability Management (Aurora VM) scans as inactive until they are rediscovered in a subsequent scan.

To completely delete an asset, see Delete assets.

When you mark an asset as inactive:
  • The asset Asset State changes to Inactive, and then the asset is removed after 120 days.
  • The asset remains in schedules until you edit the schedule.
  • The Status of any risks associated with the asset change to Resolved, and then those risks are removed after 120–150 days.
  • Agent and Internal Vulnerability Assessment (IVA) scanners remain visible.
  • The asset can appear again if an Agent or IVA scanner receives a new signal from it.
    Note: If Arctic Wolf receives any Active Directory (AD) log for the asset, the asset will reappear, even if the log shows that the asset is disabled in AD. However, if the device is disabled and no one signed into the device in the past four months, it will not reappear.
  • The asset will not appear again if you delete the associated Agent or modify an associated IVA scan.
Note: When you uninstall Arctic Wolf Agent from an asset, one of these actions occurs:
  • If the asset had only Agent as a Source — The Asset State automatically changes to Inactive and the Status of all associated risks changes to Resolved.

  • If the asset had more than one Source, for example, Agent, IVA, and DHCPAgent is no longer listed as a Source on the Asset page, the Asset State and risk Status do not change, and the State of all risks associated with the Agent remains unchanged. In this situation, you must manually set the State of any risks associated with that Agent to Accepted or Mitigated so that the risks do not impact your Risk Exposure Score.

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Assets.
  3. For each asset that you want to delete, select the checkbox.
  4. Click Mark as Inactive.
  5. Click Mark as Inactive.