Mark assets as inactive

You can mark assets that are discovered through Aurora Vulnerability Management(Aurora VM) scans as inactive until they are rediscovered in a subsequent scan.

Alternatively, you can delete an asset entirely. For more information, see Delete assets.

When you mark an asset as inactive:
  • The Asset State value changes to Inactive and the status of all risks associated with the asset change to Resolved.
  • The asset remains in scan schedules unless you edit each schedule to remove it.
  • If the asset is:
    • Rediscovered in a subsequent scan by any source — The asset reappears and the status of all associated risks will be change from Resolved to Unresolved.

    • Not rediscovered — The asset is removed after 120 days and all associated risks are automatically deleted 120–150 days after their status changes to Resolved.

      The asset can appear again if an Arctic Wolf Agent, 内部脆弱性評価(IVA) scanner, or other scan source receives a new signal from it.
      Note: If Arctic Wolf® receives an Active Directory(AD) or DHCP log for the asset, the asset will reappear unless both of these conditions are true: the log shows that the asset is disabled in AD and no one has signed in to the device in the past four months.

      However, the asset will not appear again if you uninstall the associated Agent and configure other scan sources to exclude the asset from scanning. For more information, see Delete assets.

  1. Arctic Wolf Unified Portal にサインインします。
  2. In the navigation menu, click Data Collection > Assets.
  3. For each asset that you want to mark as inactive, select the checkbox.
  4. Click Mark as Inactive.
  5. Click Mark as Inactive.