Rapid7InsightAgent vs Rapid7IVMAsset

Hello,

I was trying to query for all offline agents via api based on this “WHERE ('Rapid7InsightAgent' IN a.sources)” clause. The actual agents listing in the command platform correctly lists an asset that has an offline agent but because that asset does not have Rapid7InsightAgent as a source (only source listed is Rapid7IVMAsset), it did not return in my query. I tried to add an OR to the query but I found that it brought too much extra noise. Is there any way I can manually edit this asset’s source listing to include Rapid7InsightAgent? Any ideas for why this asset which does have an insight agent installed does not have Rapid7InsightAgent listed as one of its sources?

Thank you

Hello, JLee. At this point, you cannot edit any values of the properties of records in the ASM system. At best, you can put a tag on that asset and use the presence of the tag in your query.

Alternatively, we will soon be rolling out the “Software Inventory” capability. With this feature, you will be able to query for Assets, including those with “Rapid7IVMAsset” in sources, but not necessarily “Rapid7InsightAgent” in source, that have the insight agent software installed.

Thank you for the reply. I will try out the tag solution and see how that goes. Do you have any ideas regarding why an asset that has an insight agent installed does not have Rapid7InsightAgent listed as one of its sources? Is it possible to have an asset rediscovered/scanned in order to have its source list correctly reflect this?

The import process from the Rapid7 Command platform into ASM/Surface Command generally does not pick up offline Insight Agents. And as you probably know, an Insight Agent could be offline long term, or temporarily for various reasons. Typically, this count should be small, and vary from day to day.

1 Like