A unique identifier of an asset. An asset ID is generated automatically by Kaspersky Managed Detection and Response before the asset sends telemetry for the first time.
The status reflects the current asset state. For assets in the OK, Warning, or Critical statuses, the application additionally lists the problems (if any) for the last 72 hours.
Mail Threat Protection and Additional Microsoft Office Outlook Extension—See how to enable or configure these components in Kaspersky Endpoint Security for Windows.
Anti-virus databases are outdated by more than 7 days.
These components affect the fullness of sent telemetry. If a component is disabled or missing, Kaspersky Managed Detection and Response does not send the telemetry events related to this component. The installed EPP application may not include all of the listed components.
KSN configuration file is expiring. The application displays the expiration date. Consider updating the KSN configuration file. If you keep working with the current configuration file, the status changes to Critical few days before the expiration date.
The Warning status is applicable for assets with Kaspersky Endpoint Security for Windows 11 or later, Kaspersky Endpoint Security for Linux 11.2 or later, Kaspersky Endpoint Security for Mac 11.2 or later, or Kaspersky Security for Virtualization Light Agent 5.2 or later installed. For assets with the Kaspersky Endpoint Security for Windows in the Endpoint Detection and Response Agent (EDR Agent) configuration, this status is not displayed.
Critical (red)
Possible reasons of the Critical status:
At least one of the following EPP application components on the asset is disabled or not installed:
If any of these components are disabled or missing, Kaspersky Managed Detection and Response stops sending telemetry from the asset. The installed EPP application may not include all of the listed components.
KSN configuration file is expiring soon or is already expired. The application displays the expiration date. Consider updating the KSN configuration file.
No telemetry for more than 7 days (default value). You can change the number of days of absence of telemetry, after which the Offline status is displayed for the asset, in the Settings section. The available range is 2–29 days.
If you see the Offline status for your assets:
Make sure the EPP application components listed with Warning and Critical statuses are installed and enabled on the assets.
Make sure Kaspersky Managed Detection and Response is properly deployed in your infrastructure.
Offline status is not applicable for VDI assets (temporary virtual machines).
Absent (black)
No telemetry for more than 30 days for physical assets or for more than 24 hours for VDI assets (temporary virtual machines).
If you see the Absent status for your assets:
Make sure the EPP application components with Warning and Critical statuses are installed and enabled on the assets.
Make sure Kaspersky Managed Detection and Response is properly deployed in your infrastructure.
You can hide assets with the Absent status in the asset list, in the reports, and in the data received via the API interface.
If you want to change the number of assets shown per page of the list, select the number by clicking the entries per page option at the bottom of the page.
You can select 10, 20, or 50 assets per page.
You can hide assets with the Absent status in the asset list by selecting the check box in the Settings.
If you want to navigate the list of assets, select the page from below the list. You can use the Previous and Next options to switch between adjacent pages.
By default, the asset list contains assets that were seen in Console in the last 30 days.
To change this period:
Click the funnel icon above the list.
On the Filter panel on the right, select the period in the Last seen field.
Click Save.
You can search through the assets by clicking the magnifying glass icon located next to the funnel icon above the asset list.