Software Secure Workload
Activity Configure

Inventory Profile


 

An inventory profile page is linked from various places. One of the ways to see an inventory profile is to perform a search for inventory, then click an IP address to go to its profile. If you are working in the Scopes and Inventory page, click an IP address in the IP addresses tab, not an IP address in the Workloads tab. (Clicking an IP address in the Workloads tab displays the Workload Profile, not the Inventory Profile.)

The following information is available for the inventory:

Field

Description

Scopes

List of scopes that the inventory belongs to.

Inventory Type

  • Flow Learnt inventory was registered based on the observed flows.

  • Labeled inventory was manually uploaded using the inventory upload utility.

  • Agent inventory was reported by the software agent installed on a host.

  • Tagged inventory was either reported by connectors or external orchestrators.

User Labels

The list of user uploaded attributes for this inventory. See User Labels for more details.

Additional information is available only if both of the following are true:

  1. Inventory has been ingested through a cloud connector.

  2. Segmentation is enabled for the virtual network in which the inventory resides.

    Field

    Description

    Enforcement Health

    The status information of the host software agent. See Agent Health Tab for more details.

    Concrete Policies

    This tab shows Secure Workload concrete enforcement policies applied on the host. See Concrete Policies Tab for more details.

    Security Groups

    The list of security groups and their policies applied to this inventory.

Inventory Profile Information

Field

Description

Experimental Groups

A list of cluster or user-defined inventory filters that are used for policy live analysis.

Enforcement Groups

A list of cluster or user-defined inventory filters that are used for policy enforcement. They can be different from experimental groups depending on the versions of policies being analyzed and/or enforced in the system.


 

The inventory profile details may not be available for an IP address when:

  • The inventory is excluded from collection rules.

  • In a unidirectional flow, the inventory is available only for two minutes, and then it is removed.

  • In a bidirectional flow, the inventory is available for 30 days. If no more flows are observed during these 30 days then the inventory details are removed.