Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass 6.7 Insight Inventory Explanation

This thread has been viewed 3 times
  • 1.  ClearPass 6.7 Insight Inventory Explanation

    MVP
    Posted May 31, 2018 10:39 AM

    Hey all,

     

    Looking for some clarification on the new "Inventory" menu in Insight in ClearPass 6.7+.

     

    What is required of an endpoint to be listed here? The reason I ask, we have 850,000 endpoints in the database, but only 570,000 show up in the Inventory section in Insight. If I look at the profiler we have 824,000 devices profiled, so not sure why the numbers don't exactly line up.

     

    Thanks.



  • 2.  RE: ClearPass 6.7 Insight Inventory Explanation

    EMPLOYEE
    Posted Mar 31, 2020 05:13 PM

    Hi Michael,

     

    Insight inventory is not a replica of EP database. There are number of ways mac address can be added in EP database. Insight db gets updated by something called netevents.

     

    For example, authentication requests generate netevents and by using that insight db will be updated.

     

    So, authentication request for a particular MAC address = netevent generated for MAC = MAC added in Insight inventory.

     

    Regards,

    Pranav



  • 3.  RE: ClearPass 6.7 Insight Inventory Explanation

    EMPLOYEE
    Posted Mar 31, 2020 06:22 PM

    Hi,

     

    I second Pranav's comment as inventory is not a replication of endpoint/profiler tables. 

     

    The insight >> inventory is a data combination from multiple tables within the insight database and mainly relies on the endpoints table. 

     

    And the insight data retention has no relation with endpoint cleanups. Therefore endpoints can be purged in the Insight database, even when the same endpoints exist in the Endpoint Repository (different database - tipsdb).