> For the complete documentation index, see [llms.txt](https://docs.cybaops.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cybaops.com/modules/reports-and-exports/asset-export.md).

# Asset Export

The Asset Manager acts as the single source of truth for all organisational assets, combining information from agents, cloud integrations, RMM tools, vulnerability scanners and identity platforms into a single normalised record. \
\
The Asset Export report allows you to extract a filtered list of assets for auditing, reporting, compliance activities, licence reviews, onboarding exercises and asset inventory management.

### <mark style="color:$primary;">Asset Export</mark>&#x20;

The Asset Export report generates a downloadable inventory of assets based on the filters selected at the time of export.

The report includes asset information such as:

* Asset name
* Asset type
* Operating system and version
* Asset status
* Data source(s)
* Last seen date
* IP addresses (where available)
* Primary user (where available)
* Coverage and security information
* Associated platform metadata
* Asset posture information
* Additional source-specific attributes

The exact fields included may vary depending on the asset type and connected data source.

***

### <mark style="color:$primary;">Report Fields</mark>

#### Report Type

Determines the style of report to generate, this guides covers the Export report.

#### Export

Generates a downloadable file CSV file containing raw asset data that can be used for, asset audits, compliance reviews and data analysis.

The exrport includes all assets currently stored within the Asset Manager regardless of how they were added, including:

* Workstations
* Servers
* Users
* Mobile devices
* IP Addresses
* Websites
* Applications
* Cloud resources
* Custom asset types
* Any other asset category configured within the platform

The export reflects the normalised asset record shown within Asset Manager.&#x20;

***

### <mark style="color:$primary;">Asset Export Configuration Options</mark>

When selecting an export of asset data, other options are configurable to ensure you are exporting the data you need.&#x20;

<figure><picture><source srcset="/files/09Z5ruWnyIlZ70pAEheV" media="(prefers-color-scheme: dark)"><img src="/files/nIMMivhK25xUzZayctsW" alt=""></picture><figcaption></figcaption></figure>

#### Source

Filters assets by where their information originated from.

The Asset Manager supports multiple asset sources and can merge information from several providers into a single asset record.

#### Common Sources

Examples may include:

* Agent
* Manual
* CybaOps
* Entra
* Qualys

The filter is dynamic for all the current sources in the Asset Manager. For example, if you do not have Qualys available as an asset source, then your will not have an asset that is pulling data from Qualys.&#x20;

#### What the Filter Does

Selecting a source returns assets that contain information from that source.

For example:

**Qualys**

* Returns assets discovered or enriched through Qualys.

**CybaAgent**

* Returns assets reporting through the CybaAgent.

**Microsoft Entra**

* Returns assets synchronised from Microsoft Entra ID.

The export does not display which source supplied each individual asset record. However, only assets matching the selected source filters will be included in the exported report.

***

### Type

**Field:** Type

Filters assets by asset category.

The type determines what kind of asset is being managed within the platform.

#### Examples

* Workstation
* Server
* User
* Mobile Device
* IP Address
* Web Application
* Database
* Network Device
* Document
* Cloud Resource
* Custom Asset Types

Selecting a type limits the export to that specific asset category only.

#### Example

Selecting:

**Server**

Returns only server assets and excludes workstations, users, applications and other asset types.

***

### Platform

**Field:** Platform

Filters assets by operating platform or technology stack.

This filter is commonly used when organisations need to identify assets running a specific operating system or platform.

#### Example Values

* Windows
* Windows Server
* macOS
* Linux
* iOS
* Android
* Azure
* AWS
* Cloud Services

The values available will depend on the assets present within your environment and the information provided by connected data sources.

#### Example

Selecting:

**Windows**

Returns all assets identified as Windows-based systems.

***

### Status

**Field:** Status

Filters assets based on their current operational state.

Status provides a way to distinguish active assets from assets that are no longer in use.

#### Common Status Values

**Active**

The asset is currently in use and remains part of the operational environment.

Examples:

* User actively using a workstation.
* Production server currently running.
* Website currently live.

**Inactive**

The asset exists in the register but is no longer being used.

Examples:

* Decommissioned laptop.
* Retired server.
* Archived application.

Status is often used during:

* Asset lifecycle reviews
* Device refresh projects
* Licence optimisation exercises
* Security scope validation&#x20;

**Unknown**

The state of the asset is currently unknown

Example:

* The status wasn't provided at the point of data ingestion from either a manual upload or Qualys syncronisation.

***

### Last Seen

**Field:** Last Seen

Filters assets based on the most recent date the platform received information about them.

This helps identify active, stale, and potentially unmanaged assets.

#### Available Options

**Within 24 Hours**

Assets reporting recently.

Typical use:

* Operational monitoring
* Incident investigations

**Within 7 Days**

Assets seen during the last week.

Typical use:

* Weekly reviews
* Environment validation

**Within 30 Days**

Assets that have reported within the last month.

Typical use:

* Standard inventory reporting
* Security reviews

**Over 30 Days**

Assets that have not reported recently and may require investigation.

Typical use:

* Asset clean-up activities
* Identifying stale records

### <mark style="color:$primary;">Understanding Last Seen Values</mark>

The **Last Seen** filter uses the asset's consolidated **Last Seen** value, which is calculated from the asset data available within the Asset Manager. This value is not always the same as the last time a connected source performed a scan.

As a result, some assets may show **"Not Available"** for Last Seen, even though the source providing the data has successfully scanned or updated information recently.

#### Example

A domain may be imported from an external source such as a vulnerability scanner or cloud integration. The source itself may have run a scan within the last 24 hours, but if the asset does not provide a valid Last Seen timestamp, the asset's Last Seen value will remain **Not Available**.

In this scenario:

* The source has updated successfully.
* The asset exists within the Asset Manager.
* The asset's Last Seen value is not populated.
* The asset will not match Last Seen filters such as **Within 24 Hours**, **Within 7 Days**, or **Within 30 Days**.

#### Impact on Reports

When a Last Seen filter is selected during an export, only assets with a Last Seen value that falls within the selected timeframe are included in the report.

Assets with a Last Seen value of **Not Available** are excluded from time-based Last Seen exports, even if one or more of their connected sources have been updated recently.

#### Best Practice

If you are looking for a complete inventory of assets from a particular source, it is recommended that you:

* Use the **Source** filter to identify assets from that integration.
* Leave the **Last Seen** filter set to **All** unless you specifically want to identify assets with recent activity.
* Review the asset's **Sources** tab if you need to confirm when a particular integration last provided data.

This distinction helps ensure that reporting accurately reflects asset activity, whilst still allowing source update information to be reviewed separately where available.

***

### <mark style="color:$primary;">Example Use Cases</mark>

**Agent Deployment Review**

Filter:

* Source = CybaAgent
* Status = Active
* Last Seen = Within 7 Days

Output:

Assets that are actively communicating through the CybaAgent.

***

**Stale Asset Review**

Filter:

* Last Seen = Over 30 Days

Output:

Assets that may be decommissioned, disconnected, or no longer providing data.

***

**Operating System Inventory**

Filter:

* Platform = Windows

Output:

A complete inventory of all Windows-based assets within the Asset Register.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cybaops.com/modules/reports-and-exports/asset-export.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
