How to Use the Endpoint Comparison Matrix

How to Use the Endpoint Comparison Matrix

Overview

The comparison matrix shows which of your connected tools "see" each asset, so you can spot coverage gaps — for example a device that Active Directory knows about but your EDR does not.

In the product it is called the Asset Coverage Matrix, and it is a tab inside Asset Inventory.


Prerequisites

  • defence:dashboard:view — Asset Inventory does not render without it
  • At least two integrations connected and synced, so there is more than one source column to compare

Opening the matrix

Navigation: Sidebar → AssetsAsset InventoryAsset Coverage Matrix

  1. In the sidebar, expand Assets and click Asset Inventory.
  2. Select the Asset Coverage Matrix tab. The other two tabs are Assets Listing and User Access Coverage.

Choosing how assets are matched

Different tools identify the same machine differently, so the matrix offers three ways to line them up. Use the Filter: dropdown at the top left:

OptionRows are keyed on
Asset Coverage Matrix by HostHostname
Asset Coverage Matrix by IPIP address
Asset Coverage Matrix by DomainDomain

The view opens on Asset Coverage Matrix by Host. Next to the dropdown, a Total assets: counter shows how many rows the current matrix holds.


How to read it

Each row is one asset. The left-hand columns describe it; the remaining columns are one per connected source.

By Host

ColumnWhat it shows
HostNameThe hostname
Asset CriticalityCriticality classification
Machine TypeMachine type
Internal IPsInternal addresses
External IPsExternal addresses
OS NameOperating system
Business UnitOwning business unit

By IP replaces HostName with IP Address and Internal IPs with Hostnames. By Domain replaces HostName with Domain.

After those, one column per source. In each source cell:

  • — that source reports this asset
  • ! — that source does not report it, which is your coverage gap

A dash (-) in a descriptive column means the value is not known.


Narrowing the view

  • Search across the whole matrix from the search box.
  • Filter a source column to Exist or Not-exist to isolate the assets one tool is missing.
  • Sort by clicking a column header.
  • Page through the results with the pager below the table.
  • Export the current matrix using the table's export control.

The fastest way to find a gap: set the source column for your critical tool to Not-exist.


What to do with it

  • Find assets missing from a critical tool — EDR, patch management — and onboard them.
  • Validate a newly connected integration by checking it reports the assets you expect.
  • Switch the matching key when an asset looks absent everywhere; the tools may simply key it differently.

Troubleshooting

Symptom: The tab shows "No data available". → The matrix has not been populated yet. Confirm your integrations have completed a sync; newly connected sources take time to appear.

Symptom: Only one source column appears. → The matrix compares across sources. Connect at least two integrations and let them sync.

Symptom: An asset shows ! in every source column. → Switch the matching key with the Filter: dropdown. A machine matched by hostname may be present under its IP, or the other way round.

Symptom: Asset Inventory shows an Unauthorized screen or does not load. → You are missing defence:dashboard:view. Ask your administrator.

Symptom: The sidebar entry is greyed out. → Until your organisation has ingested data, only Integrations, Management, Manual Ingestion and Settings are usable. Connect an integration first.

Symptom: I am looking for a tab called "Endpoint Comparison Matrix". → It is labelled Asset Coverage Matrix in the product.

Related: *How to View and Manage Asset Inventory*.


Need more help? Contact support@zeron.one