After you have configured the various sources for device profiling, you will be able to view device profiles in the Manager. There are two methods to view device profiles:
Using the Attack Log: In this method, the device profiles are visible in the form of source and destination operating systems. As stated earlier, the Manager receives device profile information from three sources: IPS Sensors, NTBA Appliances, and ePolicy Orchestrator - On-premises. Each of these inputs consists of a confidence level which is compared by the Manager, which then presents the device profile that has the highest confidence. Knowledge of the operating system allows the Manager to ascribe a relevance to each alert. Relevance helps prioritize an alert since certain alerts will only be relevant to certain operating systems; if not applicable to an operating system, such alerts are treated as not relevant. For more information on relevance, refer to the section Alert Relevance.
Using the device-profile script: In this method, you initiate the device-profile script that is bundled with the Manager installable. This script fetches the device profiles of all the hosts that the Manager currently has in its database. The script displays this data in a .csv file.
In the Attack Log, you can only view the source and destination operating systems of the hosts associated with an alert. That is, if a host is not associated with an alert, you cannot view its operating system even if the Manager has this information. If you use the device-profile script, you can view the following details for all the hosts that are currently profiled:
operating system
the device type
the source of the profile - IPS Sensor, NTBA Appliance, or ePolicy Orchestrator - On-premises