---
title: "Asset Discovery for Infoblox Threat Defense"
canonical: "https://docs.infoblox.com/space/UniversalAssetInsights/1624113197/Asset%20Discovery%20for%20Infoblox%20Threat%20Defense"
format: markdown
---
The **Threat Defense Business Cloud** or **Threat Defense Advanced** license provides the following asset discovery on your network.

## Passive Discovery

Infoblox Threat Defense enables passive discovery by default. The Infoblox Portal automatically creates a passive discovery job for Threat Defense. 

To view the default discovery job:

1. Log in to the Infoblox Portal.
2. Go to **Integrations** > **Discovery**.
3. On the **Discovery** page, the default passive discovery job is displayed in the table.
4. Select the default passive discovery job and click **Edit**. The following dialog appears, but you cannot modify any information. This indicates Threat Defense has enabled the passive discovery job by default.
  Under **Type**, the following discovery sources are enabled by default for passive discovery:
  - **DHCP NIOS-X**: This data source uses DHCP logs from your NIOS-X servers. Data is discovered by default if you configure NIOS-X servers in your network.
  - **DHCP NIOS**: This data source uses DHCP logs via Cloud Data Connector, if configured. Infoblox recommends configuring IPMeta on your Cloud Data Connector to collect discovered data.
  - **Infoblox Endpoint**: This data source uses data from Infoblox-managed endpoints.

> ⚠️ Cloud Data Connector does not forward discovery service logs to the configured destination.

## NIOS Grid Connector

Define what NIOS Grid name is and identify the unique ID. Put a screenshot here.

You can configure NIOS Grid Connector to increase the number of on-prem assets Threat Defense protects.  

If you have a NIOS Grid Master that has not been connected to the Infoblox Portal, complete the following steps to configure a NIOS Grid Connector discovery:

1. Enable network discovery on the NIOS Grid before creating a discovery job in Universal DDI. For more information, see *[IP Discovery and vDiscovery](https://docs.infoblox.com/space/nios90/280267936/IP+Discovery+and+vDiscovery)*.
2. Establish a connection between the NIOS Grid and Infoblox Portal. For information, see *[Establishing Connection between NIOS Grid and Infoblox Portal](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186648247)*. After establishing the connection, the NIOS Grid Connector discovery job will be automatically created.
3. Enable the NIOS Grid Connector service. For information, see *[Enabling the NIOS Grid Connector Service](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186876116)*.

If your NIOS Grid Master is already connected to the Infoblox Portal and the NIOS Grid Connector service is enabled, the NIOS Grid Connector discovery job will be configured automatically. If the master is connected, description of the job will be "Default NIOS Job Configuration for Grid Master/Grid Master Candidate" Complete the following to configure NIOS Grid Connector discovery:

1. Enable network discovery on the NIOS Grid before creating a discovery job in Universal DDI. For more information, see *[IP Discovery and vDiscovery](https://docs.infoblox.com/space/nios90/280267936/IP+Discovery+and+vDiscovery)*.
2. Enable the NIOS Grid Connector service. For information, see *[Enabling the NIOS Grid Connector Service](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186876116)*.

## NIOS-X Discovery

To discover on-prem assets through NIOS-X servers, Infoblox recommends configuring asset discovery via NIOS-X Discovery.

To configure discovery via NIOS-X Discovery, follow the instructions in *[NIOS-X Discovery](https://infoblox-docs.atlassian.net/wiki/spaces/UniversalAssetInsights/pages/1624276993)*.

# Other Supported Discovery Sources

This section describes the cloud and third-party discovery sources for the supported Threat Defense license entitlements. 

## Cloud Sources

Infoblox Threat Defense supports asset discovery from leading cloud providers. The discovered data enhances the information in the existing threats on the **Security Workspace**.

- **Amazon Web Services **(AWS). For information, see *[Amazon Web Services](https://docs.infoblox.com/space/UniversalAssetInsights/1501299231/Amazon+Web+Services)*.
- **Microsoft Azure **(aka Microsoft Entra ID). For information, see *[Microsoft Azure](https://docs.infoblox.com/space/UniversalAssetInsights/1501299419/Microsoft+Azure)*.
- **GCP **(Google Cloud). For information, see *[Google Cloud Platform](https://docs.infoblox.com/space/UniversalAssetInsights/1501397481/Google+Cloud+Platform)*.

> 📝 **Limitation**
> 📝 
> 📝 IPAM and DNS discoveries are not supported if you only have the Infoblox Threat Defense license entitlement. To integrate IPAM and DNS discoveries, you must have the Universal DDI license entitlements. For information, see *[Universal DDI Licensing](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/846954761)*.

## Third-Party Integration Sources

Threat Defense supports integration with several third-party platforms to enrich asset discovery and security monitoring. These integrations allow customers to leverage external data sources alongside Threat Defense for improved visibility and context.

- **ServiceNow. **For information, see *[ServiceNow](https://docs.infoblox.com/space/UniversalAssetInsights/1501299520/ServiceNow)*.
- **CrowdStrike. **For information, see *[CrowdStrike](https://docs.infoblox.com/space/UniversalAssetInsights/1501397440/Crowdstrike)*.
- **Meraki. **For information, see *[Meraki](https://docs.infoblox.com/space/UniversalAssetInsights/1521451130/Meraki)*.

> 📝 **Limitation**
> 📝 
> 📝 IPAM and DNS discoveries are not supported if you only have the Infoblox Threat Defense license entitlement. To integrate IPAM and DNS discoveries, you must have the Universal DDI license entitlements. For information, see *[Universal DDI Licensing](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/846954761)*.

## Monitoring Discovered Asset Data on Infoblox Portal

For Threat Defense license entitlements without NIOS-X Discovery, asset monitoring is available in the **Security Workspace** of the Infoblox Portal:

- **Monitor **> **Security Workspace**
  - **Security** > **Threats** sub-workspace
  - **Security** > **Assets** sub-workspace

![The Security workspace dashboard (Assets tab) showing the summary monitors.](media://e722b0f0-1582-400b-b76b-7ea183ac1bf2)

For additional information on asset discovery monitoring, see *[Viewing Security Workspace](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/1588592724)*. To integrate and IPAM and DNS discoveries, you must have the Universal DDI license entitlements. For information, see *[Universal DDI Licensing](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/846954761)*.