All Products
Search
Document Center

Security Center:Manage servers

Last Updated:Mar 31, 2026

After you add servers to Security Center, manage them on the Server tab of the Host page. From there, sync asset information, view server details, organize servers into groups, set asset importance, assign tags, and change protection status.

Prerequisites

Before you begin, ensure that you have:

Synchronize latest assets

Security Center automatically syncs asset information every minute for servers where the client is installed. If you just installed the client, trigger a manual sync so that your new servers appear in the list immediately.

  1. In the navigation pane, choose Assets > Host. In the upper-left corner, select China or Outside China.

  2. On the Host page, click the Server tab, then click Synchronize Assets.

Security Center pulls the latest server information and refreshes the list.

The sync takes about one minute to complete.

Add multi-cloud assets

Security Center can protect servers not deployed on Alibaba Cloud, including third-party cloud servers and servers in data centers (IDCs). The steps vary by server type.

Server typeSteps
Third-party cloud servers (e.g., Tencent Cloud, Amazon Web Services)1. In the navigation pane, choose Assets > Host. Select Chinese Mainland or Outside Chinese Mainland. <br>2. In the Add Multi-cloud Asset area, hover over the vendor icon and click Add. <br>3. In the Add Assets Outside Cloud panel, complete the configuration. For details, see Add cloud assets using the AccessKey pair of a third-party account.
IDC servers1. In the navigation pane, choose Assets > Host. Select Chinese Mainland or Outside Chinese Mainland. <br>2. In the Add Multi-cloud Asset area, hover over the IDC接入图标 icon and click Add. <br>3. In the Add Assets Outside Cloud panel, complete the configuration. For details, see Add third-party cloud assets.
Servers outside Alibaba Cloud1. In the navigation pane, choose Assets > Host. Select Chinese Mainland or Outside Chinese Mainland. <br>2. In the Add Multi-cloud Asset area, hover over the 云外主机 icon and click Install Agent. <br>3. On the Feature Settings page, install the client. For details, see Install the client.

View server information

  1. In the navigation pane, choose Assets > Host. Select Chinese Mainland or Outside Chinese Mainland.

  2. On the Host page, click the Server tab.

Find a specific server

Use the search bar above the server list to search by Instance Name, Public IP Address, or Private IP Address. The Risk Status column shows whether each server has security risks. Click View in the Actions column to open a server's details page.

The details page contains the following tabs:

TabContents
Basic informationServer ID, region, group, and operating system. Also shows protection status (client self-protection, malicious network behavior defense, web shell connection defense, and malicious host behavior defense), vulnerability scan types, brute-force attack protection rules, and logon security settings. To change the server's group or run a quick diagnostic on an abnormal client, use this tab.
Vulnerability DetailsVulnerability scan results for the server.
AlertSecurity alert information for the server.
Asset FingerprintsDetailed server fingerprint data. Available only on Enterprise or Ultimate subscription editions (with the protection edition set to Enterprise or Ultimate), or with pay-as-you-go Host and Container Security enabled (at the Host Protection or Host and Container Protection level).
Agentless DetectionVulnerability risks, baseline configurations, and security alerts detected without an installed client.
CSPMCloud service configuration risk checks and system baseline risk check results. Available only when the baseline check feature is enabled. To enable the feature, see Enable the baseline check feature.
O&M and MonitoringRemote O&M via Cloud Assistant (command history, execution results, file transfers) and performance metrics (CPU utilization, memory usage, system load, network traffic, TCP connections).
If a server's basic information (such as MAC address or kernel version) is missing, go back to the asset list, select the server, and choose More Operations > Asset Collection.

Browse servers by status or category

The left panel groups servers by status and attribute. Click any category to filter the list.

CategoryServers shown
All ServersAll Alibaba Cloud servers and non-Alibaba Cloud servers with the client installed.
At RiskServers with active security risks: vulnerabilities, CSPM risks, or security alerts.
UnprotectedServers with a client status of Offline or Paused, and a power state of Running or Unknown. Security Center cannot protect these servers.
UnauthorizedServers on the Free Edition (subscription) or Unprotected (pay-as-you-go Host and Container Security).
ShutdownServers that are shut down.
ExposedServers that can communicate with the Internet. Requires Enterprise or Ultimate subscription (with the protection edition set to Enterprise or Ultimate), or pay-as-you-go Host and Container Security at the Host Protection or Host and Container Protection level. If these conditions are not met, Unknown is displayed. For details, see Asset exposure analysis.
AddAlibaba Cloud ECS servers purchased in the last 15 days.
Server GroupServers organized by group. Click a group name to see its servers.
Server RegionServers organized by region.
VPCServers organized by Virtual Private Cloud (VPC).
ImportanceServers organized by importance level:
Important

, Normal, or Test.

TagServers organized by tag.

Filter servers with multiple conditions

Under any category, combine search conditions to narrow the list. The following example filters for Linux servers in the China (Hangzhou) region that have active security alerts:

  1. Click Unprotected in the left panel.

  2. From the search condition drop-down list, set:

    • OS Type: Linux

    • Whether Alert Exists: Yes

    • Region: China (Hangzhou)

    For conditions that don't have a drop-down list, select the filter and type the value directly.
  3. Click AND or OR to the left of each condition to set the logical relationship between conditions.

  4. (Optional) Click Save to the right of the conditions to reuse this filter later.

多条件筛选

Server not showing up?

If a server doesn't appear in the list:

  • Verify the console region selector matches where the server is deployed.

  • If the client was just installed, trigger a manual sync — see Synchronize latest assets.

  • For non-Alibaba Cloud servers, confirm the client installation completed successfully.

Manage server groups, importance, and tags

Use groups, importance levels, and tags to organize servers for batch operations. When applying features like anti-ransomware, web tamper proofing, baseline checks, and vulnerability scans, target a server group instead of selecting servers one by one.

  1. In the navigation pane, choose Assets > Host. Select Chinese Mainland or Outside Chinese Mainland.

  2. On the Host page, click the Server tab. The Attribute panel on the left contains the Server Group, Importance, and Tag sections.

Manage server groups

Edit or delete a group

Hover over the group name, click the 设置 icon, and update the name or membership in the Group Management dialog box.

To delete a group, hover over it, click the 删除 icon, and confirm.

The default group Ungrouped cannot be deleted.

Move servers to a different group

  1. In the Server Group section, click a group name.

  2. Select the servers to move, then click Change Group below the list.

  3. In the Change Group dialog box:

    • To move to an existing group: set Mode to Move to Existing Group and select a group from the New Group drop-down list.

    • To create a new group: set Mode to Create Group and enter a name in the New Group field.

  4. Click OK.

You can also select servers directly from the main server list and click Change Group below the list to change their group without first entering a group view.

Manage server importance

Importance levels determine the asset importance factor used when calculating vulnerability fix priority scores. Set core servers to Important so Security Center prioritizes their vulnerability alerts.

Importance levelAsset importance factorWhen to use
Important1.5Servers running core services or storing critical data. A compromise has major business impact.
Normal1General-purpose servers that are highly replaceable. Limited impact if compromised.
Test0.5Servers used for testing or with minimal business impact.

For more details on how importance factors affect scoring, see Vulnerability fix priorities.

Set importance for multiple servers

In the Importance section, click Manage. In the Asset Importance Management dialog box, select an importance level, choose the servers to include, and click OK.

Adjust importance for an existing level

Hover over an importance level (e.g., Important), click the 设置 icon, and add or remove servers in the Asset Importance Management dialog box.

Set importance for a single server

In the server list, click the 标签 icon in the Server Information column, select an importance level, and click OK.

Manage server tags

Tags let you label servers with custom properties and filter the list by those properties.

Create a tag

In the Tag section, click Manage in the upper-right corner. In the Tag Management dialog box, enter a tag name, select the servers to tag, and click OK.

Edit or delete a tag

Hover over the tag, click the 设置 icon, and update the name or server membership in the Tag Management dialog box.

To delete a tag, hover over it, click the 删除 icon, and confirm in the Message dialog box.

Tag a single server

In the server list, click the 标签 icon in the Server Information column, select a tag, and click OK.

A server can have multiple tags. To remove a specific tag from a server, click the 删除 icon next to the tag in the Server Information column and confirm.

Change the protection status of servers

After the Security Center client is installed on a server, protection is automatically enabled. The Agent column shows the current status:

Disable protection

Important

While protection is disabled, Security Center stops performing vulnerability scans and generating security alerts for the server. Proceed with caution.

Select one or more servers showing the 客户端在线 icon, click More Operations, and select Disable Protection. The icon in the Agent column changes to 客户端离线.

Enable protection

Select one or more servers showing the 客户端离线 icon, click More Operations, and select Enable Protection.

After enabling protection, the offline icon may still appear if:
The Security Center client is not installed. Install the client — see Install the client. Once installed, Security Center enables protection automatically.
The client is installed but offline. Resolve the offline issue — see Troubleshoot offline clients.

Detach servers not deployed on Alibaba Cloud

If a non-Alibaba Cloud server is shut down and has pending vulnerabilities or alert events, detaching it prevents those unresolved risks from affecting your account's overall security score.

Only non-Alibaba Cloud servers need to be detached. Alibaba Cloud ECS servers remain in the asset list with an offline status even after the client is uninstalled — they are not removed automatically.
After detaching, the server no longer consumes an authorization quota. The released quota can be used for other servers.
If the server was added using an AccessKey pair from a third-party account, detaching it triggers client uninstallation and removes it from Security Center. However, the server is re-synchronized to Security Center at the next sync cycle. The client is not reinstalled automatically.
  1. In the navigation pane, choose Assets > Host. Select Chinese Mainland or Outside Chinese Mainland.

  2. On the Host page, click the Server tab, select the non-Alibaba Cloud server to detach, and choose More Operations > Unbind.

  3. In the Note dialog box, click OK.

After the server is detached, Security Center sends a command to uninstall the client, removes the server from the asset list, and stops protection.

If you prefer to uninstall the client directly without detaching through the console, all client processes and files are removed from the server. To protect the server again in the future, reinstall the client — see Install the client.

Clean up off-cloud host assets

Scheduled cleanup automatically removes offline hosts from the server list after a specified number of idle days, reclaiming authorization quotas and preventing resource waste.

  1. In the navigation pane, choose Assets > Host. Select Chinese Mainland or Outside Chinese Mainland.

  2. In the Add Multi-cloud Asset section, hover over the image icon and click Scheduled Cleanup.

  3. In the Scheduled Cleanup dialog box, click the image icon to enable the feature.

  4. Under Cleanup Rule, click the image icon and set the number of offline days. Enter an integer from 1 to 30.

Hosts that remain offline longer than the specified period are automatically removed and their authorization quotas reclaimed.

What's next