Skip to main content
Version: 6.0

Vulnerability

Description​

The Vulnerability section is designed for monitoring the statistics of vulnerability scan results.

Displayed Data​

  • Statistics on unique scanned hosts with vulnerabilities of various criticality levels
  • Statistics by vulnerability types
  • Dynamics by vulnerability types
  • Top hosts by number of vulnerabilities
  • Top most common vulnerabilities
  • Vulnerability statistics by CVE type
  • Event statistics with details by vulnerable hosts
  • Event statistics with details by vulnerabilities

List of Dashboards​

  • Vulnerabilities: Overview
  • Vulnerabilities: Scanned Host Profile
  • Vulnerabilities: Vulnerable Host Profile

Data Model​

The section uses the data source fields described below. Alias used: sm_cs_vulnerability_indexes.

Categorization Fields​

Field NameValue
event.kindevent
event.categoryvulnerability

General Purpose Fields​

Vulnerability Characteristics vulnerability​

Field NameValue
vulnerability.enumerationType of vulnerability classification (CVE, etc.).
vulnerability.idIdentifier of the vulnerability within the classification.
vulnerability.classificationVulnerability danger scoring system (CVSS, etc.).
vulnerability.score.baseDegree of vulnerability danger (0-10).
vulnerability.score.versionVersion of the scoring system.
vulnerability.severityImportance level of the vulnerability (critical | high | medium | low | none)

Vulnerability Detection Location host​

Field NameValue
host.ipIP address of the host where the vulnerability was detected.
host.nameName of the host where the vulnerability was detected.

Other Fields​

Field NameValue
event.originalOriginal event text.

Dictionaries​

Dictionaries are not applied.

Example Sources​