Skip to main content
Version: 5.0

Vulnerability

Description

The Vulnerability section is designed for monitoring the statistics of vulnerability scan results.

Displayed Data

  • Statistics on unique scanned hosts with vulnerabilities of various criticality levels
  • Statistics by vulnerability types
  • Dynamics by vulnerability types
  • Top hosts by number of vulnerabilities
  • Top most common vulnerabilities
  • Vulnerability statistics by CVE type
  • Event statistics with details by vulnerable hosts
  • Event statistics with details by vulnerabilities

List of Dashboards

  • Vulnerabilities: Overview
  • Vulnerabilities: Scanned Host Profile
  • Vulnerabilities: Vulnerable Host Profile

Data Model

The section uses the data source fields described below. Alias used: sm_cs_vulnerability_indexes.

Categorization Fields

Field NameValue
event.kindevent
event.categoryvulnerability

General Purpose Fields

Vulnerability Characteristics vulnerability

Field NameValue
vulnerability.enumerationType of vulnerability classification (CVE, etc.).
vulnerability.idIdentifier of the vulnerability within the classification.
vulnerability.classificationVulnerability danger scoring system (CVSS, etc.).
vulnerability.score.baseDegree of vulnerability danger (0-10).
vulnerability.score.versionVersion of the scoring system.
vulnerability.severityImportance level of the vulnerability (critical | high | medium | low | none)

Vulnerability Detection Location host

Field NameValue
host.ipIP address of the host where the vulnerability was detected.
host.nameName of the host where the vulnerability was detected.

Other Fields

Field NameValue
event.originalOriginal event text.

Dictionaries

Dictionaries are not applied.

Example Sources