Scans (History of Scans)
Field | Description |
---|---|
id | same thing |
saltminer.scan.id |
Unique id for the scan. Note: Used as key field for flow down fields. type: Keyword example: 123B |
saltminer.scan.critical saltminer.scan.high saltminer.scan.medium saltminer.scan.low |
System generated sum for the scan for this severity required: Yes type: integer example: 100 |
saltminer.scan.scan_date |
Timestamp from the related scan Note: Replaces last_scan_date at the issue level, represents the scan that generated this issue required: Yes type: timestamp example: 2018-06-29T12:36:52.430+0000 |
saltminer.scan.report_id | keyword Yes No unique identifier for this assessement 10112 report_id in related issues |
saltminer.scan.assessment_type |
Engine category (SAST, DAST, OPEN, PENTEST) SAST Configure allowable values required: Yes type: keyword |
saltminer.scan.product_type |
Source specific type of scan (i.e. SCA, mobile, static, etc.) SCA Not sure if this is redundant or not required: Yes type: keyword |
saltminer.scan.product |
Product used to run the scan required: Yes type: keyword example: SCA |
saltminer.scan.vendor |
Vendor for the scanner used to identify this issue required: Yes type: keyword example: Fortify |
saltminer.scan.rulepacks |
Rulepack(s) used to identify vulnerabilities in this scan required: No type: keyword |
SaltMiner Internal fields related to scans | |
saltminer.internal.agent_id |
Agent identifier for Sync Agent that was the source of this scan required: Yes type: keyword |
Flow down fields
Asset Inventory
- saltminer.asset_inv.is_production
- saltminer.asset_inv.name
- saltminer.asset_inv.description
- saltminer.asset_inv.version
- saltminer.asset_inv.attributes
- saltminer.asset_inv.key
Engagements
For Issues that were found as part of an engagement the following fields flow down
- saltminer.engagement.publish_date
- saltminer.engagement.name
- saltminer.engagement.customer
- saltminer.engagement.summary
- saltminer.engagement.scan_id
- saltminer.engagement.attachments[x].file_name
- saltminer.engagement.attachments[x].url
- saltminer.engagement.attributes
Assets
- saltminer.asset.last_scan-days_policy
- saltminer.asset.config_name
- saltminer.asset.source_type
- saltminer.asset.sub_type
- saltminer.asset.is_retired
- saltminer.asset.version_id
- saltminer.asset.asset_type
- saltminer.asset.host
- saltminer.asset.ip
- saltminer.asset.scheme
- saltminer.asset.port
- saltminer.asset.is_production
- saltminer.asset.name
- saltminer.asset.description
- saltminer.asset.version
- saltminer.asset.attributes