Scan Import - Documentation for Truesight Vulnerability Management 3.1

The Scan Import page lets you import results of scans performed by vulnerability management systems such as Qualys, Nessus, or Rapid7. After you use one of those systems to scan for potential issues in your data center environment, you can export the results so they can be imported into TrueSight Vulnerability Management. The export must be in XML format. 

When a vulnerability scan file is imported into TrueSight Vulnerability Management, assets that are included in the scan are automatically mapped to endpoints managed by the underlying endpoint manager.

The automatic mapping process depends on the endpoint manager:

  • For TrueSight Server Automation and SCCM—TrueSight Vulnerability Management matches the domain name server (DNS) and then the IP address of an asset in a vulnerability scan to an endpoint managed in TrueSight Server Automation or SCCM.
  • For TrueSight Network Automation—TrueSight Vulnerability Management matches the device address and then the IP address of an asset in a vulnerability scan to an endpoint with the same information managed in TrueSight Network Automation. 

The presence of networking gear such as firewalls, load balancers, and proxies can cause mapping discrepancies. As a result, automatic mapping may not always correctly map all endpoints. For any assets that are not automatically mapped to the correct endpoints, use the Assets page to perform manual mapping.

This topic contains the following sections:


Note: The Address (CIDR Format) filter is available from version 3.0.01.

Export files

You can import two types of export files into TrueSight Vulnerability Management:

  • Scan Reports—An export file that collects information about assets (such as servers) and the vulnerabilities associated with those assets.  
  • Asset Group Reports—A file that exports information about groupings of assets, such as server groups. You can optionally grant access to asset groups using the Asset Groups setting when configuring security groups. Click here for a full description of that process. 

For more information about what constitutes a valid scan file to be imported, see Obtaining scan files eligible for import.

Compressed files

To improve upload times, you can optionally compress the scan files you are importing into TrueSight Vulnerability Management. The import process automatically extracts the contents of the compressed file. 

If you choose to compress scan files, be aware that the compressed file can only contain a single scan file. You cannot include multiple scan files in the compressed file.

Obtaining scan files eligible for import

Only export files that meet certain requirements can be imported into TrueSight Vulnerability Management. 

Rapid7 scan files

Scan files exported from Rapid7 must use the format called XML Export 2.0. For mapping to be successful during and after the import, ensure that the reference element under the vulnerability element is populated with CVE ID in the exported file, as shown in the following example:
<vulnerability …> <reference source="CVE">CVE-2014-3596</reference></vulnerability>

Qualys scan files

The following image shows how to generate a scan export using Qualys. 

Scan exports created with Qualys must meet the following requirements:

A sample scan export is attached to this page. Below you can see the first few lines of that file. Highlighted regions flag the XML version, the DTD, and the scan ID.

Nessus scan files

Scan exports created with Nessus must meet the following requirements:

  • The scan file can be based on different types of scans (such as OS or network scans) but at minimum it must include:
    • Server name
    • Server IP address
    • Server operating system
    • Associated plugin IDs (a plugin is a check for a vulnerability)
  • The file must be in XML format and the file ending must be .nessus. Other formats for saving scan data are not supported.
  • For mapping to be successful during and after the import,  ensure that the <cve> element under the ReportItem element is populated with CVE ID in the exported file, as shown in the following example:
    <ReportItem pluginID="70322" pluginName=”” …><cve>CVE-2013-5472</cve>

A sample scan export from Nessus is attached to this page. See Creating and importing a Nessus scan file for a description of how to create and download a Nessus scan file.

Asset group report files

Currently, only Qualys lets you generate asset group files, but you can manually create an asset group file using the format in the sample attached to this page. 

The following image shows how to generate an asset group export using Qualys. 

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest