The Findings tab has two containers of information that can be expanded or collapsed:
Findings: an overall view of all findings that the user has access to view and have been published
Findings By Client: a view of findings filtered by the client
Only published findings from reports with a "Published" status are included in the analytics module. In the Admin Dashboard, administrators can default findings to "Published" upon creation.
When filters are selected, the data displayed refreshes, and the active filters are listed at the top of the page.
Search filters allow users to refine and narrow their search results based on specific criteria or parameters.
Analytics filter values and data sets are updated every minute. If a tag or field was updated but did not appear as expected, wait one minute and try again.
A list of all filters and values for the Findings tab exists below:
Client(s)
Client Tags
Date Range
Asset(s)
Asset Tags
Finding Severity: Unchecking a severity will hide any asset with only findings of that severity.
Critical
High
Medium
Low
Informational
Asset Severity
Critical
High
Medium
Low
Informational
Unspecified
Finding Tags
Finding Status
Open
In Process
Closed
Report
Report Tags
Graph View
Assignees: This field only relates to Clients, Client Tags, Finding Tags, Reports, and Report Tags. If other fields are selected, the pulldown menu for Assignees will be blank. Similarly, if a report with no assignees is set, the pulldown menu for Assignees will be empty.
CVE ID
CWE ID
The CVE and CWE filters use an “and” query condition that requires both of the specified search terms or conditions to be present in the results. In other words, the search results must meet all of the specified conditions to be included in the results. For example, if two CVE values are added as a filter, the results will only display findings that contain both values.
The Findings container displays the status, severity, client breakdown, and most critical findings for all tenant findings within defined query parameters and user permissions.
The Findings By Client container breaks down findings per client. Scroll down to see additional clients in the tenant.
More details about a specific finding can be obtained in the "Most Critical Findings" table.
Clicking the row of a finding brings up the finding details modal. From this modal, the user can:
Access the Findings tab of the Report module for further editing by clicking the "Finding ID" value.
Modify the finding status by clicking the "Status" value.
View information on an affected asset by clicking the table row of the asset.
View information on the CVE ID by clicking the link provided (when applicable).