-
Notifications
You must be signed in to change notification settings - Fork 3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added support for nessus:pro data. #567
Conversation
"macro_name": "cs_nessus", | ||
"label": "Nessus Data", | ||
"search_by": "sourcetype", | ||
"search_values": "nessus:pro:vuln,nessus:pro:plugin,nessus_json", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
is this source=nessus:pro:plugin required? seems we are not using in cyences
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
right, removed
| append [| inputlookup cs_nessus_inventory] \ | ||
| stats latest(time) as time, latest(*) as * by nessus_uuid \ | ||
| eval _key=nessus_uuid | outputlookup cs_nessus_inventory | ||
action.cyences_notable_event_action.products = nessus |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nessus
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| append [| inputlookup cs_nessus_vuln] \ | ||
| dedup nessus_uuid, vul_id sortby -_time \ | ||
| outputlookup cs_nessus_vuln | ||
action.cyences_notable_event_action.products = nessus |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nessus
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
49a16dc
to
9168bcc
Compare
No description provided.