The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Import Vulnerability Assessment report

Prev Next

The vulnerability assessment scan results of an admin domain can be imported in an XML format from a location in the Manager's file system. You can reformat the scan results and save it to a specific location, so that the Manager automatically imports the result to be later used to determine alert relevance.

Note

The Vulnerability Assessment report import feature is disabled if Alert Relevance feature is disabled in the Manager.

Steps:

  1. Select Manager → <Admin Domain Name> → Integration → Vulnerability Assessment Report Import.

    The Vulnerability Assessment Report Import page is displayed.

    GUID-10922D48-1B52-48B5-A4F0-86914D586B46-low.png
  2. Select the Enable Automatic Import? checkbox.

    Note

    By default, this option is not selected.

    The Import Settings panel is displayed with the following fields.

    Option

    Definition

    Report File Location

    Default: Specifies that the file to be imported is available in the default local location

    Custom: Specify a unique file to be imported for each admin domain.

    Report File Name

    This text field displays the default location path of the report file to be imported.

    Note

    When the Default option is selected for the Report File Location, this text field is disabled and, therefore, cannot be modified. When the Custom option is selected, this text field is enabled and you can specify a unique file name for the specific active directory.

    In an enterprise environment, the default file can be used across all admin domains. In environments such as MSSP where a unique active directory is created for each customer, a unique file can be used for each active directory.

    Sample XML File

    Click on the Sample XML File hyperlink to view the sample file located in the Manager file system, which is in the same directory as the default import file. This sample file can be used as a file template for the XML file.

    Trellix DTD File

    Click on the Trellix DTD File hyperlink to view the GenVulReportFlat.dtd located in the Manager file system. It provides the details of the XML rules for the XML format.

    Import Frequency

    To configure the frequency of import, select the following options:

    • Weekly: For weekly import, select the day (Example:Sunday) from the drop-down list, and select the weekly time for import from the at drop-down list.

    • Daily: For a daily report, select the daily time for import from the at drop-down list.

      Note

      The import frequency coincides with the server time.

    Generate Informational Faults

    Select the Generate Informational Faults to generate an informational fault when the import attempt is successful.

  3. Click Import Now to import the results from the specified results file location.

Sample XML file

The sample XML file can be used an XML file template for importing the scan result. The sample XML file contains the following root elements.

  • <Report Summary> - Contains the summary of time and security vulnerability of the scanned vulnerability report

  • <Host Summary> - Contains the summary of the host in the scanned vulnerability report

  • <HostVulnerabilities> - Contains the host vulnerability details of each vulnerability

The following table explains the list of child elements under each root element.

XML child elements

Description

<Time summary>

<Report Time>

The date when the scan was performed

Example: 09.10.2022 (MM.DD.YYYY)

<ScanStartTime>

The starting time of the scan

Example: 09.10.2022 (MM.DD.YYYY) 18:08:17 (HH:MM:SS)

Note

The scan start time coincides with the server time.

<ScanEndTime>

The end time of the scan

Example: 09.10.2022 (MM.DD.YYYY) 18:49:37 (HH:MM:SS)

<ScanElapsedTime>

The duration of the time elapsed since the scan was performed

Example: 0 day(s) 00:41:19 (HH:MM:SS)

<SecurityVulnerability Summary>

<TotalNumberOfVulnerabilities>

The total number of vulnerabilities found in the scan

<HighSeverityVulnerabilities>

The total number of high severity vulnerabilities found during the scan

<MediumSeverityVulnerabilities>

The total number of medium severity vulnerabilities found during the scan

<LowSeverityVulnerabilities>

The total number of low severity vulnerabilities found during the scan

<InformationalVulnerabilities>

The total number of informational vulnerabilities found during the scan

<Host Info>

<HostIP>

IP address of the host

<HighSeverityVulnerabilities>

High severity vulnerabilities found in the host

<MediumSeverityVulnerabilities>

Medium severity vulnerabilities found in the host

<LowSeverityVulnerabilities>

Low severity vulnerabilities found in the host

<InformationalVulnerabilities>

Informational vulnerabilities found in the host

<SingleVulnerability>

<HostIP>

IP address of the host

<OriginalDescription>

The original description of the vulnerability

<PortNumber>

The port number of the host

<Protocol>

The protocol used for communication

<ServiceName>

The service name

<Severity>

The severity of the vulnerability

<VulnerabilityDescription>

The description of the vulnerability

<Solution>

The solution for the vulnerability

<RiskFactor>

The risk factor, if exists

<CVE>

The CVE ID of the vulnerability

<BID>

BID ID for the vulnerability, if any

<OtherRef>

Other references, if any

Example: OSVDB:94 CWE:200

View import result and domain statistics

After you import a Vulnerability Assessment report, the details of the import are displayed in the Last Import panel. The following details of the import are displayed.

Field

Description

Time

The time stamp of when the import was done

Result

Displays the status of the import. The following are the available status:

  • Success -- The import is done successfully.

  • Error -- The import is not done due to an error. The reason for the error is also displayed.

  • Warning -- The import is done but not complete. The reason for the warning is also displayed.

IPs Added/Updated/Ignored

Displays the number of IPs that are added, updated or ignored during the import

The Domain Statistics panel displays the number of endpoints for the admin domain for which the vulnerability assessment result is available.

By clicking the Purge Current Results in the Domain Statistics panel, you can delete all the vulnerability assessment results that are stored for the admin domain.

Purge vulnerability assessment results

In the Domain Statistics panel, you can delete the vulnerability assessment results that are stored in the admin domain. To do so, perform the following steps.

  1. Select Manager → Admin Domain Name → Integration → Vulnerability Assessment Report Import.

  2. Click Purge Current Results in the Domain Statistics panel.

  3. Click OK to purge all results.

    With Purge Current Results, all the details of the import are reset in the Last Import panel.