Customers who use third-party vulnerability scanners (for example, Qualys and nCircle) can manually import the corresponding scanner reports to Manager.
To successfully import and view these scanner reports in the Manager, the third party reports should be converted to an intermediate XML format, as per the Document Type Definition (DTD) provided by Trellix IPS. This XML format is known as Trellix IPS Manager XML format.
Refer to the GenVulReportFlat.dtd file to convert the third-party vulnerability scanner reports to the Trellix IPS Manager XML format. You can download this file by clicking on the Trellix DTD file hyperlink at Manager → <Admin Domain Name> → Integration → Vulnerability Assessment → Non-MVM Report Import.
Why Trellix IPS Manager XML format is used?
Since, there is no industry standard for the format of vulnerability assessment reports, Trellix IPS converts all imported reports into the Trellix IPS Manager XML format. In this way, support for new report formats can be added without having to change the way the Alert Correlation Engine works. The converted report and its metadata are stored in a new table called iv_vul_record in the Manager database, which is saved as part of the standard backup and MDR synchronization processes.