Finding Data Model
The Finding data model is a security finding, which may be a vulnerability, policy violation, an alert, or a code issue. It extends the Entity Model data model.
The following table details the default attributes of the Finding data model:
Order | Attribute Name | Attribute Type | Relationship Type | Required |
---|---|---|---|---|
1 | confidence | Single Choice | N/A | No |
2 | summary | Text | N/A | No |
3 | description | Text | N/A | No |
4 | assessment | Reference (Assessment) | DISCOVERED_IN | No |
5 | severity | Single Choice | N/A | No |
6 | status | Status | N/A | No |
7 | results | Text | N/A | No |
8 | statusCategory | Single Choice | N/A | No |
9 | type | Reference (Finding definition) | IS | No |
10 | targets | Reference (Asset) | HAS | No |
11 | remediationSLA | Number | N/A | No |
12 | firstFound | Date Time | N/A | No |
13 | lastFound | Date Time | N/A | No |
14 | lastFixed | Date Time | N/A | No |
15 | baseRiskScore | Number | N/A | No |
16 | riskFactorOffset | Number | N/A | No |
17 | riskScore | Number | N/A | No |
18 | riskRating | Single Choice | N/A | No |
19 | ageInDays | Number | N/A | No |
20 | sla | Number | N/A | Yes |
21 | slaLevel | Text | N/A | No |
22 | dueDate | Date Time | N/A | No |
23 | extendedDueDate | Date Time | N/A | No |
24 | complianceStatus | Single Choice | N/A | No |
25 | daysToFix | Number | N/A | No |
26 | riskOwner | Category | N/A | No |
27 | remediationOwner | Category | N/A | No |
28 | riskScoringModel | Risk Scoring Model | N/A | No |
29 | riskFactors | Risk Factors | N/A | No |
30 | slaDefinition | SLA | N/A | No |
31 | uid | Text | N/A | Yes |
32 | dataModelName | Calculated (Text) | N/A | No |
33 | sourceUids | Text (Multivalued) | N/A | No |
34 | connectorCategories | Text (Multivalued) | N/A | No |
35 | connectorNames | Text (Multivalued) | N/A | No |
36 | dataIntegrationTitles | Text (Multivalued) | N/A | No |
37 | sourcesIcons | Source data models icons | N/A | No |
38 | name | Text | N/A | No |
39 | displayName | Text | N/A | Yes |
40 | categories | Text (Multivalued) | N/A | No |
41 | flowState | Text | N/A | No |
42 | sources | Reference (Base model) | SOURCED_FROM | No |
43 | dateCreated | Date Time | N/A | No |
44 | lastUpdated | Date Time | N/A | No |
45 | createdBy | Text | N/A | No |
46 | updatedBy | Text | N/A | No |
FOOTNOTES
- The Order column specifies the order of attributes being calculated in data computation.
- The attribute names are used in Brinqa Query Language (BQL) queries and Brinqa Condition Language (BCL) predicates.
- In the Type column, Calculated means that the value of the attribute is computed by executing a script. The text in the parentheses after Calculated denotes the type of the outcome.
- In the Type column, Reference means that two data models are related. The name in the parentheses after Reference indicates the other data model.
- The Relationship Type column only applies to the Reference type attributes. You can use the relationship type keyword in BQL queries.