Skip to main content

Incident Data Model

The Incident data model represents a security incident, which may be a vulnerability, a policy violation, an alert, or a code issue. It extends the Finding data model.

The following table details the default attributes of the Incident data model:

Attribute NameAttribute TypeRelationship TypeRequired
ageInDaysNumberN/ANo
approvedExceptionRequestCalculated (True False)N/ANo
approvedFalsePositiveRequestCalculated (True False)N/ANo
approvedRemediationValidationRequestCalculated (True False)N/ANo
approvedRiskAcceptanceRequestCalculated (True False)N/ANo
assessmentReference (Assessment)DISCOVERED_INNo
attachmentsAttachmentsN/ANo
baseRiskScoreCalculated (Number)N/ANo
categoriesText (Multivalued)N/ANo
cisaDueDateExpiredCalculated (True False)N/ANo
commentsCommentsN/ANo
complianceStatusSingle ChoiceN/ANo
confidenceSingle ChoiceN/ANo
connectorCategoriesText (Multivalued)N/ANo
connectorNamesText (Multivalued)N/ANo
createdByTextN/ANo
dataIntegrationTitlesText (Multivalued)N/ANo
dataModelNameCalculated (Text)N/ANo
dateCreatedDate TimeN/ANo
daysToFixNumberN/ANo
descriptionText AreaN/ANo
displayNameTextN/AYes
dueDateDate TimeN/ANo
extendedDueDateDate TimeN/ANo
firstFoundDate TimeN/ANo
flowStateTextN/ANo
informedUsersCategory (Informed user)INFORMED_OFNo
lastFixedDate TimeN/ANo
lastFoundDate TimeN/ANo
lastUpdatedDate TimeN/ANo
lifecycleInactiveDateCalculated (Date Time)N/ANo
lifecyclePurgeDateCalculated (Date Time)N/ANo
lifecycleStatusCalculated (Single Choice)N/ANo
nameTextN/ANo
remediationOwnerCategory (Remediation owner)OWNS_REMEDIATIONNo
remediationSLANumberN/ANo
resultsTextN/ANo
riskFactorOffsetNumberN/ANo
riskFactorsRisk FactorsN/ANo
riskOwnerCategory (Risk owner)OWNS_RISKNo
riskRatingSingle ChoiceN/ANo
riskScoreNumberN/ANo
riskScoringModelRisk Scoring ModelN/ANo
severitySingle ChoiceN/ANo
slaNumberN/ANo
slaDefinitionSLAN/ANo
slaLevelTextN/ANo
sourceStatusSingle ChoiceN/ANo
sourceUidsText (Multivalued)N/ANo
sourcesReference (Source model)SOURCED_FROMNo
sourcesIconsSource data models iconsN/ANo
statusCalculated (Single Choice)N/ANo
statusCategoryCalculated (Single Choice)N/ANo
statusConfigurationModelStatus Configuration ModelN/ANo
summaryTextN/ANo
targetsReference (Asset)HASNo
typeReference (Incident definition)ISNo
uidTextN/AYes
updatedByTextN/ANo
FOOTNOTES
  • The attribute names are used in Brinqa Query Language (BQL) queries and Brinqa Condition Language (BCL) predicates.
  • In the Type column, Calculated means that the value of the attribute is computed by executing a script. The text in the parentheses after Calculated denotes the type of the outcome. For additional information, see Calculated attributes.
  • In the Type column, Reference means that two data models are related. The name in the parentheses after Reference indicates the other data model.
  • The Relationship Type column only applies to the Category and Reference type attributes. You can use the relationship type keyword in BQL queries.