Filter Components
For general information about using filters, see Filters.
| Filter Component | Description |
|---|---|
| Access |
The level of object access to include in the filter:
|
| Actions | The alert actions to include in the filter: Email, Notify, Report, Scan, SysLog, or Ticket. For more information, see Alerts and Alert Actions. |
| Agent Scanner | The agent scanners to include in the filter. For more information, see Agent Scanning. |
| Assignee | The ticket assignees to include in the filter. For more information, see Tickets. |
| Authorized | The Log Correlation Engine Client authorization status to include in the filter: yes or no. |
| Client IP | The Log Correlation Engine Client IP addresses to include in the filter. For more information, see Tenable Log Correlation Engine Clients. |
| Completion Time |
The date range for scan results to include in the filter:
|
| Creator | The ticket creators to include in the filter. For more information, see Tickets. |
| Data Type | The repository data type to include in the filter: Agent, IPv4, IPv6, or Mobile. For more information, see Repositories. |
| Date | The date range to include in the system log filter (for example, Oct 2021). For more information, see System Logs. |
| Filter By | The type of plugin data to include in the plugin filter. For more information, see Vulnerability Analysis Filter Components. |
| Finish Time |
The date range for report results to include in the filter:
|
| Group | The groups to include in the filter. For more information, see Groups. |
| Host | The name of the host to include in the filter. For more information, see Host. |
| Initiator | The username for a user who initiated a job to include in the filter. For more information, see Job Queue Events. |
| Keywords | The keywords to include in the system logs filter (for example, login). For more information, see System Logs. |
| Log Correlation Engine Server | The Log Correlation Engine servers to include in the filter. For more information, see Tenable Log Correlation Engines. |
| Module | The type of logs to include in the system logs filter. For more information, see System Logs. |
| Name | The name of the object or user to include in the filter. For example, the name of a Tenable Nessus scanner or the name of a repository. |
| Organization | The organization to include in the filter. For more information, see Organizations. |
| OS | The operating systems to include in the filter. |
| Owner |
The object owners to include in the filter. The object owner is the user who created an object or inherited objects from a deleted user. |
| Plugin | The plugin IDs to include in the filter. |
| Plugin Family | The plugin family to include in the plugin filter. |
| Repositories | The repositories to include in the filter. For more information, see Repositories. |
| Repository | The repository to include in the filter. For more information, see Repositories. |
| Role | The user roles to include in the filter. For more information, see User Roles. |
| Scan Policy | The scan policies to include in the filter. For more information, see Scan Policies. |
| Schedule | The schedules to include in the filter. For more information, see |
| Severity | The severity to include in the filter. For more information, see CVSS vs. VPR. |
| State | The Log Correlation Engine Client state to include in the filter: Alive or Dead. For more information, see Tenable Log Correlation Engine Clients. |
| Status |
The statuses to include in the filter. |
| Tags | The tags to include in the filter. For more information, see Tags. |
| Timeframe | The date range to include in the notification filter: Last 24 Hours, Last 7 Days, or Last 30 Days. |
| Type | The object type (for example, Active or Agent scan results). |
| Username | The username to include in the filter. For more information, see User Account Options. |
| Version | The Tenable NessusLog Correlation Engine version to include in the filter. For more information, see Tenable Nessus Scanners |