6. Analyzing Findings
The Analyze page is where you work finding by finding. Every finding from every loaded scan is in one grid, joined to your POA&M and remediation plan, with a details panel for reading a finding properly and for recording what you intend to do about it.
6.1 The Analyze grid
Section titled “6.1 The Analyze grid”One row per finding — that is, one row per host, plugin and port combination. A single missing patch on forty machines is forty rows here. (Chapter 5’s Patch Summary tab is the same data collapsed the other way.)
The grid carries around sixty columns, from host identity through severity and CVSS scoring to the plugin write-up and your POA&M and remediation status. Appendix A lists every column with a plain-language explanation. The columns are colour-banded into four groups — host, risk, plugin, and POA&M / remediation — so you can find your bearings when scrolled sideways.
Every column can be sorted, filtered and grouped from its header menu, and the search box above the grid searches all of them at once.
6.2 Aggregate by Plugin ID
Section titled “6.2 Aggregate by Plugin ID”Above the grid is a switch labelled Aggregate by Plugin ID.
With it off (the default) you get one row per finding. With it on you get one row per plugin, and the host columns collapse: Hostname, Host IP, Host Description, MAC Address, DNS Name and NetBIOS list all their distinct values separated by semicolons. For other columns, where every host agrees the value is shown once; where they differ, the values are listed against the hosts they came from, in the form host1, host2: value; host3: other value.
6.3 The details panel
Section titled “6.3 The details panel”Click a row to open the details panel on the right. Its heading is the plugin name. Click a specific cell and the panel jumps to that field, highlights it and scrolls it into view — useful when a cell is truncated and you want to read all of it.
The panel has five tabs.
Vulnerability
Section titled “Vulnerability”Every column of the selected row, laid out as readable fields, with Hostname and Host IP pinned at the top. Long text fields such as the description, the solution and the plugin output run the full width of the panel; short fields pair up two to a row.
This tab has the standard panel controls described in section 2.5: Search fields…, the match counter, ⌃ and ⌄, Copy, and ⋮ to choose which fields are shown. Field values can be selected with the mouse and copied with Ctrl+C, and fields that point somewhere useful appear as underlined links.
The risk picture in one place, without hunting across columns: Nessus Severity, DOD Severity, STIG Severity, CVSS Base Score, CVSS3 Base Score, CVSS3 Temporal Score, CVSS Vector, Exploit Available, Exploitability Ease, Exploit Framework, CISA KEV, CISA KEV Due Date, KEV Ransomware, Unsupported by Vendor, Vuln Publication Date, Patch Publication Date, See Also and CWE Details.
Shows POA&M Item ID, Plugin ID, Raw Severity, eMASS POA&M Status, POA&M Required, Devices Affected, Description and Plugin Output.
When the finding matched a POA&M item and you have set your eMASS address in Options, an Open in eMASS button appears in the panel header and takes you straight to that item in your browser.
Remediation
Section titled “Remediation”An editable form that writes back into your remediation plan file. What you see depends on your situation:
| Situation | What the tab shows |
|---|---|
| No plan file loaded | Load or create a remediation plan on Files > Remediation Plan to edit these fields. |
| A plan is loaded, but this finding has no entry | This finding has no remediation plan entry yet. and a button Add to Plan (tooltip Creates an entry for this finding in the plan file marked ‘New items here’). |
| An entry exists | The editable fields: Status, Category, Action, Assigned To, POC, ECD, Completed Date, Details and Mitigation, with a line beneath reading Edits auto-save to {file name}. |
There is no Save button — edits save themselves, and the grid’s remediation columns update to match.
Exceptions
Section titled “Exceptions”For recording that a finding is documented, a false positive, or misleading. Exceptions are stored in the baseline you have open under Files → Baseline.
| Field | Notes |
|---|---|
| Vulnerability / Plugin ID | Filled in from the selected finding. Sub-label: Prefilled from the selected finding. |
| Exception Type | Exactly three choices: Documented, False Positive, Misleading. |
| Comment | Free text. Sub-label: Saves automatically to the baseline open in Files > Baseline. |
There is no Save button here either; edits save about half a second after you stop typing. A status line tells you what happened:
| Message | Meaning |
|---|---|
| Existing exception loaded from the baseline — edits update it. | This finding already had an exception; you are editing it. |
| Exception for {id} saved automatically (HH:mm:ss). | Saved successfully. |
| Not saved — open or create a baseline in Files > Baseline first. | There is nowhere to save it. Open a baseline and try again. |
| Enter the vulnerability/plugin id for the exception. | The ID field is empty. |
| Could not store the exception — is a baseline open? | The write failed. Check that the baseline is open and not read-only. |
6.4 Working with more than one view
Section titled “6.4 Working with more than one view”The Analyze page is a set of tabs. The first tab, Analyze, is always there and cannot be closed. You can add as many more as you like, each with its own columns, sorting, filters, grouping and aggregate setting.
| Button | What it does |
|---|---|
| + Add view | Creates a copy of the view you are in, named View 2, View 3 and so on. It inherits the current layout, so it is a starting point rather than a blank slate. Tooltip: Add a new view (clones the current tab). |
| + Coverage | Adds a plugin-coverage tab, named Coverage, Coverage 2 and so on. Chapter 7 covers these. Tooltip: Add a plugin-coverage check: which hosts do (or don’t) have a plugin. |
| Rename | Renames the current view. Opens a dialog titled Rename view with the prompt Tab name:. Tooltip: Rename the current view. |
| ⧉ Pop out | Opens the current view in its own 1200 × 800 window. Tooltip: Open the current view in its own window. |
Each added tab carries an ✕ (tooltip Close this view). Closing is immediate and not confirmed — but nothing is lost except the view’s layout; your findings are untouched.
While a popped-out window is opening you will see a dimmed overlay reading Opening window…. The tab leaves the tab strip while it is popped out and returns when you close the window.
Your views survive closing NESSviewer. Tab names, coverage checks and each view’s layout come back the next time you start.
6.5 Following links out
Section titled “6.5 Following links out”Some fields in the details panel are underlined links. Clicking one opens your default browser.
| Field | Where it takes you |
|---|---|
| PluginID, PluginIDNoURL | The plugin’s page on Tenable’s site, with the full write-up and history. |
| CVE | The CVE entry at NIST’s National Vulnerability Database. |
| Exploit Framework, ExploitNoURL | The exploit reference at Vulners. |
| POA&M eMASS Link ID, and the Open in eMASS button | The POA&M item in your own eMASS instance. Requires the eMASS URL setting; without it, the links do not appear. |
6.6 The fully-qualified hostname notice
Section titled “6.6 The fully-qualified hostname notice”You may see a banner at the top of the Analyze page reading {n} hosts have fully-qualified names, with an explanation and two buttons: Open Options and ✕.
The problem it is warning about is real and easy to miss. Nessus records whatever name the resolver returned, so the same machine can appear as web01 in one scan and web01.corp.example.mil in another. When that happens the machine stops matching itself — in your baseline, in your POA&M, and in any grouping by host.
Open Options takes you straight to the setting that fixes it (section 11.3), where you can turn on trimming names to the part before the first dot. ✕ dismisses the banner and leaves the setting alone.
6.7 Exporting from Analyze
Section titled “6.7 Exporting from Analyze”The toolbar above the grid exports what you are currently looking at — the current columns, the current filters, and whether you are in aggregate mode — to Excel or CSV. The suggested file names are nessus-vulnerabilities.xlsx and nessus-vulnerabilities.csv.
For a formal, multi-section document with a cover page and markings, use the Report Builder instead (chapter 10).