Skip to content

5. The Dashboard

The Dashboard answers “where do we stand?” It has six tabs, each a different way of looking at the same loaded scans:

Tab The question it answers
Summary How much is wrong, how bad, and how old?
Scan Information Which scan files am I looking at, and do they meet policy?
Scan Status Did the scan actually work on every host?
Totals by Asset Which machines carry the most?
Patch Summary What should I fix first?
IAVM Summary Which IAVM advisories apply to us?

Everything refreshes automatically when scans are loaded or unloaded and when you change severity or business-rule settings. Nothing on the Dashboard navigates you to another page — clicking opens a details panel or filters the grid you are already looking at.

If any loaded scan fails your business rules, a red-bordered banner appears at the top with a ⚠ and the text:

{n} of {m} scans violate scan policy — see the Scan Information tab.

If no scans are flagged, the banner is not shown at all.

Counting mode: occurrences or unique plugins

Section titled “Counting mode: occurrences or unique plugins”

Under the heading Vulnerability Summary is a switch with Occurrences on one side and Unique plugins on the other, and an italic caption that reads either Counting every occurrence (per host) or Counting each plugin once (unique).

Mode What a number means
Occurrences Every host-and-plugin combination counted separately. One missing patch on 40 machines counts as 40. This is the size of the problem.
Unique plugins Each plugin counted once no matter how many hosts have it. That same patch counts as 1. This is the amount of work.

The switch changes the big number on the severity tiles, both donut charts and the aging table. It does not change Hosts, Credentialed, IAVMs, Policy violations or either Top-10 list. Your choice is remembered between sessions, and switching is instant because both sets of numbers are already calculated.

Each tile shows a large number, a title, and a small grey line beneath it giving the same measure in the other counting mode — {n} unique when you are counting occurrences, {n} total when you are counting unique plugins.

Tile What it counts
Findings Every finding in the loaded scans, all severities including informational.
Hosts Distinct host IP addresses that were scanned.
Critical Findings at the top severity. This tile is renamed when you switch to DOD severity — see the note below.
High Findings at the second severity level.
Medium Findings at the third severity level.
Low Findings at the fourth severity level.
Exploitable Findings where a public exploit is known to exist.
CISA KEV Findings whose CVE appears in the CISA Known Exploited Vulnerabilities catalog — vulnerabilities confirmed to be exploited in the wild. Treat these as the front of the queue.
Unsupported (EOL) Findings on products the vendor no longer supports. These cannot be patched; they have to be replaced or isolated.
Credentialed Shown as a percentage: the share of hosts scanned with working credentials. Sub-line of hosts.
Avg age (days) The average age of your findings, measured from each plugin’s publication date. Findings with no publication date are left out of the average.
IAVMs How many distinct IAVA, IAVB and IAVT advisories apply. Sub-line advisories.
Policy violations How many scan files failed your business rules. Sub-line scans flagged. Turns red above zero.
Software list The health of your tracked software list against what the scans found. See below.
Ports list The same for your tracked ports list.

The two list tiles have three possible states:

Shows Sub-line Meaning
— not in use You have no tracked list loaded.
OK in sync with scans Your list and the scans agree — nothing to add or remove.
A number, in amber {a} to add, {r} to remove, or both That many differences are waiting for your review on the Software or Ports page.

Two charts sit side by side: Findings by Nessus Severity and Findings by DOD Severity. Each has a legend below it listing every tier with its colour and count.

Below the charts is a table headed Vulnerability Aging, with the caption Findings grouped by age (days since each plugin’s publication date).

Columns run Severity, ≤7, ≤14, ≤21, ≤30, ≤60, ≤90, ≤180, >180, Total. Rows are Critical, High, Medium, Low, Information, and a bold Total row.

The buckets do not overlap: a finding published 45 days ago appears only under ≤60. Age is measured from the date the plugin was published — how long a fix or detection has been publicly available — not from when you first observed the finding. A scan file records a single point in time and carries no history, so a first-observed date does not exist.

`Top 10 Vulnerabilities` lists the plugins affecting the most machines. Each row shows a rank, a severity-coloured dot, the plugin name, its Plugin {id}, and the number of hosts affected. This is your leverage list: fixing the top entry touches more machines than anything else you could do.

`Top 10 Hosts` lists the most exposed machines, ranked by Critical count, then High, then total. Each row shows the host name (or its IP if there is no name), the operating system beneath it, and two figures — {n} C and {n} H.

Neither list is clickable; both are for reading.

One row per scan file, plus a strip of tiles: Scan files, Hosts, Findings and Scan date range. The date range shows a single date when everything was scanned the same day, a range across two dates otherwise, and — when nothing is loaded.

Column What it shows
Scan Name The report name recorded inside the scan.
Compliance A chip reading OK or Issues, or blank when no business rules are enabled.
Hosts Distinct hosts in that file.
Findings Findings in that file.
Critical / High How many of those findings are at each severity.
Port Range The port range the scan policy was configured with.
Scan Date When the scan finished. Rows are sorted newest first.
Credentialed Whether credentialed checks were used, as reported by the scan itself.
Policy The name of the scan policy used.

Click a row to open the details panel. It contains:

  • The scan name and file name, with a Copy button (tooltip Copy this scan’s details to the clipboard) and ✕ to close. After you click Copy the button reads Copied for about a second.

  • Four figures: Hosts, Findings, Critical and High.

  • `Policy issues` — shown only when this scan is flagged, listing one line per broken rule. This is where you find out why a scan says Issues.

  • `Scan parameters` — the scan’s own settings, read out of the scan file: Policy, Nessus version, Plugin feed, Scanner edition, Scanner IP, Port scanner(s), Port range, Thorough tests, Experimental tests, Safe checks, Credentialed checks, Patch management checks, CGI scanning, Web application tests, Scan start, Scan duration and Scan for malware. Only the ones the scan recorded are shown.

  • `Scan Information plugin output` — the raw text, for when you need the original wording.

The possible Policy issues lines are:

Message What it means
Not all ports scanned ({range}) The scan policy did not cover the full port range. unknown appears in the brackets when the scan did not record a range at all.
Scan is {n} days old (limit {m}) The scan is older than your maximum scan age.
Scan/plugin date gap {n} days (limit {m}) The scanner was running plugins that were already stale when it ran, by more than your allowed gap.
Non-credentialed host(s) in scan At least one host in the file was scanned without working credentials, so its results are incomplete.
Host(s) did not scan successfully At least one host has a scan status that does not begin with Good.
No plugin Description/Synopsis/Solution in this export — enable “XML Plugin Attributes” in Security Center and re-export The export was produced without plugin attributes. The findings are all present but nothing explains them.

This is the tab that tells you whether to trust the rest of the Dashboard. A host that failed authentication produces very few findings, which looks like a clean machine and is not.

Six cards run across the top. Five of them filter the grid when you click them.

Card Counts Clickable
Hosts All distinct hosts. No
Credentialed Hosts scanned with working credentials. Green. Yes
Non-credentialed Everything else. Red above zero. Yes
Good Hosts whose status begins with Good. Green. Yes
Bad Hosts whose status begins with Bad. Red above zero. Yes
Other Error, Suspect and undetermined statuses. Amber above zero. Yes

Clicking a card filters the grid to those hosts and outlines the card. Clicking it again clears the filter. Below the cards you will see either the hint Tip: click a status card above to filter the grid or, when a filter is on, a chip reading Filtered by card: {name} with a ✕ Clear button beside it.

One row per scanned host. Columns are Host, Host IP, MAC Address, OS, Host Description, Credentialed, Scan Status, In Testplan?, Report Name, Scan Date and Scan Info.

NESSviewer works out the status from which authentication and local-check plugins fired on that host.

Status What it means for you
Good, Local Checks Enabled The scan authenticated and ran local checks. These results are complete — this is what you want to see.
Good, Local Checks Support Not Available or Unsupported OS The scan worked, but Nessus has no local checks for this platform. Nothing is wrong; expect thinner results.
Good, Local Checks Support Not Available or Identification Issues Reported The scan worked but had trouble identifying the platform.
Good, Local Checks Not Attempted Against Fragile Device Deliberately not probed because the device is fragile — printers, medical and industrial equipment.
Error, Local Checks Enabled and Issues Reported Authentication worked but something went wrong during the local checks. Results may be incomplete.
Bad, Local Checks Failed to be Enabled Due to an Error; No Fragile Devices Authentication was attempted and failed. Do not trust a low finding count on this host.
Bad, Authentication Capable or Credentials Not Provided The host could have been authenticated to, but no credentials were supplied. Fix the scan configuration and scan again.
Suspect, Authentication Protocols Not Available or Endpoint Became Unresponsive The host stopped responding or offered no usable authentication protocol.
Unable to determine scan status None of the status plugins fired, so no verdict is possible.

Clicking a host opens a panel built to answer “why did this host fail?”

  • A header with the host name and IP, a badge reading Credentialed or Not credentialed, and the status in its colour, plus Copy and ✕.

  • A plain-language description of that status, followed by an italic Logic: line showing the plugin combination that produced it.

  • `Plugins for this status` — one card per determining plugin, each with a badge reading In scan or Not in scan, the plugin name, Plugin {id} and the plugin’s output. Where the plugin did not fire, the output area reads Plugin was not in scan.

  • `Troubleshooting plugins on this host` — other diagnostic plugins found on this host, with their output.

  • `Scan Information` — a section that starts collapsed; click the heading (marked ▸ closed, ▾ open) to see the scan’s parameters.

Long plugin output is shortened to four lines with a Show more / Show less link.

Findings counted per machine. Tiles across the top show Hosts, Very High, High, Medium, Low and Total; the large number is the occurrence count and the small {n} unique line beneath it counts each plugin once. There is no counting switch on this tab and the tiles are not clickable.

The grid has one row per host, with columns Host IP, Hostname, OS, Very High, High, Medium, Low and Total, sorted with the worst machines first. The severity counts are shown in their severity colours.

The same findings collapsed to one row per plugin. This is the remediation worklist: applying one patch to fourteen machines is one job, not fourteen.

Card What it counts Clickable
Unique plugins Distinct plugins across all findings. No
Very High / High / Medium / Low Distinct plugins at each severity. Yes — filters the grid to that severity
Oldest (days) The age of the oldest outstanding item. No
Total Total remediation instances — every plugin multiplied by the hosts it affects. No

The grid columns are Plugin ID, Plugin Name, Severity, Affected Hosts, Publication Date and Days Since Publication. Clicking a row opens a panel with the plugin’s Description and Plugin Output.

The DOD IAVM advisories — IAVA, IAVB and IAVT — pulled out of your findings’ references. Other cross-references such as CWE and vendor bulletins are excluded, so this tab is only what you have to report against.

Cards show IAVMs, IAVA, IAVB, IAVT, Hosts and Total. The three advisory-type cards filter the grid when clicked; the hint line reads Tip: click an IAVA / IAVB / IAVT card above to filter the grid.

Grid columns are External Reference, Patch Publication Date, PluginID, Plugin Name, DOD Severity, STIG Severity, OS and Filename/Path. Clicking a row opens a panel with the plugin’s Description and Plugin Output.

Colours mean the same thing everywhere in NESSviewer.

Colour Used for
Red Critical / Very High severity; a Bad scan status; a non-credentialed host; a scan that failed policy; a coverage row that violates its expectation.
Red-orange High severity and CAT I.
Amber Medium / Moderate severity and CAT II; Other scan statuses; a tracked list with items awaiting review; results that cannot be verified.
Yellow Low severity and CAT III.
Grey Informational findings.
Green OK, Good, credentialed, in sync, present.

The thresholds behind the colours are yours to set. The defaults are:

Threshold Default
Aging buckets 7, 14, 21, 30, 60, 90, 180 days and over
Maximum scan age 90 days (the rule is off by default)
Maximum scan-to-plugin-feed gap 5 days (off by default)
What counts as “all ports” All, 0-65535 or 1-65535
POA&M aging 30 days at every severity (the rule is on by default)

All of these live on the Options page — see sections 11.1 and 11.2.

5.8 The Dashboard before any data is loaded

Section titled “5.8 The Dashboard before any data is loaded”

With nothing loaded, the Dashboard does not show a “load something first” message. It shows a valid picture of nothing:

  • Every number reads 0, and Credentialed reads 0%.

  • Software list and Ports list read — with the sub-line not in use.

  • Both donut charts are empty with no legend entries.

  • Vulnerability Aging shows its column headings and no rows.

  • Both Top-10 lists show their headings and nothing beneath.

  • Scan date range reads —, and every grid is empty.