5. The Dashboard
The Dashboard answers “where do we stand?” It has six tabs, each a different way of looking at the same loaded scans:
| Tab | The question it answers |
|---|---|
| Summary | How much is wrong, how bad, and how old? |
| Scan Information | Which scan files am I looking at, and do they meet policy? |
| Scan Status | Did the scan actually work on every host? |
| Totals by Asset | Which machines carry the most? |
| Patch Summary | What should I fix first? |
| IAVM Summary | Which IAVM advisories apply to us? |
Everything refreshes automatically when scans are loaded or unloaded and when you change severity or business-rule settings. Nothing on the Dashboard navigates you to another page — clicking opens a details panel or filters the grid you are already looking at.
5.1 The Summary tab
Section titled “5.1 The Summary tab”The policy violation banner
Section titled “The policy violation banner”If any loaded scan fails your business rules, a red-bordered banner appears at the top with a ⚠ and the text:
{n} of {m} scans violate scan policy — see the Scan Information tab.
If no scans are flagged, the banner is not shown at all.
Counting mode: occurrences or unique plugins
Section titled “Counting mode: occurrences or unique plugins”Under the heading Vulnerability Summary is a switch with Occurrences on one side and Unique plugins on the other, and an italic caption that reads either Counting every occurrence (per host) or Counting each plugin once (unique).
| Mode | What a number means |
|---|---|
| Occurrences | Every host-and-plugin combination counted separately. One missing patch on 40 machines counts as 40. This is the size of the problem. |
| Unique plugins | Each plugin counted once no matter how many hosts have it. That same patch counts as 1. This is the amount of work. |
The switch changes the big number on the severity tiles, both donut charts and the aging table. It does not change Hosts, Credentialed, IAVMs, Policy violations or either Top-10 list. Your choice is remembered between sessions, and switching is instant because both sets of numbers are already calculated.
The tiles
Section titled “The tiles”Each tile shows a large number, a title, and a small grey line beneath it giving the same measure in the other counting mode — {n} unique when you are counting occurrences, {n} total when you are counting unique plugins.
| Tile | What it counts |
|---|---|
| Findings | Every finding in the loaded scans, all severities including informational. |
| Hosts | Distinct host IP addresses that were scanned. |
| Critical | Findings at the top severity. This tile is renamed when you switch to DOD severity — see the note below. |
| High | Findings at the second severity level. |
| Medium | Findings at the third severity level. |
| Low | Findings at the fourth severity level. |
| Exploitable | Findings where a public exploit is known to exist. |
| CISA KEV | Findings whose CVE appears in the CISA Known Exploited Vulnerabilities catalog — vulnerabilities confirmed to be exploited in the wild. Treat these as the front of the queue. |
| Unsupported (EOL) | Findings on products the vendor no longer supports. These cannot be patched; they have to be replaced or isolated. |
| Credentialed | Shown as a percentage: the share of hosts scanned with working credentials. Sub-line of hosts. |
| Avg age (days) | The average age of your findings, measured from each plugin’s publication date. Findings with no publication date are left out of the average. |
| IAVMs | How many distinct IAVA, IAVB and IAVT advisories apply. Sub-line advisories. |
| Policy violations | How many scan files failed your business rules. Sub-line scans flagged. Turns red above zero. |
| Software list | The health of your tracked software list against what the scans found. See below. |
| Ports list | The same for your tracked ports list. |
The two list tiles have three possible states:
| Shows | Sub-line | Meaning |
|---|---|---|
| — | not in use | You have no tracked list loaded. |
| OK | in sync with scans | Your list and the scans agree — nothing to add or remove. |
| A number, in amber | {a} to add, {r} to remove, or both | That many differences are waiting for your review on the Software or Ports page. |
The donut charts
Section titled “The donut charts”Two charts sit side by side: Findings by Nessus Severity and Findings by DOD Severity. Each has a legend below it listing every tier with its colour and count.
Vulnerability Aging
Section titled “Vulnerability Aging”Below the charts is a table headed Vulnerability Aging, with the caption Findings grouped by age (days since each plugin’s publication date).
Columns run Severity, ≤7, ≤14, ≤21, ≤30, ≤60, ≤90, ≤180, >180, Total. Rows are Critical, High, Medium, Low, Information, and a bold Total row.
The buckets do not overlap: a finding published 45 days ago appears only under ≤60. Age is measured from the date the plugin was published — how long a fix or detection has been publicly available — not from when you first observed the finding. A scan file records a single point in time and carries no history, so a first-observed date does not exist.
The Top 10 lists
Section titled “The Top 10 lists”`Top 10 Vulnerabilities` lists the plugins affecting the most machines. Each row shows a rank, a severity-coloured dot, the plugin name, its Plugin {id}, and the number of hosts affected. This is your leverage list: fixing the top entry touches more machines than anything else you could do.
`Top 10 Hosts` lists the most exposed machines, ranked by Critical count, then High, then total. Each row shows the host name (or its IP if there is no name), the operating system beneath it, and two figures — {n} C and {n} H.
Neither list is clickable; both are for reading.
5.2 The Scan Information tab
Section titled “5.2 The Scan Information tab”One row per scan file, plus a strip of tiles: Scan files, Hosts, Findings and Scan date range. The date range shows a single date when everything was scanned the same day, a range across two dates otherwise, and — when nothing is loaded.
| Column | What it shows |
|---|---|
| Scan Name | The report name recorded inside the scan. |
| Compliance | A chip reading OK or Issues, or blank when no business rules are enabled. |
| Hosts | Distinct hosts in that file. |
| Findings | Findings in that file. |
| Critical / High | How many of those findings are at each severity. |
| Port Range | The port range the scan policy was configured with. |
| Scan Date | When the scan finished. Rows are sorted newest first. |
| Credentialed | Whether credentialed checks were used, as reported by the scan itself. |
| Policy | The name of the scan policy used. |
The scan details panel
Section titled “The scan details panel”Click a row to open the details panel. It contains:
-
The scan name and file name, with a Copy button (tooltip Copy this scan’s details to the clipboard) and ✕ to close. After you click Copy the button reads Copied for about a second.
-
Four figures: Hosts, Findings, Critical and High.
-
`Policy issues` — shown only when this scan is flagged, listing one line per broken rule. This is where you find out why a scan says Issues.
-
`Scan parameters` — the scan’s own settings, read out of the scan file: Policy, Nessus version, Plugin feed, Scanner edition, Scanner IP, Port scanner(s), Port range, Thorough tests, Experimental tests, Safe checks, Credentialed checks, Patch management checks, CGI scanning, Web application tests, Scan start, Scan duration and Scan for malware. Only the ones the scan recorded are shown.
-
`Scan Information plugin output` — the raw text, for when you need the original wording.
The possible Policy issues lines are:
| Message | What it means |
|---|---|
| Not all ports scanned ({range}) | The scan policy did not cover the full port range. unknown appears in the brackets when the scan did not record a range at all. |
| Scan is {n} days old (limit {m}) | The scan is older than your maximum scan age. |
| Scan/plugin date gap {n} days (limit {m}) | The scanner was running plugins that were already stale when it ran, by more than your allowed gap. |
| Non-credentialed host(s) in scan | At least one host in the file was scanned without working credentials, so its results are incomplete. |
| Host(s) did not scan successfully | At least one host has a scan status that does not begin with Good. |
| No plugin Description/Synopsis/Solution in this export — enable “XML Plugin Attributes” in Security Center and re-export | The export was produced without plugin attributes. The findings are all present but nothing explains them. |
5.3 The Scan Status tab
Section titled “5.3 The Scan Status tab”This is the tab that tells you whether to trust the rest of the Dashboard. A host that failed authentication produces very few findings, which looks like a clean machine and is not.
The cards
Section titled “The cards”Six cards run across the top. Five of them filter the grid when you click them.
| Card | Counts | Clickable |
|---|---|---|
| Hosts | All distinct hosts. | No |
| Credentialed | Hosts scanned with working credentials. Green. | Yes |
| Non-credentialed | Everything else. Red above zero. | Yes |
| Good | Hosts whose status begins with Good. Green. | Yes |
| Bad | Hosts whose status begins with Bad. Red above zero. | Yes |
| Other | Error, Suspect and undetermined statuses. Amber above zero. | Yes |
Clicking a card filters the grid to those hosts and outlines the card. Clicking it again clears the filter. Below the cards you will see either the hint Tip: click a status card above to filter the grid or, when a filter is on, a chip reading Filtered by card: {name} with a ✕ Clear button beside it.
The grid
Section titled “The grid”One row per scanned host. Columns are Host, Host IP, MAC Address, OS, Host Description, Credentialed, Scan Status, In Testplan?, Report Name, Scan Date and Scan Info.
What each scan status means
Section titled “What each scan status means”NESSviewer works out the status from which authentication and local-check plugins fired on that host.
| Status | What it means for you |
|---|---|
| Good, Local Checks Enabled | The scan authenticated and ran local checks. These results are complete — this is what you want to see. |
| Good, Local Checks Support Not Available or Unsupported OS | The scan worked, but Nessus has no local checks for this platform. Nothing is wrong; expect thinner results. |
| Good, Local Checks Support Not Available or Identification Issues Reported | The scan worked but had trouble identifying the platform. |
| Good, Local Checks Not Attempted Against Fragile Device | Deliberately not probed because the device is fragile — printers, medical and industrial equipment. |
| Error, Local Checks Enabled and Issues Reported | Authentication worked but something went wrong during the local checks. Results may be incomplete. |
| Bad, Local Checks Failed to be Enabled Due to an Error; No Fragile Devices | Authentication was attempted and failed. Do not trust a low finding count on this host. |
| Bad, Authentication Capable or Credentials Not Provided | The host could have been authenticated to, but no credentials were supplied. Fix the scan configuration and scan again. |
| Suspect, Authentication Protocols Not Available or Endpoint Became Unresponsive | The host stopped responding or offered no usable authentication protocol. |
| Unable to determine scan status | None of the status plugins fired, so no verdict is possible. |
The troubleshooting panel
Section titled “The troubleshooting panel”Clicking a host opens a panel built to answer “why did this host fail?”
-
A header with the host name and IP, a badge reading Credentialed or Not credentialed, and the status in its colour, plus Copy and ✕.
-
A plain-language description of that status, followed by an italic Logic: line showing the plugin combination that produced it.
-
`Plugins for this status` — one card per determining plugin, each with a badge reading In scan or Not in scan, the plugin name, Plugin {id} and the plugin’s output. Where the plugin did not fire, the output area reads Plugin was not in scan.
-
`Troubleshooting plugins on this host` — other diagnostic plugins found on this host, with their output.
-
`Scan Information` — a section that starts collapsed; click the heading (marked ▸ closed, ▾ open) to see the scan’s parameters.
Long plugin output is shortened to four lines with a Show more / Show less link.
5.4 The Totals by Asset tab
Section titled “5.4 The Totals by Asset tab”Findings counted per machine. Tiles across the top show Hosts, Very High, High, Medium, Low and Total; the large number is the occurrence count and the small {n} unique line beneath it counts each plugin once. There is no counting switch on this tab and the tiles are not clickable.
The grid has one row per host, with columns Host IP, Hostname, OS, Very High, High, Medium, Low and Total, sorted with the worst machines first. The severity counts are shown in their severity colours.
5.5 The Patch Summary tab
Section titled “5.5 The Patch Summary tab”The same findings collapsed to one row per plugin. This is the remediation worklist: applying one patch to fourteen machines is one job, not fourteen.
| Card | What it counts | Clickable |
|---|---|---|
| Unique plugins | Distinct plugins across all findings. | No |
| Very High / High / Medium / Low | Distinct plugins at each severity. | Yes — filters the grid to that severity |
| Oldest (days) | The age of the oldest outstanding item. | No |
| Total | Total remediation instances — every plugin multiplied by the hosts it affects. | No |
The grid columns are Plugin ID, Plugin Name, Severity, Affected Hosts, Publication Date and Days Since Publication. Clicking a row opens a panel with the plugin’s Description and Plugin Output.
5.6 The IAVM Summary tab
Section titled “5.6 The IAVM Summary tab”The DOD IAVM advisories — IAVA, IAVB and IAVT — pulled out of your findings’ references. Other cross-references such as CWE and vendor bulletins are excluded, so this tab is only what you have to report against.
Cards show IAVMs, IAVA, IAVB, IAVT, Hosts and Total. The three advisory-type cards filter the grid when clicked; the hint line reads Tip: click an IAVA / IAVB / IAVT card above to filter the grid.
Grid columns are External Reference, Patch Publication Date, PluginID, Plugin Name, DOD Severity, STIG Severity, OS and Filename/Path. Clicking a row opens a panel with the plugin’s Description and Plugin Output.
5.7 Colour coding and thresholds
Section titled “5.7 Colour coding and thresholds”Colours mean the same thing everywhere in NESSviewer.
| Colour | Used for |
|---|---|
| Red | Critical / Very High severity; a Bad scan status; a non-credentialed host; a scan that failed policy; a coverage row that violates its expectation. |
| Red-orange | High severity and CAT I. |
| Amber | Medium / Moderate severity and CAT II; Other scan statuses; a tracked list with items awaiting review; results that cannot be verified. |
| Yellow | Low severity and CAT III. |
| Grey | Informational findings. |
| Green | OK, Good, credentialed, in sync, present. |
The thresholds behind the colours are yours to set. The defaults are:
| Threshold | Default |
|---|---|
| Aging buckets | 7, 14, 21, 30, 60, 90, 180 days and over |
| Maximum scan age | 90 days (the rule is off by default) |
| Maximum scan-to-plugin-feed gap | 5 days (off by default) |
| What counts as “all ports” | All, 0-65535 or 1-65535 |
| POA&M aging | 30 days at every severity (the rule is on by default) |
All of these live on the Options page — see sections 11.1 and 11.2.
5.8 The Dashboard before any data is loaded
Section titled “5.8 The Dashboard before any data is loaded”With nothing loaded, the Dashboard does not show a “load something first” message. It shows a valid picture of nothing:
-
Every number reads 0, and Credentialed reads 0%.
-
Software list and Ports list read — with the sub-line not in use.
-
Both donut charts are empty with no legend entries.
-
Vulnerability Aging shows its column headings and no rows.
-
Both Top-10 lists show their headings and nothing beneath.
-
Scan date range reads —, and every grid is empty.