Skip to content

3. Loading Your Scan Data

Everything in NESSviewer starts on the Files page. Until a scan is loaded, the Dashboard reads zero, the Analyze grid is empty and the reports have nothing to describe.

The Files page has four tabs: Files, Baseline, eMASS POA&M and Remediation Plan. This chapter covers the Files tab, which is where scans are loaded. The other three tabs are covered in chapter 4.

The Files tab has four parts, top to bottom:

  1. A row of loading controls: Load Files with a dropdown of recently used scan files, and Load Folder with a dropdown of recently used folders.

  2. A toolbar above the grid, carrying the export commands and — once you tick a row — an Unload button.

  3. The grid of loaded scan files, which doubles as the drag-and-drop target.

  4. A panel headed Reference Files with a row each for Baseline, eMASS POA&M and Remediation Plan.

`Load Files` opens a file picker titled Select Nessus file(s) that accepts .nessus and .zip files. You can select several at once.

`Load Folder` opens a folder picker. NESSviewer then loads every file it recognises anywhere in that folder, including files in subfolders.

The dropdown beside each button lists the files and folders you loaded most recently — up to ten of each. Choosing an entry loads it straight away.

You can drag files or folders from File Explorer straight onto the grid area. While the grid is empty it shows the prompt:

Drag and drop .nessus scans, a test plan (.tpln), remediation plan (.xml), POA&M (.xlsx), or a folder of them — or use the buttons above

While you are dragging over it, the prompt changes to Drop scans, test plan, remediation plan, POA&M, or a folder of them. Dropping loads immediately, with no confirmation step.

3.3 What NESSviewer accepts, and what each file is

Section titled “3.3 What NESSviewer accepts, and what each file is”

NESSviewer decides what a file is from its extension. There is one exception: an .xml file is opened and accepted only if it really is a remediation plan.

Extension Treated as In plain language
.nessus Scan A Nessus or ACAS scan export. Contains the hosts, the findings and the plugin write-ups. This is the file NESSviewer is built around.
.zip Scan bundle Opened automatically; every .nessus file inside is loaded, including scans inside nested zips.
.tpln Baseline / test plan Your site test plan: the authoritative list of hosts and which STIGs or ACAS batteries each must be tested with.
.xlsx or .xlsm eMASS POA&M An eMASS POA&M export — your open items with their statuses, milestones and completion dates.
.xml Remediation plan A remediation plan keyed by plugin ID: action, category, estimated completion date, point of contact, details and mitigation.
Anything else Ignored Silently skipped. See section 3.7.

While files are loading, the grid dims and a spinner appears in the centre. There is no per-file progress or “3 of 20” counter, so a large folder can look inactive for a while — the spinner is the only signal that work is happening.

Behind that spinner, NESSviewer:

  • Parses each scan, several at a time, and extracts the findings, the per-host software inventory and every host property the scan recorded.

  • Works out a scan status for every host — whether the scan actually succeeded on that machine — from the authentication plugins that fired. Chapter 5 covers what each status means.

  • Judges each scan file against your business rules and fills in the Compliance column.

  • Joins the findings to your eMASS POA&M, if one is loaded, matching on plugin ID.

  • Joins the findings to your remediation plans, if any are loaded, again on plugin ID.

  • Fills in blank hostnames and host descriptions from the baseline, if you have turned those options on.

  • Works out which findings are old enough to require a POA&M entry.

One row per loaded scan file.

Column What it shows
File The file name on its own.
Report Name The report name recorded inside the scan export — usually the scan job’s name in Security Center.
Compliance Whether the scan passes your business rules: OK, Issues, or blank. Blank means no rules are switched on, so there is nothing to judge against.
Scan Date When the scan finished.
Plugin Date The date of the plugin feed the scanner was using. A large gap between this and Scan Date means the scanner was running on stale plugins.
Type Always Nessus.
Path The full path the file was loaded from.

To find out why a scan shows Issues, go to the Dashboard’s Scan Information tab and click the scan — the details panel lists each broken rule in plain language. Section 5.2 covers this.

To take a scan back out:

  1. Tick the checkbox at the left of each row you want to remove. You can tick several.

  2. Click Unload in the toolbar — it appears as soon as at least one row is ticked.

Unload does not touch reference files. To change the baseline, POA&M or remediation plan, use their own tabs (chapter 4).

NESSviewer skips files it cannot use rather than interrupting you with error messages. That keeps a big folder load moving, but it means a file that fails simply is not there afterwards. If you drop twenty scans and get nineteen rows, this section is why.

What you see Likely cause
A .nessus file you loaded is not in the grid The file could not be parsed — damaged or truncated XML, a file still being written, a file open in another program, or a permissions problem. It is skipped silently.
A .nessus file loaded but produced no row The export contains no hosts. This happens with scans that found nothing or were aborted early.
A .zip loaded and nothing happened The archive is damaged or locked, or it contains no .nessus files.
An XML file you expected to load did not Only remediation plans are accepted as .xml. A STIG checklist, a test plan saved as .xml, or a .ckl renamed to .xml will not load.
A .ckl, .cklb, .csv, .json, .txt or .pdf did nothing Those types are not supported. The drop is accepted and then ignored.
An unrelated spreadsheet was treated as a POA&M Any .xlsx or .xlsm is assumed to be an eMASS POA&M export. Load spreadsheets deliberately rather than by dropping a folder.
Findings loaded but have no Description, Synopsis or Solution The scan was exported from Security Center without XML Plugin Attributes. The findings are real; the explanatory text was never included. Re-export with that setting enabled.
A scan’s date column looks wrong The scan recorded its end time in an unexpected format. The age-based business rules cannot be applied to that file.