3. Loading Your Scan Data
Everything in NESSviewer starts on the Files page. Until a scan is loaded, the Dashboard reads zero, the Analyze grid is empty and the reports have nothing to describe.
3.1 The Files page at a glance
Section titled “3.1 The Files page at a glance”The Files page has four tabs: Files, Baseline, eMASS POA&M and Remediation Plan. This chapter covers the Files tab, which is where scans are loaded. The other three tabs are covered in chapter 4.
The Files tab has four parts, top to bottom:
-
A row of loading controls: Load Files with a dropdown of recently used scan files, and Load Folder with a dropdown of recently used folders.
-
A toolbar above the grid, carrying the export commands and — once you tick a row — an Unload button.
-
The grid of loaded scan files, which doubles as the drag-and-drop target.
-
A panel headed Reference Files with a row each for Baseline, eMASS POA&M and Remediation Plan.
3.2 Loading scans
Section titled “3.2 Loading scans”Using the buttons
Section titled “Using the buttons”`Load Files` opens a file picker titled Select Nessus file(s) that accepts .nessus and .zip files. You can select several at once.
`Load Folder` opens a folder picker. NESSviewer then loads every file it recognises anywhere in that folder, including files in subfolders.
Using the recent lists
Section titled “Using the recent lists”The dropdown beside each button lists the files and folders you loaded most recently — up to ten of each. Choosing an entry loads it straight away.
Drag and drop
Section titled “Drag and drop”You can drag files or folders from File Explorer straight onto the grid area. While the grid is empty it shows the prompt:
Drag and drop .nessus scans, a test plan (.tpln), remediation plan (.xml), POA&M (.xlsx), or a folder of them — or use the buttons above
While you are dragging over it, the prompt changes to Drop scans, test plan, remediation plan, POA&M, or a folder of them. Dropping loads immediately, with no confirmation step.
3.3 What NESSviewer accepts, and what each file is
Section titled “3.3 What NESSviewer accepts, and what each file is”NESSviewer decides what a file is from its extension. There is one exception: an .xml file is opened and accepted only if it really is a remediation plan.
| Extension | Treated as | In plain language |
|---|---|---|
| .nessus | Scan | A Nessus or ACAS scan export. Contains the hosts, the findings and the plugin write-ups. This is the file NESSviewer is built around. |
| .zip | Scan bundle | Opened automatically; every .nessus file inside is loaded, including scans inside nested zips. |
| .tpln | Baseline / test plan | Your site test plan: the authoritative list of hosts and which STIGs or ACAS batteries each must be tested with. |
| .xlsx or .xlsm | eMASS POA&M | An eMASS POA&M export — your open items with their statuses, milestones and completion dates. |
| .xml | Remediation plan | A remediation plan keyed by plugin ID: action, category, estimated completion date, point of contact, details and mitigation. |
| Anything else | Ignored | Silently skipped. See section 3.7. |
3.4 What happens when a scan loads
Section titled “3.4 What happens when a scan loads”While files are loading, the grid dims and a spinner appears in the centre. There is no per-file progress or “3 of 20” counter, so a large folder can look inactive for a while — the spinner is the only signal that work is happening.
Behind that spinner, NESSviewer:
-
Parses each scan, several at a time, and extracts the findings, the per-host software inventory and every host property the scan recorded.
-
Works out a scan status for every host — whether the scan actually succeeded on that machine — from the authentication plugins that fired. Chapter 5 covers what each status means.
-
Judges each scan file against your business rules and fills in the Compliance column.
-
Joins the findings to your eMASS POA&M, if one is loaded, matching on plugin ID.
-
Joins the findings to your remediation plans, if any are loaded, again on plugin ID.
-
Fills in blank hostnames and host descriptions from the baseline, if you have turned those options on.
-
Works out which findings are old enough to require a POA&M entry.
3.5 Reading the Files grid
Section titled “3.5 Reading the Files grid”One row per loaded scan file.
| Column | What it shows |
|---|---|
| File | The file name on its own. |
| Report Name | The report name recorded inside the scan export — usually the scan job’s name in Security Center. |
| Compliance | Whether the scan passes your business rules: OK, Issues, or blank. Blank means no rules are switched on, so there is nothing to judge against. |
| Scan Date | When the scan finished. |
| Plugin Date | The date of the plugin feed the scanner was using. A large gap between this and Scan Date means the scanner was running on stale plugins. |
| Type | Always Nessus. |
| Path | The full path the file was loaded from. |
To find out why a scan shows Issues, go to the Dashboard’s Scan Information tab and click the scan — the details panel lists each broken rule in plain language. Section 5.2 covers this.
3.6 Removing scans
Section titled “3.6 Removing scans”To take a scan back out:
-
Tick the checkbox at the left of each row you want to remove. You can tick several.
-
Click Unload in the toolbar — it appears as soon as at least one row is ticked.
Unload does not touch reference files. To change the baseline, POA&M or remediation plan, use their own tabs (chapter 4).
3.7 When a file does not appear
Section titled “3.7 When a file does not appear”NESSviewer skips files it cannot use rather than interrupting you with error messages. That keeps a big folder load moving, but it means a file that fails simply is not there afterwards. If you drop twenty scans and get nineteen rows, this section is why.
| What you see | Likely cause |
|---|---|
| A .nessus file you loaded is not in the grid | The file could not be parsed — damaged or truncated XML, a file still being written, a file open in another program, or a permissions problem. It is skipped silently. |
| A .nessus file loaded but produced no row | The export contains no hosts. This happens with scans that found nothing or were aborted early. |
| A .zip loaded and nothing happened | The archive is damaged or locked, or it contains no .nessus files. |
| An XML file you expected to load did not | Only remediation plans are accepted as .xml. A STIG checklist, a test plan saved as .xml, or a .ckl renamed to .xml will not load. |
| A .ckl, .cklb, .csv, .json, .txt or .pdf did nothing | Those types are not supported. The drop is accepted and then ignored. |
| An unrelated spreadsheet was treated as a POA&M | Any .xlsx or .xlsm is assumed to be an eMASS POA&M export. Load spreadsheets deliberately rather than by dropping a folder. |
| Findings loaded but have no Description, Synopsis or Solution | The scan was exported from Security Center without XML Plugin Attributes. The findings are real; the explanatory text was never included. Re-export with that setting enabled. |
| A scan’s date column looks wrong | The scan recorded its end time in an unexpected format. The age-based business rules cannot be applied to that file. |