I have reports Quarter1.csv and Quarter2.csv. after I upload these two csv report I got
host="***" source="****" sourcetype="***" and those fields IP_Address,Plugin_Name,Severity,Protocol,Port...
See more...
I have reports Quarter1.csv and Quarter2.csv. after I upload these two csv report I got
host="***" source="****" sourcetype="***" and those fields IP_Address,Plugin_Name,Severity,Protocol,Port,Exploit,Synopsis,Description,Solution,See_Also,CVSS_V2_Base_Score,CVE,Plugin.
I want 3 reports base on joining with these 6 files:
IP_Address, Plugin_Name, Severity, Protocol, Port, Exploit,
| table IP_Address,Plugin_Name,Severity,Protocol,Port,Exploit,Synopsis,Description,Solution,See_Also,CVSS_V2_Base_Score,CVE,Plugin, status
First report: - if the event are in Quarter1.csv and Quarter2.csv. show status as "Active Vulnerability"
Second report:- if the event are in Quarter1.csv but not in Quarter2.csv. show status as "Fixed"
Third report:- if the event are not in Quarter1.csv but there are in Quarter2.csv. show status as "New Active Vulnerability"