On Sun, Jun 02, 2002 at 08:21:33PM +0200, Florian Weimer wrote:
> Can you point me to a description of the NBE format, please?  Is it
> already stable?  Does it make sense to base custom reporting scripts
> on data exported from Nessus in this format?

The data is :

<category>|<subnet>|<host>|[Info]

Where :

<category> is either "timestamps" or "results".

If <category> is timestamps, then the format of [info] is :

<action>|<time>|

with
        <action> = scan_start, scan_end, host_start or host_end
if action is scan_{start,end} then the fields subnet and host are empty.

If <category> is "results", then [info] is plain old .nsr, that is :
<port>|<plugin_id>|<category>|<report>

With <port> being the port in plain text (ie: "tcpmux (1/tcp)"),
<plugin_id> is the ID of the plugin which generated an alert, <category>
is one of {Security Hole, Security Warning, Security Note} and <report>
is the report, with return carriages and newlines escaped as '\r' and '\n'




                                -- Renaud

Reply via email to