查询条件说明
<p class="shortdesc">本章介绍如何自定义查询条件。</p>
<section class="section prereq"><div class="tasklabel"><h2 class="doc-tairway">前提条件</h2></div>
<ul class="ul" id="queryFields__ul_d2g_b5b_2sb">
<li class="li">您已创建安全日志审计实例。</li>
<li class="li">您已添加资产,并且资产已发送日志到平台上。</li>
</ul>
</section>
<section><div class="tasklabel"><h2 class="doc-tairway">操作步骤</h2></div><ol class="ol steps"><li class="li step stepexpand">
<span class="ph cmd">登录<a class="xref" href="https://www.ocftcloud.com/console/log-audit" target="_blank" rel="external noopener">安全日志审计SLA控制台</a>,进入<span class="keyword wintitle">实例列表</span>页面。</span>
</li><li class="li step stepexpand">
<span class="ph cmd">单击目标实例<span class="ph uicontrol"> 操作</span>列的<span class="ph uicontrol">管理</span>,进入安全日志审计控制台。</span>
<div class="itemgroup info">
<img class="image" id="queryFields__d22e53" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112057-1ecc508f988a.png" width="830">
</div>
</li><li class="li step stepexpand">
<span class="ph cmd">在页面上边栏选择<span class="ph uicontrol">事件管理</span>,在左侧菜单栏选择<span class="ph menucascade"><span class="ph uicontrol">事件</span><abbr> > </abbr><span class="ph uicontrol">自定义查询</span></span>,进入<span class="keyword wintitle">自定义查询</span>页面,设置查询条件。</span>
<div class="itemgroup info">
<img class="image" id="queryFields__image_h15_p1q_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1049c5a19881.png" width="830">
<div class="p">查询条件各配置项含义如下:<ul class="ul" id="queryFields__ul_nfx_pks_hsb">
<li class="li"><strong class="ph b">关键字</strong><p class="p">关键字查询索引字段包含客户ID、资产ID、客户管理帐号ID、事件级别、事件类型、事件名称、原始日志、效果信息描述、应用协议信息、源地址、源端口、目标地址。</p><p class="p">关键字查询支持模糊查询。例如,输入“Deny
udp”,事件中存在Deny或udp的事件都会被查询出来。</p></li>
<li class="li"><strong class="ph b">威胁等级</strong><table class="table" id="queryFields__table_bcz_sks_hsb"><caption></caption><colgroup><col style="width:24.69135802469136%"><col style="width:30.12345679012346%"><col style="width:45.18518518518519%"></colgroup><thead class="thead">
<tr class="row">
<th class="entry" id="queryFields__table_bcz_sks_hsb__entry__1">
<p class="p">威胁等级分类</p>
</th>
<th class="entry" id="queryFields__table_bcz_sks_hsb__entry__2">
<p class="p">威胁等级图标</p>
</th>
<th class="entry" id="queryFields__table_bcz_sks_hsb__entry__3">
<p class="p">说明</p>
</th>
</tr>
</thead><tbody class="tbody">
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__1 " rowspan="4">
<p class="p">低等级</p>
</td>
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_svn_cls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-19eb0e5493a7.png"></div>
</div>
</td>
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__3 " rowspan="4">
<p class="p">和安全有一定关系,需要管理员进行一定的关注。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_bnp_dls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-163db4b695b8.png"></div>
</div>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_xpd_2ls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1529ef969c5e.png"></div>
</div>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_uxl_2ls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-131a75669fe1.png"></div>
</div>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__1 " rowspan="3">
<p class="p">中等级</p>
</td>
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_gry_2ls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1b3ff80e9522.png"></div>
</div>
</td>
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__3 " rowspan="3">
<p class="p">潜在的攻击,不确定是否已造成实际危害、是否攻击。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_wqg_fls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-135b8bce9d54.png"></div>
</div>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_inr_fls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1469cf21969f.png"></div>
</div>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__1 " rowspan="4">
<p class="p">高等级</p>
</td>
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_lmb_gls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1c9dd2019952.png"></div>
</div>
</td>
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__3 " rowspan="4">
<p class="p">对系统已造成危害。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_slk_gls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1264d8ad9e82.png"></div>
</div>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_v2c_hls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-100177fb9d8e.png"></div>
</div>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_bcz_sks_hsb__entry__2 ">
<div class="p">
<div class="imageleft"><img class="image imageleft" id="queryFields__image_dwm_hls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1f0c969d9c29.png"></div>
</div>
</td>
</tr>
</tbody></table></li>
<li class="li"><strong class="ph b">事件类型</strong><table class="table" id="queryFields__table_jzk_lls_hsb"><caption></caption><colgroup><col><col></colgroup><thead class="thead">
<tr class="row">
<th class="entry" id="queryFields__table_jzk_lls_hsb__entry__1">
<p class="p">事件类型</p>
</th>
<th class="entry" id="queryFields__table_jzk_lls_hsb__entry__2">
<p class="p">说明</p>
</th>
</tr>
</thead><tbody class="tbody">
<tr class="row">
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__1 ">
<p class="p">原始事件</p>
</td>
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__2 ">
<p class="p">解析规则暂不支持解析的事件。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__1 ">
<p class="p">基本事件</p>
</td>
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__2 ">
<p class="p">经过平台分析后的事件。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__1 ">
<p class="p">关联事件</p>
</td>
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__2 ">
<p class="p">通过综合分析各种网络告警信息产生的新的安全告警事件。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__1 ">
<p class="p">聚合事件</p>
</td>
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__2 ">
<p class="p">通过算法把存在重复和并发关系的事件合并为一条事件。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__1 ">
<p class="p">三维关联事件</p>
</td>
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__2 ">
<p class="p">发送事件的资产存在弱点,并且该弱点与知识库中的弱点相对应,则平台将产生一条三维关联事件。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__1 ">
<p class="p">内部事件</p>
</td>
<td class="entry" headers="queryFields__table_jzk_lls_hsb__entry__2 ">
<p class="p">日志审计平台自身发生的事件,即通信服务器的日志事件。</p>
</td>
</tr>
</tbody></table></li>
</ul></div>
</div>
</li><li class="li step stepexpand">
<span class="ph cmd">单击<span class="ph uicontrol">更多条件</span>可设置更多查询条件。其中,对<span class="keyword wintitle">描述</span>和<span class="keyword wintitle">设备</span>页签的参数说明请参见下表。</span>
<div class="itemgroup info">
<table class="table" id="queryFields__table_wgq_rls_hsb"><caption></caption><colgroup><col style="width:21.978021978021978%"><col style="width:27.472527472527474%"><col style="width:50.54945054945055%"></colgroup><thead class="thead">
<tr class="row">
<th class="entry" id="queryFields__table_wgq_rls_hsb__entry__1">
<p class="p">页签</p>
</th>
<th class="entry" id="queryFields__table_wgq_rls_hsb__entry__2">
<p class="p">参数</p>
</th>
<th class="entry" id="queryFields__table_wgq_rls_hsb__entry__3">
<p class="p">说明</p>
</th>
</tr>
</thead><tbody class="tbody">
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__1 " rowspan="3">
<p class="p">描述</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">名称</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">事件详情中的事件名称。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">描述</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">事件详情中的事件描述。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">原始日志</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">事件详情中的原始事件。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__1 " rowspan="8">
<p class="p">设备</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">处理动作</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">与事件相关联的设备动作,如accept、deny等。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">危险级别</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">发送日志的设备特定评估的事件严重程度。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">报文</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">发送日志的设备获取到的报文内容。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">域名</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">与事件相关的设备的特定域名。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">源端口</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">与事件相关联的流量入接口。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">目标端口</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">与事件相关联的流量出接口。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">分类</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">发送事件的设备对事件的分类,如:管理事件、安全事件、系统事件等。</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__2 ">
<p class="p">分类ID</p>
</td>
<td class="entry" headers="queryFields__table_wgq_rls_hsb__entry__3 ">
<p class="p">发送事件的设备对事件的分类ID,如:管理事件为01、安全事件为02、系统事件为03等。</p>
</td>
</tr>
</tbody></table>
</div>
</li><li class="li step stepexpand">
<span class="ph cmd">页面提供的查询条件涵盖事件解析的基本参数条件,如果仍不满足查询要求,您也可以自定义条件查询。单击<span class="ph uicontrol">更多条件</span>,选择<span class="keyword wintitle">自定义</span>页签<img class="image" id="queryFields__image_b1q_zls_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1edd53da9e80.png" width="600"></span>
<ol type="a" class="ol substeps" id="queryFields__substeps_xkj_bms_hsb">
<li class="li substep substepexpand">
<span class="ph cmd">单击<img class="image" id="queryFields__image_c4z_bms_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1a27ebba9b91.png">图标,可以新增自定义查询条件。</span>
<div class="itemgroup info">
<p class="p">自定义条件查询格式:左侧框输入字段名参数,右侧框输入字段查询值。例如查询行为结果为成功的事件,左右两个输入框分别输入catOutcome和OK。更多查询条件字段请参见下表。</p>
<table class="table" id="queryFields__table_hdf_2ms_hsb"><caption></caption><colgroup><col><col><col><col></colgroup><thead class="thead">
<tr class="row">
<th class="entry" id="queryFields__table_hdf_2ms_hsb__entry__1">
<p class="p">字段名参数</p>
</th>
<th class="entry" id="queryFields__table_hdf_2ms_hsb__entry__2">
<p class="p">字段名</p>
</th>
<th class="entry" id="queryFields__table_hdf_2ms_hsb__entry__3">
<p class="p">参考查询值</p>
</th>
<th class="entry" id="queryFields__table_hdf_2ms_hsb__entry__4">
<p class="p">说明</p>
</th>
</tr>
</thead><tbody class="tbody">
<tr class="row">
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__1 ">
<p class="p">fileName</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__2 ">
<p class="p">文件名称</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__3 ">
<p class="p">system</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__4 ">
<p class="p">与事件相关的文件名称</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__1 ">
<p class="p">restartTure</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__2 ">
<p class="p">重启标记</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__3 ">
<p class="p">true</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__4 ">
<p class="p">系统重启则restartTrue=true</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__1 ">
<p class="p">loginOutTrue</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__2 ">
<p class="p">登出标记</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__3 ">
<p class="p">true</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__4 ">
<p class="p">登出、注销操作</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__1 ">
<p class="p">virusBaseVerion</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__2 ">
<p class="p">病毒库版本</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__3 ">
<p class="p">-</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__4 ">
<p class="p">指事件相关病毒库版本号</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__1 ">
<p class="p">sqlAction</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__2 ">
<p class="p">数据库操作字段</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__3 ">
<p class="p">-</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__4 ">
<p class="p">指数据库SQL操作动作</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__1 ">
<p class="p">accountLocked</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__2 ">
<p class="p">用户锁定标记</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__3 ">
<p class="p">true</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__4 ">
<p class="p">用户被锁定则accountLocked=true</p>
</td>
</tr>
<tr class="row">
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__1 ">
<p class="p">originator</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__2 ">
<p class="p">攻击源标记</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__3 ">
<p class="p">true</p>
</td>
<td class="entry" headers="queryFields__table_hdf_2ms_hsb__entry__4 ">
<p class="p">如果IP为攻击源,则定义originator=true</p>
</td>
</tr>
</tbody></table>
</div>
</li>
<li class="li substep substepexpand">
<span class="ph cmd">单击<img class="image" id="queryFields__image_f4z_jms_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1a5a75c59c52.png">图标,可以删除自定义查询条件。</span>
</li>
</ol>
</li><li class="li step stepexpand">
<span class="ph cmd">单击<span class="ph uicontrol">查询</span>。</span>
</li></ol></section>
<section class="section result" id="queryFields__result_j1n_4ms_hsb"><div class="tasklabel"><h2 class="doc-tairway">执行结果</h2></div>
<div class="p">在<span class="keyword wintitle">自定义查询</span>页面可得到查询结果,如下图所示。<img class="image" id="queryFields__image_skl_pms_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1e899cfa9790.png" width="830"></div>
<div class="p">在查询结果中,单击事件名称即可进入该事件的详情页面。不同类型事件的展示页面有所不同,但各类型的事件均包含时间信息、基本信息、来源信息、目标信息、事件分类信息和设备信息。<ul class="ul" id="queryFields__ul_rpv_5ms_hsb">
<li class="li"><strong class="ph b">基本事件详情</strong><img class="image" id="queryFields__image_rwh_wms_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1ac732129e87.png" width="700"></li>
<li class="li"><strong class="ph b">关联事件详情</strong><div class="p">单击<strong class="ph b">关联事件</strong>可以查看产生关联事件的原始事件列表。在列表中单击事件,即可查看原始事件详情。<img class="image" id="queryFields__image_zly_dns_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1916255291eb.png" width="600"></div></li>
<li class="li"><strong class="ph b">三维关联事件</strong><div class="p">三维关联通过资产、安全知识库、弱点库三个维度进行分析事件是否存在威胁。在基本事件的信息的基础上,增加了三维关联指示图,如下图所示。<img class="image" id="queryFields__image_dcw_gns_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-128811749fe4.png" width="830"></div><ul class="ul" id="queryFields__ul_u5r_jns_hsb">
<li class="li"><strong class="ph b">事件</strong>页签展示事件的基本详细信息。</li>
<li class="li"><strong class="ph b">威胁</strong>页签展示该事件的详细威胁信息,包括漏洞编号、漏洞名称、漏洞的详细描述、漏洞的类型以及漏洞的解决方案,如下图。<img class="image" id="queryFields__image_c3n_pns_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-15acc47b9cf6.png" width="830"></li>
<li class="li"><strong class="ph b">资产</strong>页签展示该事件对应资产的详细信息,如下图所示。<img class="image" id="queryFields__image_ywn_rns_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-14faf4fa9a4c.png" width="830"></li>
<li class="li"><strong class="ph b">弱点</strong>页签展示该资产对应的扫描结果中对应的弱点信息。内容包括弱点类型、危险级别、弱点类型url、参数值、资产名称等信息,如下图。弱点主要通过将扫描器手动导入或者通过扫描器授权连接在线导入。弱点导入详请请参见<u class="ph u">导入弱点库</u>。<img class="image" id="queryFields__image_pjp_5ns_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1f5354019a66.png" width="830"></li>
</ul></li>
<li class="li"><strong class="ph b">事件回放</strong><div class="p">在自定义查询结果页面,单击右上角的<strong class="ph b">回放</strong>,进入事件回放页面,页面会逐条显示当前查询结果中的事件,如下图所示。<img class="image" id="queryFields__image_aly_wns_hsb" src="https://obs-cn-shanghai.ocftcloud.com/pacloud/20222803112055-1c4d3e519fce.png" width="700"></div></li>
</ul></div>
</section>
提交成功!非常感谢您的反馈,我们会继续努力做到更好!