Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/content/help/glossary.de.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ Verwaltete Integrationen, die Befunde und Befundgruppen aus DefectDojo in Issue-
## Universal Parser (Pro)
Eine generalisierte Parsing-Engine, die vom Universal Importer verwendet wird, um eingehende Scandaten zu interpretieren. Sie wendet für nicht unterstützte Formate eine einheitliche Normalisierungs- und Deduplizierungslogik an.
## Smart Upload (Pro)
Ein intelligenter Erfassungsworkflow, der automatisch bestimmt, wie Scan-Ergebnisse Assets oder Engagements zugeordnet werden sollen, wodurch die manuelle Konfiguration beim Import reduziert wird.
Ein intelligenter Erfassungsworkflow, der automatisch bestimmt, wie Scan-Ergebnisse Assets oder Engagements zugeordnet werden sollen, wodurch die manuelle Konfiguration beim Import reduziert wird. Wenn ein gescannter Host zu mehr als einem Asset gehört, wird in jedem passenden Asset eine Kopie des Findings erstellt.
## Executive Insights (Pro)
Business-orientierte Analysen auf hoher Ebene, die für Führungskräfte konzipiert sind und sich auf Trends, Risikoexposition und den Gesamtzustand des Programms konzentrieren statt auf einzelne Befunde.
## Priority Insights (Pro)
Expand Down
2 changes: 1 addition & 1 deletion docs/content/help/glossary.fr.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ Des intégrations gérées qui envoient les Constatations et les Groupes de Cons
## Universal Parser (Pro)
Un moteur d'analyse généraliste utilisé par l'Universal Importer pour interpréter les données de scan entrantes. Il applique une logique cohérente de normalisation et de déduplication aux formats non pris en charge.
## Smart Upload (Pro)
Un workflow d'ingestion intelligent qui détermine automatiquement comment les résultats de scan doivent être associés aux Actifs ou aux Engagements, réduisant la configuration manuelle lors de l'import.
Un workflow d'ingestion intelligent qui détermine automatiquement comment les résultats de scan doivent être associés aux Actifs ou aux Engagements, réduisant la configuration manuelle lors de l'import. Lorsqu'un hôte analysé appartient à plusieurs Actifs, une copie de la Constatation est créée dans chaque Actif correspondant.
## Executive Insights (Pro)
Des analyses de haut niveau, orientées métier, conçues pour un public dirigeant, mettant l'accent sur les tendances, l'exposition et la santé du programme plutôt que sur les Constatations individuelles.
## Priority Insights (Pro)
Expand Down
2 changes: 1 addition & 1 deletion docs/content/help/glossary.ja.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ DefectDojoが連携するすべてのツールのための、Pro UI(インポ
## Universal Parser(Pro)
Universal Importerが取り込まれるスキャンデータを解釈するために使用する、汎用的な解析エンジンです。サポート対象外の形式に対しても、一貫した正規化と重複排除のロジックを適用します。
## Smart Upload(Pro)
スキャン結果をアセットやエンゲージメントにどのようにマッピングするかを自動的に判断する、インテリジェントな取り込みワークフローであり、インポート時の手動設定を減らします。
スキャン結果をアセットやエンゲージメントにどのようにマッピングするかを自動的に判断する、インテリジェントな取り込みワークフローであり、インポート時の手動設定を減らします。スキャンされたホストが複数のアセットに属している場合、一致する各アセットに検出事項のコピーが作成されます。
## Executive Insights(Pro)
個々の検出事項ではなく、傾向、エクスポージャー、プログラムの健全性に焦点を当てた、経営層向けに設計された高レベルでビジネス志向の分析です。
## Priority Insights(Pro)
Expand Down
2 changes: 1 addition & 1 deletion docs/content/help/glossary.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ Managed integrations that push Findings and Finding Groups out of DefectDojo int
## Universal Parser (Pro)
A generalized parsing engine used by the Universal Importer to interpret incoming scan data. It applies consistent normalization and deduplication logic across unsupported formats.
## Smart Upload (Pro)
An intelligent ingestion workflow that automatically determines how scan results should be mapped to Assets or Engagements, reducing manual configuration during import.
An intelligent ingestion workflow that automatically determines how scan results should be mapped to Assets or Engagements, reducing manual configuration during import. When a scanned Host belongs to more than one Asset, a copy of the Finding is created in each matching Asset.
## Executive Insights (Pro)
High-level, business-oriented analytics designed for leadership audiences, focusing on trends, exposure, and program health rather than individual Findings.
## Priority Insights (Pro)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ Smart Upload ist ein spezialisierter Importer, der Berichte von **Tools für Inf

Smart Upload ist insofern besonders, als es Befunde aus einer Scan-Datei auf verschiedene Produkte aufteilen kann. Das ist im Kontext von Infrastruktur-Scans relevant, wo die Befunde viele unterschiedliche Teams betreffen, unterschiedliche implizite SLAs haben oder je nach Fundort in Ihrer Infrastruktur in getrennte Berichte aufgenommen werden müssen.

Smart Upload löst das, indem eingehende Befunde anhand der im Scan gefundenen Endpunkte sortiert werden. Zunächst müssen diese Befunde manuell zugewiesen oder aus einer Liste nicht zugewiesener Befunde in das richtige Produkt geleitet werden. Sobald ein Befund einem Produkt zugewiesen wurde, werden jedoch alle nachfolgenden Befunde, die denselben Endpunkt oder Host haben, an dasselbe Produkt gesendet.
Smart Upload löst das, indem eingehende Befunde anhand der im Scan gefundenen Endpunkte sortiert werden. Zunächst müssen diese Befunde manuell zugewiesen oder aus einer Liste nicht zugewiesener Befunde in das richtige Produkt geleitet werden. Sobald ein Befund einem Produkt zugewiesen wurde, werden jedoch alle nachfolgenden Befunde, die denselben Endpunkt oder Host haben, an dasselbe Produkt gesendet. Wenn dieser Host mit mehr als einem Produkt verknüpft ist, wird der Befund an jedes davon gesendet (siehe unten).

## Menüoptionen von Smart Upload

Expand Down Expand Up @@ -57,3 +57,11 @@ Immer wenn ein Befund einem neuen oder bestehenden Produkt zugewiesen wird, wird
### Verworfene Befunde

Wenn ein Befund verworfen wird, wird er aus der Liste der nicht zugewiesenen Befunde entfernt. Der Befund wird jedoch nicht dauerhaft gespeichert, sodass er bei nachfolgenden Scan-Uploads erneut in der Liste der nicht zugewiesenen Befunde erscheinen kann.

## Befunde, die zu mehr als einem Produkt passen

Ein einzelner Host oder Endpunkt kann zu mehr als einem Produkt gehören, zum Beispiel ein gemeinsam genutzter Load Balancer oder ein Host, den zwei Teams verfolgen. Wenn Smart Upload den Host eines eingehenden Befunds mehreren Produkten zuordnet, wählt es nicht eines aus: Es erstellt in **jedem** passenden Produkt eine Kopie des Befunds und legt jede Kopie im eigenen Smart-Upload-Engagement und -Test dieses Produkts ab.

Das ist beabsichtigt. Jedes Produkt behält ein vollständiges Bild der Schwachstellen, die die von ihm verwalteten Hosts betreffen, und Berichte, SLAs und Metriken bleiben für jedes Produkt unabhängig.

Die Zuordnung erfolgt anhand des im Scan gefundenen Host-Werts (der vollständig qualifizierte Domänenname, ersatzweise die IP-Adresse), sodass jedes Produkt, das diesen Host bereits besitzt, eine Kopie des Befunds erhält.
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ Smart Upload es un importador especializado que ingiere informes de **herramient

Smart Upload es único porque puede dividir los Hallazgos de un archivo de análisis en Productos independientes. Esto es relevante en un contexto de análisis de infraestructura, donde los Hallazgos pueden aplicarse a muchos equipos distintos, tener SLA implícitos diferentes, o necesitar incluirse en informes separados según el lugar de la infraestructura donde se descubrieron.

Smart Upload resuelve esto clasificando los hallazgos entrantes según los Endpoints descubiertos en el análisis. Al principio, esos Hallazgos deberán asignarse manualmente, o dirigirse al Producto correcto desde una lista de Hallazgos sin asignar. Sin embargo, una vez que un Hallazgo se ha asignado a un Producto, todos los Hallazgos posteriores que compartan un Endpoint o Host se enviarán a ese mismo Producto.
Smart Upload resuelve esto clasificando los hallazgos entrantes según los Endpoints descubiertos en el análisis. Al principio, esos Hallazgos deberán asignarse manualmente, o dirigirse al Producto correcto desde una lista de Hallazgos sin asignar. Sin embargo, una vez que un Hallazgo se ha asignado a un Producto, todos los Hallazgos posteriores que compartan un Endpoint o Host se enviarán a ese mismo Producto. Si ese Host está asociado a más de un Producto, el Hallazgo se envía a cada uno de ellos (consulte más abajo).

## Opciones del menú de Smart Upload

Expand Down Expand Up @@ -57,3 +57,11 @@ Cuando un Hallazgo se asigna a un Producto nuevo o existente, se colocará en un
### Hallazgos descartados

Si un Hallazgo se descarta (Disregard), se eliminará de la lista Unassigned Findings. Sin embargo, el Hallazgo no quedará registrado en memoria, por lo que las cargas de análisis posteriores pueden hacer que el Hallazgo vuelva a aparecer en la lista Unassigned Findings.

## Hallazgos que coinciden con más de un Producto

Un mismo Host o Endpoint puede pertenecer a más de un Producto, por ejemplo un balanceador de carga compartido o un host que dos equipos rastrean. Cuando Smart Upload hace coincidir el Host de un Hallazgo entrante con varios Productos, no elige uno solo: crea una copia de ese Hallazgo en **cada** Producto coincidente, colocando cada copia en el Compromiso y el Test de Smart Upload propios de ese Producto.

Esto es intencionado. Cada Producto conserva una imagen completa de las vulnerabilidades que afectan a los hosts que posee, y los informes, los SLA y las métricas de cada Producto permanecen independientes.

La coincidencia se basa en el valor de Host descubierto en el análisis (el nombre de dominio completo y, en su defecto, la dirección IP), de modo que cualquier Producto que ya posea ese Host recibe una copia del Hallazgo.
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ Smart Upload est un importateur spécialisé qui ingère les rapports provenant

Smart Upload a la particularité de pouvoir répartir les Constatations d'un fichier d'analyse entre plusieurs Produits distincts. Cela est pertinent dans un contexte d'analyse d'infrastructure, où les Constatations peuvent concerner de nombreuses équipes différentes, avoir des SLA implicites différents, ou devoir figurer dans des rapports séparés selon l'endroit où elles ont été découvertes dans votre infrastructure.

Smart Upload gère cela en triant les constatations entrantes en fonction des Points de terminaison découverts lors de l'analyse. Dans un premier temps, ces Constatations devront être assignées manuellement, ou dirigées vers le bon Produit depuis une liste de Constatations non assignées. Cependant, une fois qu'une Constatation a été assignée à un Produit, toutes les Constatations suivantes qui partagent un Point de terminaison ou un hôte seront envoyées vers ce même Produit.
Smart Upload gère cela en triant les constatations entrantes en fonction des Points de terminaison découverts lors de l'analyse. Dans un premier temps, ces Constatations devront être assignées manuellement, ou dirigées vers le bon Produit depuis une liste de Constatations non assignées. Cependant, une fois qu'une Constatation a été assignée à un Produit, toutes les Constatations suivantes qui partagent un Point de terminaison ou un hôte seront envoyées vers ce même Produit. Si cet hôte est associé à plusieurs Produits, la Constatation est envoyée vers chacun d'eux (voir ci-dessous).

## Smart Upload menu options

Expand Down Expand Up @@ -57,3 +57,11 @@ Chaque fois qu'une Constatation est assignée à un Produit nouveau ou existant,
### Disregarded Findings

Si une Constatation est ignorée, elle sera retirée de la liste des Constatations non assignées. Cependant, la Constatation ne sera pas enregistrée en mémoire, si bien que les téléversements d'analyse suivants peuvent faire réapparaître la Constatation dans la liste des Constatations non assignées.

## Constatations correspondant à plusieurs Produits

Un même hôte ou Point de terminaison peut appartenir à plusieurs Produits, par exemple un répartiteur de charge partagé ou un hôte suivi par deux équipes. Lorsque Smart Upload fait correspondre l'hôte d'une Constatation entrante à plusieurs Produits, il n'en choisit pas un seul : il crée une copie de cette Constatation dans **chaque** Produit correspondant, en plaçant chaque copie dans l'Engagement et le Test Smart Upload propres à ce Produit.

C'est intentionnel. Chaque Produit conserve une vue complète des vulnérabilités affectant les hôtes qu'il possède, et les rapports, les SLA et les métriques de chaque Produit restent indépendants.

La correspondance repose sur la valeur d'hôte découverte lors de l'analyse (le nom de domaine complet, à défaut l'adresse IP), de sorte que tout Produit possédant déjà cet hôte reçoit une copie de la Constatation.
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ aliases:

スマートアップロードの特徴は、スキャンファイル内の検出事項を複数の製品に分割できる点です。これはインフラストラクチャスキャンにおいて重要な機能であり、検出事項がさまざまなチームに関係していたり、暗黙のSLAが異なっていたり、インフラストラクチャ内で発見された場所に応じて別々のレポートに含める必要があったりする場合に役立ちます。

スマートアップロードは、スキャンで発見されたエンドポイントに基づいて受信した検出事項を振り分けることでこれを実現します。最初は、これらの検出事項を手動で割り当てるか、未割り当て検出事項一覧から適切な製品へ振り分ける必要があります。ただし、いったん検出事項が製品に割り当てられると、同じエンドポイントまたはホストを共有する以降のすべての検出事項は同じ製品に送られます。
スマートアップロードは、スキャンで発見されたエンドポイントに基づいて受信した検出事項を振り分けることでこれを実現します。最初は、これらの検出事項を手動で割り当てるか、未割り当て検出事項一覧から適切な製品へ振り分ける必要があります。ただし、いったん検出事項が製品に割り当てられると、同じエンドポイントまたはホストを共有する以降のすべての検出事項は同じ製品に送られます。このホストが複数の製品に関連付けられている場合、その検出事項はそれぞれの製品に送られます(下記を参照)。

## スマートアップロードメニューのオプション

Expand Down Expand Up @@ -57,3 +57,11 @@ aliases:
### 無視された検出事項

検出事項が無視されると、未割り当て検出事項一覧から削除されます。ただし、その検出事項はメモリに記録されないため、以降のスキャンアップロードによって再び未割り当て検出事項一覧に表示される可能性があります。

## 複数の製品に一致する検出事項

1つのホストまたはエンドポイントが複数の製品に属することがあります。たとえば、共有ロードバランサーや、2つのチームが追跡しているホストなどです。スマートアップロードが受信した検出事項のホストを複数の製品に一致させた場合、いずれか1つを選ぶのではなく、**一致するすべての**製品にその検出事項のコピーを作成し、各コピーをその製品専用のSmart Uploadエンゲージメントおよびテストに配置します。

これは意図的な動作です。各製品は、自身が保有するホストに影響する脆弱性の全体像を保持し、レポート、SLA、メトリクスは製品ごとに独立して保たれます。

一致はスキャンで検出されたホスト値(完全修飾ドメイン名、なければIPアドレス)に基づいて行われるため、そのホストをすでに保有しているすべての製品が検出事項のコピーを受け取ります。
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ Smart upload is a specialized importer that ingests reports from **infrastructur

Smart Upload is unique in that it can split Findings from a scan file into separate Assets. This is relevant in an Infrastructure scanning context, where the Findings may apply to many different teams, have different implicit SLAs, or need to be included in separate reports due to where they were discovered in your infrastructure.

Smart Upload handles this by sorting incoming findings based on the Endpoints discovered in the scan. At first, those Findings will need to be manually assigned, or directed into the correct Asset from an Unassigned Findings list. However, once a Finding has been assigned to an Asset, all subsequent Findings that share an Endpoint or Host will be sent to the same Asset.
Smart Upload handles this by sorting incoming findings based on the Endpoints discovered in the scan. At first, those Findings will need to be manually assigned, or directed into the correct Asset from an Unassigned Findings list. However, once a Finding has been assigned to an Asset, all subsequent Findings that share an Endpoint or Host will be sent to the same Asset. If that Host is associated with more than one Asset, the Finding is sent to each of them (see [Findings that match more than one Asset](#findings-that-match-more-than-one-asset) below).

## Smart Upload menu options

Expand Down Expand Up @@ -56,3 +56,11 @@ Whenever a Finding is assigned to a New or Existing Asset, it will be placed in
### Disregarded Findings

If a Finding is Disregarded it will be removed from the Unassigned Findings list. However, the Finding will not be recorded in memory, so subsequent scan uploads may cause the Finding to appear in the Unassigned Findings list again.

## Findings that match more than one Asset

A single Host or Endpoint can belong to more than one Asset, for example a shared load balancer, or a host that two teams both track. When Smart Upload matches an incoming Finding's Host to multiple Assets, it does not choose one: it creates a copy of that Finding in **every** matching Asset, placing each copy in that Asset's own Smart Upload Engagement and Test.

This is intentional. Each Asset keeps a complete picture of the vulnerabilities affecting the Hosts it owns, and reports, SLAs, and metrics for each Asset stay independent.

Matching is based on the Host value discovered in the scan (the fully qualified domain name, falling back to the IP address), so any Asset that already owns that Host receives a copy of the Finding.
Loading