CrowdStrike Falcon Cloud Security Connector

The CrowdStrike Falcon Cloud Security Connector ingests cloud asset and vulnerability data from CrowdStrike Falcon Cloud Security (CWP) into Qualys Enterprise TruRisk Management (ETM). This enables centralized visibility of cloud workloads and security risks within the ETM platform for improved risk analysis and prioritization.

The CrowdStrike Falcon Cloud Security Connector can be activated only after Unified Asset Inventory (UAI) is enabled for your subscription. Contact your Technical Account Manager (TAM) or Qualys Support to activate UAI and the CrowdStrike Falcon Cloud Security connector.

Connector Details

Here is a comprehensive overview of what the CrowdStrike Falcon Cloud Security Connector supports.

Vendor CrowdStrike
Product Name CrowdStrike Falcon Cloud Security
Connector Category CNAPP
Asset Types Supported
  • We are covering the following four Assets: 
    • Compute 
    • Serverless
    • Container Image
    • Container Instance.
  • These assets can be part of these three cloud providers -
    • AWS
    • GCP
    • Azure
  • Findings for Compute AWS and Container Images
Finding Types Supported Vulnerabilities
Supported Cloud Providers AWS, Azure, GCP
Version 1.0.0
Supported Version & Type SaaS (Latest)
Integration Method API Integration (REST / GraphQL)
Direction Unidirectional (CrowdStrike to Qualys)
Incremental Sync (Delta) Not Supported
Import of Installed Software Not Supported
Import of Source Tags Not Supported
Filters / Filter Query Not Supported

Connection Settings

User Roles and Permissions

To configure the connector, you must generate API credentials in the CrowdStrike Falcon console with the required permissions.

Required API permissions:

  • read: Vulnerabilities
  • read: Hosts
  • read: Assets
  • read: Host Groups
  • read: Cloud Security API Assets
  • read: Cloud Security API Detection
  • read: Falcon Container Image

Authentication Details

Provide the following credentials in the connector configuration screen.

Name Key Type Description
Auth URL auth_url String CrowdStrike authentication endpoint
Client ID client_id String API client identifier
Client Secret client_secret Encrypted API client secret
API Token api_token String CrowdStrike API token
Domain domain String Example: https://api.<domain>.crowdstrike.com

Creating an API Client

  1. Log in to the CrowdStrike Falcon console.
  2. Navigate to Support > API Clients and Keys.
  3. Select Add new API client.
  4. Provide a client name.
  5. Assign the required API scopes and permissions.
  6. Generate and save the API token.

Save the generated API token securely. The token cannot be retrieved again after creation.

Connector Configuration

Basic Details

  1. Log in to Qualys ETM.
  2. Navigate to Connectors > Integration.
  3. Locate CrowdStrike Falcon Cloud Security CWP.
  4. Click Manage.
  5. Provide a Name and Description.
  6. Enter the required authentication details.

Schedule

Schedules control the execution and scope of the connector.

Configure the following options:

  • Execution schedule
  • Supported asset types
  • Findings to ingest

Mapping Details

Data Model

The CrowdStrike Falcon Cloud Security connector provides default transformation mappings that convert CrowdStrike asset and vulnerability data into the Qualys ETM data model.

Transform Maps

Default transform maps are automatically applied during connector execution. You may clone or modify these maps in ETM if customization is required.


Profiles

Profiles control how the connector executes.

  1. Click + to create a new profile.
  2. Provide a Name and Description.
  3. Select the required Transform Map.
  4. Set Status (Active or Inactive).
  5. Configure a schedule (single run or recurring).

Scoring

Use the scoring screen to map vendor severity values to the Qualys Detection Score (QDS) scale from 0 to 100.

Identification Rules

Identification Rules determine how findings are associated with assets in ETM. Qualys CSAM provides default precedence rules for matching imported data.

These rules currently apply to Compute asset types. You may proceed without modifying them.

How Does a Connection Work?

When the connector runs (scheduled or on-demand), it authenticates with the CrowdStrike API and retrieves selected asset classes and vulnerability findings. The data is then transformed using the default ETM mappings and imported into the ETM inventory.

In the Connector screen, your newly configured connector will appear with the state Processed once execution completes.

Connector States

  • Registered – Connector created successfully.
  • Scheduled – Connector scheduled for execution.
  • Processing – Data is currently being fetched.
  • Processed – Data ingestion completed.

The entire import process may take several hours depending on the data volume.

Viewing Assets and Findings in ETM

After ingestion, view imported data in ETM.

  • Assets
    Enterprise TruRisk Management > Inventory > Assets > All Assets
    Filter using: inventory.source:"CrowdStrike Falcon Cloud Security"
  • Findings
    Enterprise TruRisk Management > Risk Management > Findings > Vulnerability
    Filter using: finding.vendorProductName:"CrowdStrike Falcon Cloud Security"

Additional Resources

Additional Information related to the Crowdstrike Connector.

API Reference

Here are the APIs executed for the Crowdstrike connection.

Name

Filters

Endpoint

Auth API

N/A     
https://api.<domain>.crowdstrike.com/oauth2/token

Fetch Vulnerabilities API

Finding Type:

Vulnerabilities

/spotlight/queries/vulnerabilities/v1

/spotlight/entities/vulnerabilities/v2

/container-security/combined/images/detail/v1

Fetch Devices associated with Vulnerabilities /devices/queries/devices/v1
Fetch Assets/Resources API Asset type: Hosts

/cloud-security-assets/queries/resources/v1

/cloud-security-assets/entities/resources/v1

Fetch Containers Asset type: Containers

/container-security/combined/containers/v1

Asset type: Container Images /image-assessment/entities/reports/v2

Crowdstrike CWP Falcon Cloud Security Transformation Map

The default transformation map for different asset classes, configured for the Crowdstrike Cloud Security connector is fetched from the database and utilized during the execution of the connector profile to perform data transformation.

Compute

AWS EC2 instanceAWS EC2 instance

Source Field Target Field
cloud_provider asset.assetDetail.cloudInfo.provider
id asset.assetHeader.vendorAssetId
creation_time asset.assetDetail.sourceCreatedAt
account_id asset.assetDetail.cloudInfo.accountId
account_name asset.assetDetail.cloudInfo.accountName
updated_at asset.assetDetail.sourceUpdatedAt
resource_type_name asset.assetDetail.computeAssetClass.services[].name
resource_name asset.assetDetail.name
resource_id asset.assetDetail.hostIdentity.hostname
resource_url asset.assetDetail.cloudInfo.providerUrl
resource_id asset.assetHeader.externalAssetId
region asset.assetDetail.cloudInfo.region
zone asset.assetDetail.cloudInfo.availabilityZone
cloud_context.host.state asset.assetDetail.computeAssetClass.cloudInstance.state
externalTags asset.assetDetail.externalTags
configuration.architecture asset.assetDetail.computeAssetClass.gpu[].architecture
configuration.vpcId asset.assetDetail.computeAssetClass.cloudInstance.vpcId
configuration.privateDnsName asset.assetDetail.network[0].privateDnsName
configuration.privateDnsName asset.assetDetail.network[0].publicDnsName
configuration.privateIpAddress asset.assetDetail.network[0].ipv4Addresses[0]
configuration.networkInterfaces[0].macAddress asset.assetDetail.computeAssetClass.cloudInstance.macAddress
configuration.networkInterfaces[].macAddress asset.assetDetail.network[].macAddress
configuration.instanceType asset.assetDetail.computeAssetClass.cloudInstance.type
cloud_context.instance_id asset.assetDetail.computeAssetClass.cloudInstance.id
configuration.subnetId asset.assetDetail.computeAssetClass.cloudInstance.subnetId
configuration.imageId asset.assetDetail.computeAssetClass.cloudInstance.imageId
configuration.blockDeviceMappings[0].ebs.volumeId asset.assetDetail.typedAttributes.&
arn asset.assetDetail.typedAttributes.&
cloud_context.host.platform_name asset.assetDetail.operatingSystem.name
configuration.networkInterfaces[0].networkInterfaceId asset.assetDetail.computeAssetClass.cloudInstance.networkInterfaceId
cloud_context.instance_state asset.assetHeader.status

Azure VM InstanceAzure VM Instance

Source Field Target Field
cloud_provider asset.assetDetail.cloudInfo.provider
id asset.assetHeader.vendorAssetId
creation_time asset.assetDetail.sourceCreatedAt
account_id asset.assetDetail.cloudInfo.accountId
account_name asset.assetDetail.cloudInfo.accountName
tenant_id asset.assetDetail.cloudInfo.tenantId
updated_at asset.assetDetail.sourceUpdatedAt
resource_type_name asset.assetDetail.computeAssetClass.services[].name
resource_name asset.assetDetail.name
resource_url asset.assetDetail.cloudInfo.providerUrl
resource_id asset.assetHeader.externalAssetId
region asset.assetDetail.cloudInfo.region
resource_group asset.assetDetail.computeAssetClass.cloudInstance.resourceGroupName
cloud_context.host.state asset.assetDetail.computeAssetClass.cloudInstance.state
externalTags asset.assetDetail.externalTags
configuration.properties.networkProfile.networkInterfaces[0].id asset.assetDetail.computeAssetClass.cloudInstance.networkInterfaceId
configuration.properties.osProfile.computerName asset.assetDetail.computeAssetClass.cloudInstance.hostName
configuration.properties.extended.instanceView.osName asset.assetDetail.operatingSystem.name
configuration.properties.extended.instanceView.osVersion asset.assetDetail.operatingSystem.version
configuration.properties.osProfile.computerName asset.assetDetail.hostIdentity.hostname
configuration.properties.vmId asset.assetDetail.computeAssetClass.cloudInstance.id
configuration.properties.storageProfile.osDisk.managedDisk.storageAccountType asset.assetDetail.computeAssetClass.storage[0].type
configuration.properties.storageProfile.osDisk.managedDisk.id asset.assetDetail.computeAssetClass.cloudInstance.imageId
cloud_context.insights.details.publicIpAddress.context.interfaces[0].public_ip asset.assetDetail.network[0].publicIpv4Addresses[0]
cloud_context.instance_state asset.assetHeader.status

Compute GCP VMCompute GCP VM

Source Field Target Field
cloud_provider asset.assetDetail.cloudInfo.provider
id asset.assetHeader.vendorAssetId
creation_time asset.assetDetail.sourceCreatedAt
project_id asset.assetDetail.cloudInfo.accountId
account_name asset.assetDetail.cloudInfo.accountName
updated_at asset.assetDetail.sourceUpdatedAt
resource_type_name asset.assetDetail.computeAssetClass.services[].name
configuration.name asset.assetDetail.name
resource_url asset.assetDetail.cloudInfo.providerUrl
resource_id asset.assetHeader.externalAssetId
resource_id asset.assetDetail.hostIdentity.hostname
cloud_context.legacy_resource_id asset.assetDetail.computeAssetClass.cloudInstance.id
region asset.assetDetail.cloudInfo.region
cloud_context.host.state asset.assetDetail.computeAssetClass.cloudInstance.state
externalTags asset.assetDetail.externalTags
configuration.networkInterfaces[0].subnetwork asset.assetDetail.computeAssetClass.cloudInstance.networkInterfaceId
configuration.networkInterfaces[0].networkIP asset.assetDetail.network[0].ipv4Addresses[0]
cloud_context.instance_state asset.assetHeader.status

OCI VM InstanceOCI VM Instance

Source Field Target Field
cloud_provider asset.assetDetail.cloudInfo.provider
id asset.assetHeader.vendorAssetId
creation_time asset.assetDetail.sourceCreatedAt
account_id asset.assetDetail.cloudInfo.accountId
updated_at asset.assetDetail.sourceUpdatedAt
resource_type_name asset.assetDetail.computeAssetClass.services[].name
resource_url asset.assetDetail.cloudInfo.providerUrl
resource_id asset.assetHeader.externalAssetId
region asset.assetDetail.cloudInfo.region
cloud_context.instance_state asset.assetDetail.computeAssetClass.cloudInstance.state
externalTags asset.assetDetail.externalTags
configuration.shape asset.assetDetail.computeAssetClass.cloudInstance.type
configuration.imageId asset.assetDetail.computeAssetClass.cloudInstance.imageId
configuration.displayName asset.assetDetail.name
cloud_context.instance_state asset.assetHeader.status
resource_id asset.assetDetail.hostIdentity.hostname
CONSTANT: "oci-compute-instance" asset.assetHeader.assetTypeName

Container ImageContainer Image

SourceField TargetField

name

asset.assetDetail.name

id

asset.assetHeader.vendorAssetId

type

asset.assetHeader.assetTypeName

asset_unique_id

asset.assetDetail.typedAttributes.&

data.ImageName.value

asset.assetDetail.containerImageAssetClass.name

data.CloudAccount.id

asset.assetDetail.cloudInfo.accountId

data.CloudAccount.name

asset.assetDetail.cloudInfo.accountName

data.ImageName.value

asset.assetDetail.containerImageAssetClass.imageTagReferences[].name

data.RepositoryName.value

asset.assetDetail.containerImageAssetClass.repository

data.RepositoryName.value

asset.assetDetail.containerImageAssetClass.imageTagReferences[].repository

data.ImageDigest.value

asset.assetDetail.containerImageAssetClass.digest

data.ImageSize.value

asset.assetDetail.containerImageAssetClass.sizeInBytes

data.ImageSize.value

asset.assetDetail.containerImageAssetClass.layers[].sizeInBytes

data.RepositoryUri.value

asset.assetDetail.containerImageAssetClass.registry

data.ImageTags.value

asset.assetDetail.containerImageAssetClass.tag

data.RepositoryUri.value

asset.assetDetail.containerImageAssetClass.imageTagReferences[].registry

data.ImageTags.value

asset.assetDetail.containerImageAssetClass.imageTagReferences[].tag

data.ImageDigest.value

asset.assetDetail.containerImageAssetClass.layers[].digest

data.AssetUniqueId.value

asset.assetHeader.externalAssetId

data.ConsoleUrlLink.value

asset.assetDetail.cloudInfo.providerUrl

data.FirstSeen.value (DATE_FORMAT)

asset.assetDetail.sourceCreatedAt

data.LastSeen.value (DATE_FORMAT)

asset.assetDetail.sourceUpdatedAt

vulnerabilities[].data.Inventory.name

findingGroup.findings[].asset.assetName

vulnerabilities[].data.Inventory.asset_unique_id

findingGroup.findings[].asset.externalAssetId

vulnerabilities[].data.CVE.data.PublicName.value

findingGroup.findings[].name

vulnerabilities[].data.CVE.data.Id.value

findingGroup.findings[].externalFindingId

vulnerabilities[].data.SourceLink.value

findingGroup.findings[].findingURL

vulnerabilities[].data.FirstSeen.value (DATE_FORMAT)

findingGroup.findings[].firstFoundOn

vulnerabilities[].data.CVE.data.LastModifiedDate.value (DATE_FORMAT)

findingGroup.findings[].lastFoundOn

vulnerabilities[].data.data.FirstSeen.value (DATE_FORMAT)

findingGroup.findings[].ingestedOn

vulnerabilities[].data.CveId.value (FUNCTION_PICKER REGEX_MATCH_RETURN)

findingGroup.findings[].findingType.vulnerability.cveId

vulnerabilities[].data.HasExploit.value

findingGroup.findings[].findingType.vulnerability.isExploitAvailable

vulnerabilities[].data.Description.value

findingGroup.findings[].description

vulnerabilities[].data.PatchAvailable.value (FUNCTION_PICKER LOOKUP)

findingGroup.findings[].findingType.vulnerability.isPatchAvailable

vulnerabilities[].data.CvssVector.value

findingGroup.findings[].cvss.vector

vulnerabilities[].data.CvssSeverity.value (FUNCTION_PICKER LOOKUP)

findingGroup.findings[].severity

vulnerabilities[].data.CvssScore.value

findingGroup.findings[].riskScore

Container Instance

AWS ContainerAWS Container

SourceField TargetField
name asset.assetDetail.name
id asset.assetHeader.vendorAssetId
asset_unique_id asset.assetDetail.typedAttributes.asset_unique_id
data.RiskLevel.value asset.assetDetail.typedAttributes.RiskLevel
data.OrcaScore.value asset.assetDetail.typedAttributes.OrcaScore
data.AssetUniqueId.value asset.assetHeader.externalAssetId
data.ConsoleUrlLink.value asset.assetDetail.cloudInfo.providerUrl
data.cloudAccount.id asset.assetDetail.cloudInfo.accountId
data.CloudAccount.name asset.assetDetail.cloudInfo.accountName
data.Arn.value asset.assetDetail.containerInstanceAssetClass.id
data.Status.value asset.assetDetail.containerInstanceAssetClass.status
data.ImageName.value asset.assetDetail.containerInstanceAssetClass.Image.name
data.FirstSeen.value (DATE_FORMAT) asset.assetDetail.sourceCreatedAt
data.LastSeen.value (DATE_FORMAT) asset.assetDetail.sourceUpdatedAt
vulnerabilities[].data.Inventory.name findingGroup.findings[].asset.assetName
vulnerabilities[].data.Inventory.asset_unique_id findingGroup.findings[].asset.externalAssetId
vulnerabilities[].data.CVE.data.PublicName.value findingGroup.findings[].name
vulnerabilities[].data.CVE.data.Id.value findingGroup.findings[].externalFindingId
vulnerabilities[].data.SourceLink.value findingGroup.findings[].findingURL
vulnerabilities[].data.FirstSeen.value (DATE_FORMAT) findingGroup.findings[].firstFoundOn
vulnerabilities[].data.CVE.data.LastModifiedDate.value (DATE_FORMAT) findingGroup.findings[].lastFoundOn
vulnerabilities[].data.data.FirstSeen.value (DATE_FORMAT) findingGroup.findings[].ingestedOn
vulnerabilities[].data.CveId.value (FUNCTION_PICKER REGEX_MATCH_RETURN) findingGroup.findings[].findingType.vulnerability.cveId
vulnerabilities[].data.HasExploit.value findingGroup.findings[].findingType.vulnerability.isExploitAvailable
vulnerabilities[].data.Description.value findingGroup.findings[].description
vulnerabilities[].data.PatchAvailable.value (FUNCTION_PICKER LOOKUP) findingGroup.findings[].findingType.vulnerability.isPatchAvailable
vulnerabilities[].data.CvssVector.value findingGroup.findings[].cvss.vector
vulnerabilities[].data.CvssSeverity.value (FUNCTION_PICKER LOOKUP) findingGroup.findings[].severity
vulnerabilities[].data.CvssScore.value findingGroup.findings[].riskScore
vulnerabilities[].data.SourceLink.value findingGroup.findings[].findingDetectionURL

Container Instance

GCP CloudRunGCP CloudRun

SourceField TargetField
name asset.assetDetail.name
id asset.assetHeader.vendorAssetId
asset_unique_id asset.assetDetail.typedAttributes.asset_unique_id
data.RiskLevel.value asset.assetDetail.typedAttributes.RiskLevel
data.OrcaScore.value asset.assetDetail.typedAttributes.OrcaScore
data.AssetUniqueId.value asset.assetDetail.containerInstanceAssetClass.id
data.CloudAccount.id asset.assetDetail.cloudInfo.accountId
data.CloudAccount.name asset.assetDetail.cloudInfo.accountName
data.Status.value asset.assetDetail.containerInstanceAssetClass.status
data.Name.value asset.assetDetail.containerInstanceAssetClass.host.name
data.PrivateClusterConfig.value.privateEndpoint asset.assetDetail.containerInstanceAssetClass.host.ipAddress
data.ImageName.value asset.assetDetail.containerInstanceAssetClass.Image.name
data.AssetUniqueId.value asset.assetHeader.externalAssetId
data.ConsoleUrlLink.value asset.assetDetail.cloudInfo.providerUrl
data.FirstSeen.value (DATE_FORMAT) asset.assetDetail.sourceCreatedAt
data.LastSeen.value (DATE_FORMAT) asset.assetDetail.sourceUpdatedAt
vulnerabilities[].data.Inventory.name findingGroup.findings[].asset.assetName
vulnerabilities[].data.Inventory.asset_unique_id findingGroup.findings[].asset.externalAssetId
vulnerabilities[].data.CVE.data.PublicName.value findingGroup.findings[].name
vulnerabilities[].data.CVE.data.Id.value findingGroup.findings[].externalFindingId
vulnerabilities[].data.SourceLink.value findingGroup.findings[].findingURL
vulnerabilities[].data.FirstSeen.value (DATE_FORMAT) findingGroup.findings[].firstFoundOn
vulnerabilities[].data.CVE.data.LastModifiedDate.value (DATE_FORMAT) findingGroup.findings[].lastFoundOn
vulnerabilities[].data.data.FirstSeen.value (DATE_FORMAT) findingGroup.findings[].ingestedOn
vulnerabilities[].data.CveId.value findingGroup.findings[].findingType.vulnerability.cveId
vulnerabilities[].data.HasExploit.value findingGroup.findings[].findingType.vulnerability.isExploitAvailable
vulnerabilities[].data.Description.value findingGroup.findings[].description
vulnerabilities[].data.PatchAvailable.value (FUNCTION_PICKER LOOKUP) findingGroup.findings[].findingType.vulnerability.isPatchAvailable
vulnerabilities[].data.CvssVector.value findingGroup.findings[].cvss.vector
vulnerabilities[].data.CvssSeverity.value (FUNCTION_PICKER LOOKUP) findingGroup.findings[].severity
vulnerabilities[].data.CvssScore.value findingGroup.findings[].riskScore
vulnerabilities[].data.SourceLink.value findingGroup.findings[].findingDetectionURL

Serverless

AWS Lambda functionAWS Lambda function

Source Field Target Field
resource_type_name asset.assetDetail.serverlessAssetClass.serviceName
id asset.assetHeader.vendorAssetId
arn asset.assetDetail.name
arn asset.assetHeader.externalAssetId
first_seen asset.assetDetail.sourceCreatedAt
region asset.assetDetail.cloudInfo.region
account_id asset.assetDetail.cloudInfo.accountId
account_name asset.assetDetail.cloudInfo.accountName
updated_at asset.assetDetail.sourceUpdatedAt
cloud_provider asset.assetDetail.cloudInfo.provider
resource_url asset.assetDetail.cloudInfo.providerUrl
externalTags asset.assetDetail.externalTags
configuration.functionName asset.assetDetail.serverlessAssetClass.functionName
configuration.runtime asset.assetDetail.serverlessAssetClass.runtime
configuration.state asset.assetHeader.status

Azure FunctionAzure Function

Source Field Target Field
resource_type_name asset.assetDetail.serverlessAssetClass.serviceName
id asset.assetHeader.vendorAssetId
resource_name asset.assetDetail.name
resource_id asset.assetHeader.externalAssetId
first_seen asset.assetDetail.sourceCreatedAt
region asset.assetDetail.cloudInfo.region
subscription_id asset.assetDetail.cloudInfo.accountId
account_name asset.assetDetail.cloudInfo.accountName
tenant_id asset.assetDetail.cloudInfo.tenantId
updated_at asset.assetDetail.sourceUpdatedAt
cloud_provider asset.assetDetail.cloudInfo.provider
resource_url asset.assetDetail.cloudInfo.providerUrl
externalTags asset.assetDetail.externalTags
configuration.name asset.assetDetail.serverlessAssetClass.functionName
configuration.state asset.assetHeader.status

GCP FunctionGCP Function

Source Field Target Field
resource_type_name asset.assetDetail.serverlessAssetClass.serviceName
id asset.assetHeader.vendorAssetId
resource_id asset.assetDetail.name
resource_id asset.assetHeader.externalAssetId
first_seen asset.assetDetail.sourceCreatedAt
region asset.assetDetail.cloudInfo.region
project_id asset.assetDetail.cloudInfo.accountId
account_name asset.assetDetail.cloudInfo.accountName
updated_at asset.assetDetail.sourceUpdatedAt
cloud_provider asset.assetDetail.cloudInfo.provider
externalTags asset.assetDetail.externalTags
configuration.name asset.assetDetail.serverlessAssetClass.functionName
configuration.status.url asset.assetDetail.serverlessAssetClass.functionURL

Vulnerability Compute AWS EC2Vulnerability Compute AWS EC2

Source Field Target Field
cve.id findingGroup.findings[].findingType.vulnerability.cveId
vulnerability_id findingGroup.findings[].name
created_timestamp findingGroup.findings[].firstFoundOn
updated_timestamp findingGroup.findings[].lastFoundOn
status findingGroup.findings[].findingStatus
confidence findingGroup.findings[].typeDetected
cve.severity findingGroup.findings[].severity
cve.types[0] findingGroup.findings[].category
cve.cwes[] findingGroup.findings[].findingType.vulnerability.cweIds[]
cve.description findingGroup.findings[].description
cve.references[] findingGroup.findings[].references[]
closed_timestamp findingGroup.findings[].lastFixedOn
apps[].product_name_normalized findingGroup.findings[].product.name
apps[].product_name_version findingGroup.findings[].product.version
apps[].vendor_normalized findingGroup.findings[].product.vendor
host_info.instance_id asset.assetHeader.externalAssetId
id findingGroup.findings[].externalFindingId
id asset.assetHeader.vendorAssetId
resource_name asset.assetDetail.name
resource_id asset.assetDetail.hostIdentity.hostname
id findingGroup.findings[].id