Merge Rules

Source Trust Ranking 

Use source trust ranking to aggregate and then merge findings. The Reorder button allows you to specify the order of priority in which you trust the source data. This source trust ranking order is used during conflict resolution and when merging the findings from various sources. 

Custom Merge

Use custom merge to aggregate and then merge findings based on the selection of pre-defined attributes. The following pre-defined attributes of the Common Data Model are available for finding data aggregation. 

  • First Found
    • Min First Found
  • Last Found
    • Max Last Found
  • Status
    • Status of record with Latest Last Found or (STR).

The Add Attributes button allows you to specify the aforementioned aggregation attributes to be used for finding data aggregation. 

Use Case

Use Case Aggregated Record

Standard ID: CVE-456, Vendor ID: TID 123, Source: T, AssetID: 1, Last Scan Date: March 8, Status: Fixed, first found: March 1

Standard ID: CVE-456, Vendor ID: VID 54321, Source: V, AssetID: 1, Last Scan Date: March 5, Status: Open, first found: March 3

Last Detected = Latest (T & V)

Status - Status (Latest Last Scan Date)

First detected= Min(Scan Date)

CVE-456,

ETM Finding Id: ETM-001,

External Vendor Ids: (TID 123, VID 54321), Category: Vulnerability

Sources: [T, V]

Last Detected = March 8

Status - Fixed

First detected= March 1

Source information (sorted by latest found date) :

Source 1:

CVE-456, Vendor ID: TID 123, Source: T, AssetID: 1, Last Scan Date: March 8, Status: Fixed, first found: March 1

Source 2:

Standard ID: CVE-456, Vendor ID: VID 54321, Source: V, AssetID: 1, Last Scan Date: March 5, Status: Open, first found: March 3