Vulnerability events cover finding ingestion, change events, and state reports. Vulnerability finding events are the primary model for third-party ingested scan results. State and change events (vulnerability.event, entity.event, vulnerability.state, entity.state) are produced by Dynatrace-generated vulnerability management only.
Entity change events are change events at the entity level. An event is generated whenever a vulnerability's affected entity undergoes a status or assessment change.
Query entity status change events.
fetch security.events| filter event.category == "VULNERABILITY_MANAGEMENT"| filter event.type == "VULNERABILITY_STATUS_CHANGE_EVENT"| filter event.level == "ENTITY"
General event information.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stableDisplay name: |
|
| array | resource stableList of attributes updated as part of the change event. Values in the list match a |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource stableMain reference point to which the event or data is related. Possible values are |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource stableName of the product providing this event. |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | resource stableType of event trigger (for example, whether it was generated by the system, ingested via API, or triggered by the user). |
|
| string | resource stableID of the user who triggered the event. If generated by Dynatrace, the value is |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
Information about the vulnerability at the entity level and its global parent, as well as its previous values.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string[] | resource **deprecatedUse |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string[] | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| boolean | experimentalDisplay name: | |
| timestamp | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | experimentalDisplay name: |
|
| string[] | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
Information about the vulnerability's affected entity and related entities.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| array | resource stableIDs of the processes that are currently affected by the vulnerability. |
|
| array | resource stableNames of the processes that are currently affected by the vulnerability. |
|
| string | resource stableID of the affected entity. |
|
| array | resource stableIDs of the management zones to which the affected entity belongs. |
|
| array | resource stableNames of the management zones to which the affected entity belongs. |
|
| string | resource stableName of the affected entity. |
|
| long | resource experimentalNumber of reachable data assets. |
|
| array | resource experimentalIDs of the data assets that can be reached by the affected entities of the vulnerability. |
|
| array | resource experimentalNames of the data assets that can be reached by the affected entities of the vulnerability. |
|
| string | resource stableType of affected entity. |
|
| string | resource stableID of the vulnerable component causing the vulnerability. |
|
| string | resource stableName of the vulnerable component causing the vulnerability. |
|
| string | resource experimentalPackage name of the vulnerable component causing the vulnerability. |
|
| string | resource stableShort name of the vulnerable component causing the vulnerability. |
|
| array | resource stableVulnerable functions detected, containing or causing the vulnerability. |
|
| array | resource experimentalVulnerable functions detected which Dynatrace can't tell if they're in use due to limited insights. |
|
| array | resource experimentalVulnerable functions detected which are not actively used. |
|
| Attribute | Type | Description | Examples |
|---|---|---|---|
| long | resource stableNumber of related applications. |
|
| array | resource stableIDs of the applications related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related databases. |
|
| array | resource stableIDs of the databases related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related hosts. |
|
| array | resource stableIDs of the hosts related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related Kubernetes clusters. |
|
| array | resource stableIDs of the Kubernetes clusters related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related Kubernetes workloads. |
|
| array | resource stableIDs of the Kubernetes workloads related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related services. |
|
| array | resource stableIDs of the services related to the vulnerability's affected entities. |
|
A vulnerability status change event at the entity level, generated when Dynatrace resolved the vulnerability for a specific process group after the library was updated.
{"event.kind": "SECURITY_EVENT","event.type": "VULNERABILITY_STATUS_CHANGE_EVENT","event.level": "ENTITY","event.group_label": "CHANGE_EVENT","event.provider": "Dynatrace","event.provider_product": "Runtime Vulnerability Analytics","event.description": "Status of S-8418 Apache MINA vulnerable to Deserialization of Untrusted Data for BloatedJavaSoftwareGroup-IG-1 has changed to RESOLVED","event.status_transition": "CLOSE","event.status": "RESOLVED","event.trigger.type": "DT_PLATFORM","event.trigger.user": "SYSTEM","event.change_list": ["vulnerability.resolution.status"],"vulnerability.id": "18269550188425474761","vulnerability.display_id": "S-8418","vulnerability.external_id": "DTV-2026-JAVA-0000321","vulnerability.title": "Apache MINA vulnerable to Deserialization of Untrusted Data","vulnerability.references.cve": ["CVE-2026-41635"],"vulnerability.risk.level": "CRITICAL","vulnerability.risk.score": 9.8,"vulnerability.resolution.status": "RESOLVED","vulnerability.previous.resolution.status": "OPEN","vulnerability.mute.status": "NOT_MUTED","vulnerability.stack": "CODE_LIBRARY","vulnerability.type": "Deserialization of Untrusted Data","vulnerability.technology": "JAVA","affected_entity.id": "PROCESS_GROUP-A15E7F3CFFF5B15F","affected_entity.name": "BloatedJavaSoftwareGroup-IG-1","affected_entity.type": "PROCESS_GROUP"}
Entity state events are historical vulnerability states reported at the entity level. The current vulnerability state per entity is exported to Grail regularly.
Query entity state events.
fetch security.events| filter event.category == "VULNERABILITY_MANAGEMENT"| filter event.type == "VULNERABILITY_STATE_REPORT_EVENT"| filter event.level == "ENTITY"
General event information.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource stableMain reference point to which the event or data is related. Possible values are |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource stableName of the product providing this event. |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
Information about the vulnerability at the entity level and its global vulnerability, with a focus on the affected entities
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string[] | resource **deprecatedUse |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string[] | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| boolean | experimentalDisplay name: | |
| timestamp | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
This section contains information about the vulnerability's affected and related entities.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| array | resource stableIDs of the processes that are currently affected by the vulnerability. |
|
| array | resource stableNames of the processes that are currently affected by the vulnerability. |
|
| string | resource stableID of the affected entity. |
|
| array | resource stableIDs of the management zones to which the affected entity belongs. |
|
| array | resource stableNames of the management zones to which the affected entity belongs. |
|
| string | resource stableName of the affected entity. |
|
| long | resource experimentalNumber of reachable data assets. |
|
| array | resource experimentalIDs of the data assets that can be reached by the affected entities of the vulnerability. |
|
| array | resource experimentalNames of the data assets that can be reached by the affected entities of the vulnerability. |
|
| string | resource stableType of affected entity. |
|
| string | resource stableID of the vulnerable component causing the vulnerability. |
|
| string | resource stableName of the vulnerable component causing the vulnerability. |
|
| string | resource experimentalPackage name of the vulnerable component causing the vulnerability. |
|
| string | resource stableShort name of the vulnerable component causing the vulnerability. |
|
| array | resource stableVulnerable functions detected, containing or causing the vulnerability. |
|
| array | resource experimentalVulnerable functions detected which Dynatrace can't tell if they're in use due to limited insights. |
|
| array | resource experimentalVulnerable functions detected which are not actively used. |
|
| Attribute | Type | Description | Examples |
|---|---|---|---|
| long | resource stableNumber of related applications. |
|
| array | resource stableIDs of the applications related to the vulnerability's affected entities. |
|
| array | resource stableNames of the applications related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related databases. |
|
| array | resource stableIDs of the databases related to the vulnerability's affected entities. |
|
| array | resource stableNames of the databases related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related hosts. |
|
| array | resource stableIDs of the hosts related to the vulnerability's affected entities. |
|
| array | resource stableNames of the hosts related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related Kubernetes clusters. |
|
| array | resource stableIDs of the Kubernetes clusters related to the vulnerability's affected entities. |
|
| array | resource stableNames of the Kubernetes clusters related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related Kubernetes workloads. |
|
| array | resource stableIDs of the Kubernetes workloads related to the vulnerability's affected entities. |
|
| array | resource stableNames of the Kubernetes workloads related to the vulnerability's affected entities. |
|
| long | resource stableNumber of related services. |
|
| array | resource stableIDs of the services related to the vulnerability's affected entities. |
|
| array | resource stableNames of the services related to the vulnerability's affected entities. |
|
A vulnerability state report event at the entity level, showing the current state of an open vulnerability for a specific process group and the vulnerable component it contains.
{"event.kind": "SECURITY_EVENT","event.type": "VULNERABILITY_STATE_REPORT_EVENT","event.level": "ENTITY","event.group_label": "STATE_REPORT","event.provider": "Dynatrace","event.provider_product": "Runtime Vulnerability Analytics","event.description": "S-5774 Potential to access user credentials from the log files when debug logging enabled state event reported","event.status": "OPEN","vulnerability.id": "10985110393469819658","vulnerability.display_id": "S-5774","vulnerability.external_id": "DTV-2019-JAVA-0000054","vulnerability.title": "Potential to access user credentials from the log files when debug logging enabled","vulnerability.references.cve": ["CVE-2019-10212"],"vulnerability.risk.level": "CRITICAL","vulnerability.risk.score": 9.8,"vulnerability.resolution.status": "OPEN","vulnerability.mute.status": "NOT_MUTED","vulnerability.stack": "CODE_LIBRARY","vulnerability.type": "Insertion of Sensitive Information into Log File","vulnerability.technology": "JAVA","affected_entity.id": "PROCESS_GROUP-A15E7F3CFFF5B15F","affected_entity.name": "BloatedJavaSoftwareGroup-IG-1","affected_entity.type": "PROCESS_GROUP","affected_entity.vulnerable_component.name": "io.undertow:undertow-core:1.4.18.Final","affected_entity.vulnerable_component.short_name": "undertow-core"}
Vulnerability change events are change events at the vulnerability level. An event is generated whenever a vulnerability undergoes a status or assessment change.
Query vulnerability status change events.
fetch security.events| filter event.category == "VULNERABILITY_MANAGEMENT"| filter event.type == "VULNERABILITY_STATUS_CHANGE_EVENT"
Query vulnerability assessment change events.
fetch security.events| filter event.category == "VULNERABILITY_MANAGEMENT"| filter event.type == "VULNERABILITY_ASSESSMENT_CHANGE_EVENT"
General event information.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stableDisplay name: |
|
| array | resource stableList of attributes updated as part of the change event. Values in the list match a |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource stableMain reference point to which the event or data is related. Possible values are |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource stableName of the product providing this event. |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | resource stableType of event trigger (for example, whether it was generated by the system, ingested via API, or triggered by the user). |
|
| string | resource stableID of the user who triggered the event. If generated by Dynatrace, the value is |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
Information about the vulnerability and its status and assessment changes.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string[] | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| boolean | experimentalDisplay name: | |
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
Information on changes regarding vulnerability's affected entities.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| long | resource stableNumber of affected entities. |
|
| long | resource stableNumber of affected hosts. |
|
| long | resource stableNumber of affected nodes. |
|
| long | resource deprecatedNumber of affected entities before the last change event. |
|
| long | resource deprecatedNumber of affected hosts before the last change event. |
|
| long | resource deprecatedNumber of affected Kubernetes nodes before the last change event. |
|
| long | resource deprecatedNumber of affected process groups before the last change event. |
|
| long | resource stableNumber of affected process groups. |
|
| array | resource stableTypes of affected entities. |
|
Information on changes regarding vulnerability's related entities.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| long | resource stableNumber of related applications. |
|
| long | resource stableNumber of related databases. |
|
| long | resource stableNumber of related hosts. |
|
| long | resource stableNumber of related Kubernetes clusters. |
|
| long | resource stableNumber of related Kubernetes workloads. |
|
| long | resource deprecatedNumber of related databases before the last change event. |
|
| long | resource stableNumber of related services. |
|
A vulnerability status change event at the vulnerability level, generated when Dynatrace automatically resolved a vulnerability after the affected library was removed from all process groups.
{"event.kind": "SECURITY_EVENT","event.type": "VULNERABILITY_STATUS_CHANGE_EVENT","event.level": "VULNERABILITY","event.group_label": "CHANGE_EVENT","event.provider": "Dynatrace","event.provider_product": "Runtime Vulnerability Analytics","event.description": "S-7593 Infinite loop in Apache MINA status has changed to RESOLVED","event.status_transition": "CLOSE","event.status": "RESOLVED","event.trigger.type": "DT_PLATFORM","event.trigger.user": "SYSTEM","event.change_list": ["vulnerability.resolution.status"],"vulnerability.id": "10969751970532702025","vulnerability.display_id": "S-7593","vulnerability.external_id": "DTV-2021-JAVA-0000102","vulnerability.title": "Infinite loop in Apache MINA","vulnerability.references.cve": ["CVE-2021-41973"],"vulnerability.risk.level": "MEDIUM","vulnerability.risk.score": 6.5,"vulnerability.resolution.status": "RESOLVED","vulnerability.previous.resolution.status": "OPEN","vulnerability.mute.status": "NOT_MUTED","vulnerability.stack": "CODE_LIBRARY","vulnerability.type": "Infinite Loop","vulnerability.technology": "JAVA"}
Vulnerability-finding events contain generic sections and fields like metadata, affected entity data and vulnerability data.
Meta-information on the vulnerability-finding event.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| timestamp | stableDisplay name: |
|
Information about the vulnerability that caused the vulnerability-finding event (vulnerability ID, description, risk level, and so on).
| Attribute | Type | Description | Examples |
|---|---|---|---|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
Information about the third-party product from where Dynatrace fetches data.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | resource experimentalThe feature of the product that performed the scan. |
|
| string | resource experimentalProduct name. |
|
| string | resource experimentalProduct vendor. |
|
Information about the scan that detected this vulnerability.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | resource experimentalUnique identifier of the scan. |
|
| string | resource experimentalName of the scan. |
|
| timestamp | resource experimentalTime when the scan was completed. |
|
| timestamp | resource experimentalTime when the scan was started. |
|
Risk assessment fields added by Dynatrace to normalize and rank the vulnerability across the environment.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
The following field sets are optional context that varies by finding source. Field definitions are shared across all security event types. See the field reference for container image fields, OS fields, Kubernetes fields, host fields, AWS resource fields, Azure resource fields, GCP fields, software component fields, and entry point fields.
This section contains container-image-specific data.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | resource experimentalDisplay name: |
|
| string | resource experimentalDisplay name: |
|
| string | resource experimentalDisplay name: |
|
| array | resource experimentalDisplay name: |
|
Information about the operating system on which the affected entity is running.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | resource experimentalDisplay name: |
|
| string | resource stableDisplay name: |
|
| string | resource experimentalDisplay name: |
|
| string | resource stableDisplay name: |
|
The associated host (if any) on which the vulnerability was found.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string[] | resource experimentalDisplay name: |
|
| ipAddress[] | resource experimentalDisplay name: |
|
| string | resource experimentalDisplay name: |
|
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | experimentalDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | experimentalDisplay name: |
|
Entity ID and Smartscape reference fields added by Dynatrace during ingest when the affected entity is matched in Smartscape. These fields are not present in externally ingested findings.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | resource **deprecatedThis field is deprecated and will be removed in the future. Use |
|
| string | resource **deprecatedThis field is deprecated and will be removed in the future. Use |
|
| string | resource **deprecatedThis field is deprecated and will be removed in the future. Use |
|
| string | resource **deprecatedThis field is deprecated and will be removed in the future.**Display name: |
|
| smartscapeId | resource stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource **deprecatedThis field is deprecated and will be removed in the future. Use |
|
| string | resource **deprecatedThis field is deprecated and will be removed in the future. Use |
|
The value of this field will be based on the value of one of the dt.smartscape.<type> fields. That means that the dt.smartscape_source.id and dt.smartscape.<type> fields will both be set to the same ID.
The value of this field will be based on the value of one of the dt.entity.<type> fields. This means that the dt.source_entity and dt.entity.<type> fields will both be set to the same ID.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| record[] | resource experimentalEntry points of a vulnerability. |
|
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | resource experimentalName of the function that executes the command, query, or similar with tainted parameters. |
|
| string | resource experimentalNamespace of the sink code function. |
|
| array | resource experimentalParameter types as defined in the method signature of the sink code function, which help distinguish in case of method overloads. For example, for a method with the |
|
A vulnerability finding links a vulnerability (typically a CVE) to an affected object—a container image, host, code artifact, or runtime process—and the component that introduces it. Vulnerability finding events carry scan results from both Dynatrace Runtime Vulnerability Analytics (library, code-level, and runtime vulnerabilities) and ingested findings from third-party scanners (Snyk, Qualys, Amazon Inspector, and others).
Unlike a detection finding, which reports suspicious activity, a vulnerability finding reports a known weakness in a scanned object. It does not imply that the weakness was exploited.
A vulnerability finding generated by Dynatrace Runtime Vulnerability Analytics, reporting a critical XML External Entity (XXE) vulnerability in the log4net library detected in a running easyTravel .NET process. Dynatrace resolves the process to a Smartscape entity and adds dt.smartscape_source.* during ingest.
{"event.kind": "SECURITY_EVENT","event.type": "VULNERABILITY_FINDING","product.vendor": "Dynatrace","product.name": "Runtime Vulnerability Analytics","product.feature": "Library Vulnerability Analytics","finding.id": "9ac6b6a2-5af1-35e1-97d9-1bd275e3d9c7","finding.title": "Vulnerability DTV-2021-DOTNET-0000002 of component log4net:1.2.10.0 was detected in IIS app pool dotNetFrontend_easyTravel_x64","finding.severity": "CRITICAL","finding.time.created": "2026-07-14T19:06:58.290441206Z","vulnerability.id": "DTV-2021-DOTNET-0000002","vulnerability.title": "XML External Entity attack in log4net","vulnerability.references.cve": ["CVE-2018-1285"],"vulnerability.cvss.base_score": 9.8,"vulnerability.risk.level": "CRITICAL","vulnerability.risk.score": 9.8,"vulnerability.remediation.status": "AVAILABLE","dt.security.risk.level": "CRITICAL","dt.security.risk.score": 9.8,"object.id": "PROCESS_GROUP_INSTANCE-8D4D208A40DAE589","object.type": "process_group_instance","object.name": "IIS app pool dotNetFrontend_easyTravel_x64","component.name": "log4net","component.version": "1.2.10.0","software_component.purl": "pkg:nuget/log4net@1.2.10.0","software_component.type": "library","software_component.version": "1.2.10.0","scan.id": "1e69f852-60bf-4b7c-a1bf-56c61d94fcdb","dt.smartscape_source.id": "PROCESS-8D4D208A40DAE589","dt.smartscape_source.type": "PROCESS"}
A vulnerability finding for a Debian curl package detected in a scanned container image, showing the affected object, the vulnerable component, container image coordinates, and the normalized Dynatrace risk level.
{"event.kind": "SECURITY_EVENT","event.type": "VULNERABILITY_FINDING","event.provider": "Snyk","product.vendor": "Snyk","product.name": "Snyk Container","finding.id": "c70138a6-7a32-426b-b074-a7c80dfb575e/curl/libcurl3-gnutls7.64.0-4+deb10u5","finding.title": "CVE-2023-38546","finding.severity": "LOW","finding.time.created": "2026-01-16T00:29:30.399000000Z","vulnerability.id": "SNYK-DEBIAN10-CURL-5955039","vulnerability.references.cve": ["CVE-2023-38546"],"vulnerability.cvss.base_score": 3.7,"dt.security.risk.level": "LOW","object.id": "ecr/unguard-frontend/sha256:dae2332cbc9c9e27d60d745085246ad23ec82e28ae9a1d19a80d38fb3ef94595","object.type": "CONTAINER_IMAGE","object.name": "unguard-frontend","component.name": "curl/libcurl3-gnutls","component.version": "7.64.0-4+deb10u5","container_image.registry": "ecr","container_image.repository": "unguard-frontend","container_image.tags": ["v0.8.0"],"container_image.digest": "sha256:794382e1c15d43a1ae7dc3e0f3bd47270c130f7371a440ebf64b602969f64a35","scan.id": "85e58e04-c80e-4a81-a2fc-9e0b36deec94"}
Vulnerability state events are historical states at the vulnerability level. The current vulnerability state is exported to Grail regularly.
Query vulnerability state events.
fetch security.events| filter event.category == "VULNERABILITY_MANAGEMENT"| filter event.type == "VULNERABILITY_STATE_REPORT_EVENT"| filter event.level == "VULNERABILITY"
General event information.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource stableMain reference point to which the event or data is related. Possible values are |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | resource stableName of the product providing this event. |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
Information about the vulnerability.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string[] | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| boolean | experimentalDisplay name: | |
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string[] | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| timestamp | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| double | stableDisplay name: |
|
| string | experimentalDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
| string | stableDisplay name: |
|
This section contains information on the vulnerability's affected and related entities.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| long | resource stableNumber of affected processes. |
|
| long | resource stableNumber of affected entities. |
|
| long | resource stableNumber of affected hosts. |
|
| long | resource stableNumber of affected nodes. |
|
| array | resource stableIDs of the management zones to which the affected entities belong. |
|
| array | resource stableNames of the management zones to which the affected entities belong. |
|
| long | resource stableNumber of processes of the process group. |
|
| long | resource stableNumber of affected process groups. |
|
| array | resource stableTypes of affected entities. |
|
| array | resource stableDynatrace IDs of the vulnerable components causing the vulnerability. |
|
| array | resource stableNames of the vulnerable components causing the vulnerability. | |
|
| array | resource stableVulnerable functions detected, containing or causing the vulnerability. |
|
| Attribute | Type | Description | Examples |
|---|---|---|---|
| long | resource stableNumber of related applications. |
|
| long | resource stableNumber of related databases. |
|
| long | resource stableNumber of related hosts. |
|
| long | resource stableNumber of related Kubernetes clusters. |
|
| long | resource stableNumber of related Kubernetes workloads. |
|
| long | resource stableNumber of related services. |
|
A vulnerability state report event at the vulnerability level, showing the current state of an open Node.js vulnerability across affected process groups.
{"event.kind": "SECURITY_EVENT","event.type": "VULNERABILITY_STATE_REPORT_EVENT","event.level": "VULNERABILITY","event.group_label": "STATE_REPORT","event.provider": "Dynatrace","event.provider_product": "Runtime Vulnerability Analytics","event.description": "S-7538 Improper Restriction of Operations within the Bounds of a Memory Buffer state event reported","event.status": "OPEN","vulnerability.id": "7331221926697449085","vulnerability.display_id": "S-7538","vulnerability.external_id": "CVE-2015-5380","vulnerability.title": "Improper Restriction of Operations within the Bounds of a Memory Buffer","vulnerability.references.cve": ["CVE-2015-5380"],"vulnerability.risk.level": "HIGH","vulnerability.risk.score": 7.5,"vulnerability.resolution.status": "OPEN","vulnerability.mute.status": "NOT_MUTED","vulnerability.stack": "SOFTWARE","vulnerability.type": "Improper Restriction of Operations within the Bounds of a Memory Buffer","vulnerability.technology": "NODE_JS","affected_entities.count": 1,"affected_entities.process_groups.count": 1,"affected_entities.vulnerable_components.names": ["Node.js 0.3.2"]}