Nozomi Vantage Attribute Reference
Focus
Focus
Device Security

Nozomi Vantage Attribute Reference

Table of Contents

Nozomi Vantage Attribute Reference

This reference lists the attributes that Device Security collects from Nozomi Vantage, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Nozomi Vantage, it imports OT and network visibility data to enrich the device inventory. The attributes in this reference cover device identification, network details, and vulnerability findings collected from the Nozomi Vantage platform.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Device Attributes

Device Security collects device attributes from Nozomi Vantage. The following table lists each Nozomi Vantage attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Nozomi Vantage Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
attributes.name
nozomi_vantage.attributes.name
hostname
Name of the device
attributes.mac_address
nozomi_vantage.attributes.mac_address
id; MAC Address
MAC address
attributes.ip
nozomi_vantage.attributes.ip
IP Address
IP
attributes.last_activity_time
nozomi_vantage.attributes.last_activity_time
Last Activity
Last activity time
attributes.firmware_version
nozomi_vantage.attributes.firmware_version
latest_firmware_version
Firmware version running on the device
attributes.os
nozomi_vantage.attributes.os
raw_os
OS
attributes.serial_number
nozomi_vantage.attributes.serial_number
Serial Number
Serial number
attributes.software_inventory
—
third_party_learned_installed_software
Software inventory
attributes.vendor
nozomi_vantage.attributes.vendor
Vendor
Device vendor
attributes.zones
nozomi_vantage.attributes.zones
Zone
Zones
attributes._asset_kb_id
nozomi_vantage.attributes._asset_kb_id
—
Asset kb ID
attributes.appliance_hosts
nozomi_vantage.attributes.appliance_hosts
—
Appliance hosts
attributes.capture_device
nozomi_vantage.attributes.capture_device
—
Capture device
attributes.created_at
nozomi_vantage.attributes.created_at
—
Created at
attributes.device_id
nozomi_vantage.attributes.device_id
—
Device ID
attributes.end_of_sale_date
nozomi_vantage.attributes.end_of_sale_date
—
End of sale date
attributes.end_of_support_date
nozomi_vantage.attributes.end_of_support_date
—
End of support date
attributes.has_remediations
nozomi_vantage.attributes.has_remediations
—
Has remediations
attributes.has_replacement
nozomi_vantage.attributes.has_replacement
—
Has replacement
attributes.id
nozomi_vantage.attributes.id
—
Unique identifier
attributes.is_ai_enriched
nozomi_vantage.attributes.is_ai_enriched
—
Is ai enriched
attributes.is_arc_enriched
nozomi_vantage.attributes.is_arc_enriched
—
Is arc enriched
attributes.is_sp_enriched
nozomi_vantage.attributes.is_sp_enriched
—
Is sp enriched
attributes.is_ti_enriched
nozomi_vantage.attributes.is_ti_enriched
—
Is ti enriched
attributes.latitude
nozomi_vantage.attributes.latitude
—
Latitude
attributes.level
nozomi_vantage.attributes.level
—
Level
attributes.lifecycle
nozomi_vantage.attributes.lifecycle
—
Lifecycle
attributes.location_source
nozomi_vantage.attributes.location_source
—
Location source
attributes.longitude
nozomi_vantage.attributes.longitude
—
Longitude
attributes.mobility
nozomi_vantage.attributes.mobility
—
Mobility
attributes.nozomi_risk
nozomi_vantage.attributes.nozomi_risk
—
Nozomi risk
attributes.os_or_firmware
nozomi_vantage.attributes.os_or_firmware
—
OS or firmware
attributes.product_name
nozomi_vantage.attributes.product_name
—
Product name
attributes.protocols
nozomi_vantage.attributes.protocols
—
Protocols
attributes.record_created_at
nozomi_vantage.attributes.record_created_at
—
Record created at
attributes.redundant_at
nozomi_vantage.attributes.redundant_at
—
Redundant at
attributes.replacement
nozomi_vantage.attributes.replacement
—
Replacement
attributes.replacement_url
nozomi_vantage.attributes.replacement_url
—
Replacement URL
attributes.risk
nozomi_vantage.attributes.risk
—
Risk
attributes.roles
nozomi_vantage.attributes.roles
—
Roles
attributes.technology_category
nozomi_vantage.attributes.technology_category
—
Technology category
attributes.time
nozomi_vantage.attributes.time
—
Time
attributes.type
nozomi_vantage.attributes.type
—
Type
attributes.updated_at
nozomi_vantage.attributes.updated_at
—
Updated at
attributes.vendor_country
nozomi_vantage.attributes.vendor_country
—
Vendor country
attributes.vlan_id
nozomi_vantage.attributes.vlan_id
—
Vlan ID

Vulnerability Attributes

Device Security collects vulnerability attributes from Nozomi Vantage. The following table lists each Nozomi Vantage attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Nozomi Vantage Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
attributes.cve
nozomi_vantage.attributes.cve
cve
CVE
attributes.score
nozomi_vantage.attributes.score
cvss_base_score
Score
attributes.time
—
detected_time
Time
attributes.mac_address
—
id
MAC address
attributes.resolved
—
state
Resolved
attributes.cwe_name
nozomi_vantage.attributes.cwe_name
—
Cwe name
attributes.epss_score
nozomi_vantage.attributes.epss_score
—
Epss score
attributes.probability
nozomi_vantage.attributes.probability
—
Probability
* Only some attributes map to a Device Security Common Attribute.