Asset Fields Imported in File-Based Adapters

The following sections detail which fields are imported as common data fields for each asset file (Devices, Users, etc.). Any other data in the CSV/JSON/XML is exclusively adapter-specific data.

General guidelines

  • These fields apply to the general CSV adapter and the JSON and Custom Files adapters, according to the asset types fetched by each adapter. Any other asset-specific requirements are listed under the specific file type.

    📘

    Note

    In addition for the general CSV adapter, Axonius has several CSV Asset-Specific Adapters. Generally, these are no longer supported (see note in each page), but you can still use them for reference.

  • For all values under Accepted CSV Field Name(s), spaces, hyphens and underscores are ignored, and the field name is always lowercase. For example, First_Name --> `firstname'.

  • Fields marked as Yes under Required Field? indicate that you need to include at least one of these fields as part of the imported CSV file. More of these fields available in the CSV file help provide stronger correlation.

Note about Security Findings fields

Security Findings are generated from the Security Findings complex field (table) within your assets. To import them, you must first import the corresponding assets (Devices, Users, etc.); then, map the Security Findings fields using the Adapter Custom Parsing capability, where you can define how to parse specific fields from the raw data fetched.

Fields Imported with a Devices File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
ArchitecturearchitectureNo
Asset Namename, vmname, displayname, assetname, machinename, instancename, samaccountname, endpointname, machineNoIf no hostname is configured, the Asset Name value is used for the Host Name.
Asset Tagassettag, tags, tag, labels, labelNoAccepts multiple formats (see below)
Cloud IDcloudid, linodeidNo
Cloud Providercloudprovider, cloudprovidorNo
Device Manufacturermanufacturer, devicemanufacturerNo
Device Manufacturer Serialserial, serialnumber, sn, hostserialnumber, deviceserialnumber, serial, endpointserialnumber, allserialnumbersYes
Device Modelmodel, modelid, endpointmodelNo
Domaindomain, domainname, endpointdomainNoIf not specified and device is in DOMAIN\Name format, Axonius replaces the Domain with the parsed value.
Host Namehostname, host, fqdn, fullyqualifieddomainname, compname, computername, servername, dnsname, hosthostname, endpointfqdnYesParses DOMAIN out if in DOMAIN\Name format. If set to "unknown", field is set to blank.
IDid, identifier, serialnumber, assetid, resourceidYesCombination of the "CSV File Name" and the specified field names.
IPsipaddresstext, ip, ipaddress, ipaddresses, ips, primaryip, endpointipaddress, registerip, sourceip, managementip, privateip, allips, lastip, address, ipaddresslist, ipaddri, ipaddrs, ipaddr, localip, privateipaddresses, ipfirstNoAccepts a comma-separated set of IP addresses.
Last Seenlastmessagetime, lastdiscoveredtime, lastseen, lastcheckinNoIf not specified, uses the time the file was last imported.
Last Used UsersusernameNoAppends to existing list if the device already exists.
MACmac, macaddress, macaddresses, macsYesAccepts a comma-separated set of MAC addresses.
MachinenameNo
Network InterfacesnetworkinterfacesNoAxonius attempts to parse IP, MAC, and NICs from this field.
OSos, osname, osversion, operatingsystem, osmode, uname, endpointosNoParsed into multiple properties. Reach out to Axonius if an OS is not parsing as expected.
OS: Kernel Versionkernel, kernelversionNo
Software NamepackagesNoDelimited by spaces.
Tag Nametagname, tagkey, labelname, labelkeyNo
Tag Valuetagvalue, labelvalueNo

Acceptable Formats for the Asset Tag Field

FormatExample
Comma-separated string"Production,Critical,Web" → 3 tags
List of string["Production", "Critical"] → 2 tags
List of key-value dictionaries[{"key": "env", "value": "prod"}] → 1 tag with key
Single dictionary{"key": "env", "value": "prod"} → 1 tag with key

Fields Imported with a Users File

UI Field NameAccepted CSV Field Name(s)Required Field?Notes
Domaindomain, domainname, endpointdomainNo
First Namefirstname, givennameNo
IDid, identifier, serialnumber, assetid, resourceid, useridYesThe ID field is a combination of the "CSV File Name" value and the specified field names.
Last Namelastname, surname, snNo
Mailmail, email, usermail, mailaddress, email address, emailprimarywork, companyemailYes
Namename, vmname, displayname, assetname, machinename, instancename, samaccountname, endpointnameYes
User NameusernameYes

Fields Imported with a Software Applications File

The minimum requirements to parse Vulnerabilities from the CSV adapter are as follows:

- The File contains installed software parameter is checked.
- The file has at least the following headers:
- Hostname (or any of the headers supported as hostname)
- Software Name (header must be present, though may be empty on a row)
- CVE ID

The other headers (or data in a row for those headers) are optional for the purposes of parsing Vulnerabilities.

UI Field NameAccepted CSV Field Name(s)Required Field?Notes
Host Namehostname, host, fqdn, fullyqualifieddomainname, compname, computername, servername, dnsname, hosthostname, endpointfqdnYesThis field is required as the software list is imported to each individual device.
Software Namesoftwarename, swnameYesThis field is required in order to parse installed software. This field may be left empty on a row with CVE ID.
Software Pathsoftwarepath, swpathNo
Software Vendorsoftwarevendor, swvendorNo
Software Versionsoftwareversion, swversionNo
CVE IDcve, cveid, cvelist, grypecveNoIf present, a row featuring a CVE ID is parsed as vulnerable software in addition to installed software.
CVE DescriptioncvedescriptionNoThis field will be ignored if CVE ID is empty or not present.
CVE SeveritycveseverityNoCVE Severity needs to be one of the values listed here. An invalid CVE Severity value is ignored. This field will be ignored if CVE ID is empty or not present. 'NONE', 'LOW', 'MEDIUM', 'MODERATE', 'SEVERE', 'SERIOUS', 'HIGH', 'CRITICAL', 'URGENT', 'INFO', 'UNTRIAGED', 'NEGLIGIBLE'
CVE StatuscvestatusNoCVE Status needs to be one of the values listed here. An invalid CVE Status value is ignored. This field will be ignored if CVE ID is empty or not present. 'open', 'closed', 'reopen', 'expired', 'done', 'valid', 'obsolete', 'pending'

Fields Imported with a Databases File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, serialnumber, assetid, recid, deviceid, objectid, hostid, databaseidYesThis field is required (database ID).
Namename, displayname, assetname, instancename, databasename, datname, database, schemanameYesThis field is required (database name).
IPip, ipaddress, ipaddresses, ips, sourceip, ipaddresstext, paddresstext, primaryip, endpointipaddress, registerip, managementip, privateip, allips, ipfirst, lastip, address, ipaddresslist, ipaddri, ipaddrs, ipaddr, localip, privateipaddresses, databaseipNo
PortportNo
Status / Asset Statusstatus, assetstatus, databasestatus, stateNo
Instance / Instance Typeinstance, instancetypeNo
Creation Date / Timecreationdatetime, datecreation, createddatetime, creationtimeNo

Fields Imported with an Accounts File

UI Field NameAccepted CSV Field Name(s)Required Field?Notes
IDid, identifier, serialnumber, assetid, recid, deviceid, objectid, hostid, accounteidYesThis field is required (account ID).
Namename, diaplayname, assetname, instancename, accountenameYesThis field is required (account name).
Creation Timecreationdatetime, datecreationNo

Fields Imported with a Business Applications File

UI Field NameAccepted CSV Field Name(s)Required Field?Notes
IDid, application number, applicationnumberYesThis field is required
Namename, application name, applicationnameYesThis field is required
Application Typeapplication type, applicationtypeNo
Application Descriptiondescription, application description, applicationdescriptionNo
Managed Bymanaged by, managedbyNo
Business Criticalitybusiness critically, businesscriticallyNo
Operational Statusoperational status, operationalstatusNo

Fields Imported with an Alerts/Incidents File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, incidentid, cloudid, uniqueidYesThis field is required
Namename, incidentname, dusplaynameNo
Descriptioncreated, createdtime, creationtime, creteddatetime, createdatNo
Statusstatus, incidentstatus, stateNo
Created Atstarttime, startNo
Start Timestarttime, startNo
End Timeendtime, endNo

Fields Imported with a Network Services File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, uniqueidYes
Namename, displaynameYes
Cloud IDcloudid, linodeidYes
Cloud Providercloudprovider, cloudprovidorNo
Vendorvendor, provider, vendornameNo
Asset Typeinstance, instancetypeNo
Descriptionassettype, txtassettype, typeNo
Statusstatus, incidentstatus, stateNo
Createdcreated, creationdate, datecreationNo
Last Seenlastmessagetime, lastdiscoveredtime, lastseen, lastcheckinNo
IPsipaddresstext, ip, ipaddress, ipaddresses, ips, primaryip, endpointipaddress, registerip, sourceip, managementip, privateip, allips, lastip, address, ipaddresslist, ipaddri, ipaddrs, ipaddr, localip, privateipaddresses, ipfirstNoThis field accepts a comma separated set of IP addresses.

Fields Imported with a Certificates File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, uniqueid, certificateid, certificateremoteidYes
Namename, displayname, certificatename, commonnameYes
Cloud IDcloudid, linodeidYes
Asset Typeassettype, certificatetype, typeNoOne of: AWS Certificate, GoDaddy Certificate, Keyfactor Certificate, Webscan Certificate, Network Discovery Certificate, Cloudflare Certificate, CertificateFromKeyVault, ADCS Certificate, CSC DomainManager Certificate, Wiz Certificate, F5-IControl SSL Certificate
Create Timecreatetime, created, createdtime, creationtime, createdatetimeNo
Issuerissuer, issuedby, certificateissuerNoMust be in DN (Distinguished Name) format
Versionversion, certificateversionNo
Serial Numberserialnumber, serial, certificateserialnumberYes
Subjectsubject, issuedto, certificatesubjectNoMust be in DN (Distinguished Name) format
Begins Onbeginson, validfrom, notbefore, startdateNo
Expires Onexpireson, validto, notafter, expirationdate, expiration, expirationtimeNo
Bit Sizebitsize, keysize, keylengthNo
Issued Distinguished Nameissueddistinguishedname, distinguishedname, dnNo
Statusstatus, certificatestatus, stateNo
Key Algorithmkeyalgorithm, keyalg, publickeyalgorithmNo
Signature Algorithmsignaturealgorithm, signaturealg, sigalgorithmNo
Not Beforenotbefore, validfrom, beginsonNo
Imported Atimportedat, importtime, importedtimeNo
Cloud Providercloudprovider, cloudprovidorNo
Assigned IP Addressipaddresstext, ip, ipaddress, ipaddresses, ips, primaryip, endpointipaddress, registerip, sourceip, managementip, privateip, allips, ipfirst, lastip, address, ipaddresslist, ipaddri, ipaddrs, ipaddr, localip, privateipaddressesNo

Fields Imported with a Firewalls File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, uniqueid, firewallidYes
Namename, displayname, firewallnameYes
Original Sourceoriginal_source, originalsource, presource, prenatsourceNoPre-NAT source IP/CIDR/range or 'any'. Supports the following formats:
Plain IP (10.0.0.5), CIDR (10.0.0.0/24), IP range (10.0.0.1-10.0.0.10), Any (any or 0.0.0.0/0)
Translated Sourcetranslated_source, translatedsource, postsource, postnatsource, snatsourceNoPost-NAT source IP/CIDR/range (SNAT). Supports same formats as Original Source
Original Destinationoriginal_destination, originaldestination, predestination, prenatdestinationNoPre-NAT destination IP/CIDR/range or 'any'. Supports same formats as Original Source
Translated Destinationtranslated_destination, translateddestination, postdestination, postnatdestination, dnatdestinationNoPost-NAT destination IP/CIDR/range (DNAT). Supports same formats as Original Source
Original Portoriginal_port, originalport, preport, prenatportNoPre-NAT port: single port (e.g., 443) or port range (e.g., 80-443)
Translated Porttranslated_port, translatedport, postport, postnatportNoPost-NAT port: single port or port range
Protocolsprotocols, protocolNoA list of comma-separated protocols (TCP, UDP, ICMP, ANY)
NAT Typenat_type, nattype, typeNoOptional hint: SNAT / DNAT / NAT (automatically inferred if omitted)
Is Staticis_static, isstatic, staticNo

Fields Imported with a Load Balancers File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, uniqueid, loadbalancerid, lbidYes
Namename, displayname, loadbalancername, lbnameYes
Host IPshost_ips, hostips, ipaddress, ip, loadbalancerip, lbipNoAccepts comma-separated values for multiple IP addresses
Balanced IPsbalanced_ips, balancedips, backendips, serverips, targetipsNoAccepts comma-separated values for multiple IP addresses (balanced backend servers)
Balanced Hostnamesbalanced_hostnames, balancedhostnames, backendhostnames, serverhostnames, targethostnamesNoAccepts comma-separated values for multiple hostnames (balanced backend servers)

Fields Imported with a URLs/Domains File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, uniqueid, urlid, domainidYes
Base URLbase_url, baseurl, urlYeshttps://example.com
Domaindomain, domainname, hostnameYesexample.com
IP Addressesip_addresses, ipaddresses, ips, ipNoAccepts comma-separated IP addresses associated with the URL
Destination Hostnamesdestination_hostnames, destinationhostnames, targethostnames, resolvedhostnamesNoAccepts comma-separated destination hostnames the URL resolves to

Fields Imported with a Network Routes File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, uniqueid, routeid, networkrouteidYes
Namename, displayname, routename, descriptionYesRoute name or description
📘

Note

Additional routing-specific fields can be provided as needed for your network topology.

Fields Imported with a Containers File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, uniqueid, assetidYes
Namename, displayname, assetnameYes

Fields Imported with an Application Settings File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
Setting Namesetting_nameYes
Vendor Namevendor_nameYes
Setting Valuesetting_valueYes
Is Validis_validYes

Fields Imported with a Compute Services File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
IDid, identifier, uniqueid, cloudidYesEither the ID, Name, or Cloud ID fields must be populated
Namename, displayname, clustername, servicenameYesEither the ID, Name, or Cloud ID fields must be populated
Cloud IDcloud_id, cloudidYesEither the ID, Name, or Cloud ID fields must be populated
Cloud Providercloud_provider, cloudproviderNo
Asset Typeassettype, typeNo
Descriptiondescription, detailsNo
Statusstatus, stateNo
Locationlocation, region, zoneNo

Fields Imported with a Tickets File

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
Ticket IDticket_id, ticketid, id, number, ticketnumber, incidentnumberYes
Summarysummary, title, short_description, shortdescriptionNo
Statusstatus, state, ticketstatusNo
Prioritypriority, ticketpriority, urgencyNo
Assigneeassignee, assigned_to, assignedtoNo
Reporterreporter, created_by, createdby, opened_byNo
Createdcreated, createdat, creationtime, createddatetimeNo
Updatedupdated, updatedat, modifiedat, lastmodifiedNo

Fields Imported with a Software File

📘

Note

The field names must be exactly as listed under Accepted CSV/JSON Field Name(s).

UI Field NameAccepted CSV/JSON Field Name(s)Required Field?Notes
NameAxonius_Software_NameYes
VendorAxonius_Publisher_NameYes
VersionAxonius_Software_VersionNo
Approval StatusAxonius_Approval_StatusNo

Additional Asset Types

📘

Note

This section lists different asset-specific CSV adapters, which are generally no longer supported by Axonius; however, you can still refer to these pages to see the required table fields for each asset type.

For SaaS Applications see the structure in CSV - Applications.

For DNS Records see the structure in CSV - DNS Records.

For Expenses see the structure in CSV - Expenses.

For Licenses see the structure in CSV - Licenses

For Networks see the structure in in CSV - Networks.

For Network Services see the structure in CSV - Network Services.

For URLs see the structures in CSV - URLs.



Did this page help you?