<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to write DQL to get Vulnerability details for application or process in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-write-DQL-to-get-Vulnerability-details-for-application-or/m-p/291262#M38200</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/46340"&gt;@heramb_sawant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vulnerability state reports are stored as security events in Grail. The recommended way is to query the security.events table for VULNERABILITY_STATE_REPORT_EVENT, deduplicate to the latest snapshot per affected entity, and (optionally) join to monitored entities (e.g., process or process group) to enrich with names, tags, ownership, etc.&lt;/P&gt;&lt;DIV&gt;As usggested by&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/58682"&gt;@AntonPineiro&lt;/a&gt;&lt;DIV&gt;that’s the perfect documentation for this topic—it provides ready-made DQL queries for vulnerability state reports, Management Zone scoping, and severity filters.&lt;BR /&gt;You can also refer to this doc that explains where vulnerability events live in Grail (security.events), including bucket details and retention:&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.dynatrace.com/docs/secure/threat-observability/concepts" target="_blank"&gt;Threat Observability concepts — Dynatrace Docs&lt;/A&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 10 Dec 2025 21:32:37 GMT</pubDate>
    <dc:creator>sujit_k_singh</dc:creator>
    <dc:date>2025-12-10T21:32:37Z</dc:date>
    <item>
      <title>How to write DQL to get Vulnerability details for application or process</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-write-DQL-to-get-Vulnerability-details-for-application-or/m-p/291211#M38191</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;I w am building SRG for Security check/Vulnerabilities. Can someone help to to know how can I write DQL to fetch vulnerability details from grail.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Heramb sawant&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 09:20:01 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-write-DQL-to-get-Vulnerability-details-for-application-or/m-p/291211#M38191</guid>
      <dc:creator>heramb_sawant</dc:creator>
      <dc:date>2025-12-10T09:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to write DQL to get Vulnerability details for application or process</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-write-DQL-to-get-Vulnerability-details-for-application-or/m-p/291231#M38197</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You can check &lt;A title="DQL examples for security data" href="https://docs.dynatrace.com/docs/shortlink/security-events-examples" target="_blank" rel="noopener"&gt;DQL examples for security data&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 13:28:43 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-write-DQL-to-get-Vulnerability-details-for-application-or/m-p/291231#M38197</guid>
      <dc:creator>AntonPineiro</dc:creator>
      <dc:date>2025-12-10T13:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to write DQL to get Vulnerability details for application or process</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/How-to-write-DQL-to-get-Vulnerability-details-for-application-or/m-p/291262#M38200</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/46340"&gt;@heramb_sawant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vulnerability state reports are stored as security events in Grail. The recommended way is to query the security.events table for VULNERABILITY_STATE_REPORT_EVENT, deduplicate to the latest snapshot per affected entity, and (optionally) join to monitored entities (e.g., process or process group) to enrich with names, tags, ownership, etc.&lt;/P&gt;&lt;DIV&gt;As usggested by&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/58682"&gt;@AntonPineiro&lt;/a&gt;&lt;DIV&gt;that’s the perfect documentation for this topic—it provides ready-made DQL queries for vulnerability state reports, Management Zone scoping, and severity filters.&lt;BR /&gt;You can also refer to this doc that explains where vulnerability events live in Grail (security.events), including bucket details and retention:&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.dynatrace.com/docs/secure/threat-observability/concepts" target="_blank"&gt;Threat Observability concepts — Dynatrace Docs&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Dec 2025 21:32:37 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/How-to-write-DQL-to-get-Vulnerability-details-for-application-or/m-p/291262#M38200</guid>
      <dc:creator>sujit_k_singh</dc:creator>
      <dc:date>2025-12-10T21:32:37Z</dc:date>
    </item>
  </channel>
</rss>

