KB Article

kb_article

The KB Article object contains metadata that describes the patch or update.

Attributes

CaptionNameTypeDescription
Average Timespanavg_timespanTime Span[]

The average time to patch.

Patch BulletinbulletinString

The kb article bulletin identifier.

ClassificationclassificationString

The vendors classification of the kb article.

Created Timecreated_timeTimestamp

The date the kb article was released by the vendor.

Install Stateinstall_stateString

The install state of the kb article.

Install State IDinstall_state_idInteger

The normalized install state ID of the kb article.

  • 0: Unknown (UNKNOWN)
  • 1: Installed (INSTALLED)
  • 2: Not Installed (NOT_INSTALLED)
  • 3: Installed Pending Reboot (INSTALLED_PENDING_REBOOT)
  • 99: Other (OTHER)
The patch is superseded.is_supersededBoolean

The kb article has been replaced by another.

OSosOperating System (OS)[]

The operating system the kb article applies.

ProductproductProduct[]

The product details the kb article applies.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

SeverityseverityString

The severity of the kb article.

SizesizeLong

The size in bytes for the kb article.

Source URLsrc_urlURL String

Entity:URL_STRING
The kb article link from the source vendor.

TitletitleString

The title of the kb article.

Unique IDuidString

The unique identifier for the kb article.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

Relationships

KB Article shown in context

Inbound Relationships

These objects and events reference KB Article in their attributes:

Outbound Relationships

KB Article references the following objects and events in its attributes:

This page describes ocsf-1.4.0