lacework / extensible-reporting

A command line tool for generating Lacework Reports
12 stars 4 forks source link

Issue with Max Vuln Results #77

Open jbonner7 opened 1 year ago

jbonner7 commented 1 year ago

There appears to be a limitation when the API returns more than 100 pages of host vuln data:

2022-12-15 10:26:38 providers.lacework.host_vulns[95135] INFO Saving page 99 2022-12-15 10:26:38 laceworksdk.http_session[95135] INFO GET request to URI: https://customer.lacework.net/api/v2/Vulnerabilities/Hosts/MDJkMTY5ZDEtNDU3Ni00MmJlLWFlZmEtZTQ0NTliNmQ5Mjk0LDQ5NTAwMCw1MDAwMDAsMA 2022-12-15 10:26:41 providers.lacework.host_vulns[95135] INFO Saving page 100 2022-12-15 10:26:41 providers.lacework.host_vulns[95135] WARNING Lacework API returned maximum pages of host vuln results (100 pages). Processed dataset is likely incomplete.

jvogt commented 1 year ago

Unfortunately this is a limitation of the vuln API endpoints. API responses for vuln data are exceedingly verbose, and are paginated even for very small host and container vuln datasets. The LW API caps pagination at 100 pages.