Explore your data
Veracode Analytics provides Explores to analyze data and present insights and metrics on your application’s security status. Explores are the foundation of Veracode Analytics because they provide an interface to query data, create visualizations and build dashboards.
Using Explores, you can access data from across the Veracode Platform to provide insights into security posture, findings, and policy compliance across teams and applications. For example, use findings and policy data to gain insight into findings that impact policies. Similarly, combine application and policy data to determine the number of applications that are policy compliant. Veracode Analytics offers multiple Explores, each with its own set of views.
Views, dimensions, and measures
In an Explore, views are groups of fields that help you create queries and build visualizations. For example, the Applications view has fields related to applications, and the Findings view has finding fields. Depending on the Explore you choose, the relevant views are available to query from.
Fields in a view are categorized and grouped into dimensions and measures. Dimensions are text, date, or numeric fields that represent a row-level attribute in a database table. For example, in the Applications explore, Business Unit, Created Date, and Current Policy Compliance are all dimensions.
In a view, measures are calculated values or mathematical aggregations such as sums and averages. For example, in the Scans explore, Count, Count 365 Days, and Count 90 Days are all measures. Using dimensions and measures in views, you can build complex queries to analyze your applications' security posture from multiple perspectives.
Available Explores
The following Explores are available in the Veracode Platform. When deciding which Explore to choose, think about the primary information you are investigating. For example, if you are investigating findings, choose the Findings Explore.
- Applications: information on your application, including custom fields, application metadata, application counts, and security consultations.
- Scans: data on your scan information, including scan types, scan counts, scan duration, and analysis size.
- Findings: data on the findings discovered in your application, including CWE data, flaw age, mitigation status, and flaw counts.
- IDE and Pipeline Scans: data on Veracode Pipeline Scan usage (including Veracode Scan IDE plugins and the REST API) by users, language, and scan results. You only have data in this explore if you are a licensed user of the products providing the data.
- Users: data on Veracode Platform user accounts, including login status, account state, and username details.
- SCA Agent-Based Scans: data on SCA Agent-Based Scan usage and results, including workspaces, projects, scans, libraries, and license risk.
- SCA Agent-Based Scan Issues: data from the SCA Agent-Based Scans Explore, plus date of issues, including CVEs and CWEs.
- Firewall: information on Veracode Package Firewall usage.
Use Analytics Explores to create an insight
You can see all the Explores on the Explore Your Data page. However, Veracode only provides data for products that your organization has purchased. To understand how to create an insight, use the Findings Explore to determine the count of high-severity findings for applications.
- In the Veracode Platform, select Analytics, and then Explore Your Data. The Explore Your Data page opens.
- Select the Findings Explore. The list of views is available on the left.
- Open the Applications view and select Application Name. This field is a dimension.
- Open the Findings view and select Count of Custom High Severity Findings under Total Number of Findings. This field is a measure. You have created an insight.
- To run this insight, select Run. The count of custom high-severity findings for each application is displayed.
You can turn this insight into a visualization using the Visualization tab.