Using the Create SCAP 1.3 Compatible Report wizard
The SCAP Compatible Report wizard helps users make reports that follow SCAP standards. It guides the process of compiling compliance and vulnerability scan results in a standard format, making it easier to share, analyze, and meet regulatory requirements. This guide explains how to use the Web Reports interface to create a compliance report in the Asset Reporting Format (ARF).
About this task
For optimal performance and compatibility, use Microsoft Edge or Google Chrome as your browser when running ARF reports.
To generate an SCAP 1.3 ARF file, see the instructions on how to use the SCAP command line tools located here: SCAP 1.3.
- Open the BigFix Console.
- Navigate to
Tools→Launch Web Reports. - Enter your web report credentials when
prompted.

- Click on Report List.
- Select ARF Report Generator 1.0.71b from the list.
Follow the steps below to generate the ARF report:
Procedure
-
Click the dropdown arrow beside BigFix SCAP Reporting to
expand the menu.

-
Click the Import Source Data Stream and
choose a datastream file to import.

-
Click on Import Source Site Data and
select the Custom Site from the
dropdown menu.


-
Click the Run button.

-
Once the run is complete, select the report view titled
Single Machine Full Results with System
Characteristics to generate the ARF
report.

BigFix SCAP Reporting - ARF Report Types SummaryNote: Single Machine With This Results- Key Data Included: Evaluation Results (TestResult) ONLY.
- System Characteristics: No (Minimal Data).
- Best Use Case: Quick verification, debugging, minimal metadata needs.
Note: Single Machine Full Results With System Characteristics- Key Data Included: Evaluation Results (TestResult) + System Characteristics (oval-system-characteristics).
- System Characteristics: Yes (Full Data).
- Best Use Case: Official NIST SCAP 1.3 certification, compliance submissions, full audit.
Note: Single Machine Full Results Without System Characteristics- Key Data Included: Evaluation Results (TestResult) ONLY.
- System Characteristics: No (Anonymized Data).
- Best Use Case: Privacy-conscious export, combining reports (aggregation), data redaction.
-
Select the specific endpoint (machine) for which you wish to
generate the compliance report.


-
On the generated report view, click the Download Report
button. The ARF result file will be downloaded with the
generic name:
xmlresult.xml.
-
It is essential to rename the generated
xmlresult.xmlto a more meaningful name based on the datastream used. For example: If the datastream isr.400.1.1, rename the file tor.400.1.1.xml.