Vulnerable Response and Virtual Machines
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-10-2025 08:50 AM
With in our company, we have been using ServiceNow for over 5 years, with me being moved up into the team 2 years ago. During that time, a lot of changes/customizations have been implemented, changed, rolled back, etc. At this point in time, we are trying to shift back to OOB practices.
At this time we are trying to get VR off the ground (or have been for over a year). Due to the size of our company, we could not fully implement VR as the shear number of vulnerable items and associated Remediation tasks created would have overwhelmed our reporting and support staff, so we created assignment rules to filter out non-DMZ devices for starting point, dumping these all into a dummy VR-Wasteland assignment group.
Question 1:
Remediation tasks, as well as vulnerable items, are being created that we are no dealing with. This is starting to create a heavy load on our database. From the VR documentation, filtering by site seems to be the way to go for not bringing in VR data we will not be working with. Unfortunately, this may take a big overhaul on how they set up sites in Rapid7, so they are asking if there is a different/better way to filter the incoming data?
Question 2:
As a company, we are doing major clean up of or Virtual server environments. With that, there are often VIs that are permanently removed, in which case they are asking me to remove it from the CMDB. In doing this, the auto close in VR is not happening, and the VR team is complaining about this. The worry and ask for removing the VI data is that often times, the CI name will be re-used, often within a month or 2. Wondering how others may deal with that, and if retiring them so that VR can auto close is better? What happens when the CI name gets re-used? right now we don't manage VIs (or servers in general) in HAM pro, but that may start within a year or 2. How would that impact HAM?
Thanks for reading my novella of a post here.