Autoclose Vulnerable items on Retired CIs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-24-2022 04:57 PM
We just upgraded to VR version 15, where autoclose retired CIs is a checkbox, which we have checked. However, we changed some CIs to retired state and their vulnerable items have not closed after multiple days. Is there somewhere in VR we can look to show why this feature is not working?
Thanks,
Andrew
- Labels:
-
Vulnerability Response
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
We are using the Auto-close rules module (which uses the Auto-close Rule Processor scheduled job) and using the install status of the CI. This works fine, however I am seeing that the Discovered Item state remains matched and not marked as CI Decommissioned. We are seeing where the scanner will re-open Closed VITs (from our auto-close rules) on decommissioned CIs and create a flapping issue. My question is, should I add install status to the "sn_sec_cmn.ci_lifecycle_status_source" system property and activate the Close detections/VIs for decommissioned CIs scheduled job as well so that it will mark our discovered items as CI Decommissioned, AND still use the auto-close rules? I am hoping using both (and marking discovered items as CI Decommissioned on the associated retired CI) will prevent the closed VITs from flapping back open again
